HHS Posts on its Website First Covered Entities Reporting HIPAA Data Breaches
On February 22, 2010, the Office of Civil Rights (OCR) posted on its website the first list of covered entities that have reported breaches of unsecured protected health information (PHI) affecting more than 500 individuals. OCR acknowledged the HITECH Act requires HHS to make this information public by posting it on an HHS website. HHS' breach notification rule became effective on September 23, 2009. This rule requires covered entities to provide notification of breaches of unsecured PHI directly to the Secretary of HHS, as well as to the affected individuals. Breaches that affect 500 or more individuals must be reported to HHS within 60 days, and covered entities must provide this notification via the online form on the OCR website. For more information, send an email to info@hipaarx.net or call (866) 447-2211. About BridgeFront / HIPAA Solutions Rx: |