<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; media notification</title>
	<atom:link href="http://www.experiordata.com/blog/tag/media-notification/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Congress to HHS: Remove the harm assessment!</title>
		<link>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/</link>
		<comments>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/#comments</comments>
		<pubDate>Sat, 03 Oct 2009 19:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[congress]]></category>
		<category><![CDATA[media notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=143</guid>
		<description><![CDATA[



Image via Wikipedia



In a strongly-worded letter sent and signed by six congressmen to HHS Secretary Kathleen Sebelius the message was clear: remove the harm assessment that lawmakers rejected when writing the privacy regulations into ARRA. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 218px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg"><img title="Kansas Governor :en:Kathleen Sebelius speaks w..." src="http://upload.wikimedia.org/wikipedia/commons/1/1d/Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg" alt="Kansas Governor :en:Kathleen Sebelius speaks w..." width="208" height="332" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>In a strongly-worded <a title="Letter from Congress to HHS asking to remove harm standard from breach notification" href="http://energycommerce.house.gov/Press_111/20091001/sebelius_letter.pdf" target="_blank">letter</a> sent and signed by six congressmen to <a class="zem_slink" title="United States Secretary of Health and Human Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/United_States_Secretary_of_Health_and_Human_Services">HHS Secretary</a> <a class="zem_slink" title="Kathleen Sebelius" rel="wikipedia" href="http://en.wikipedia.org/wiki/Kathleen_Sebelius">Kathleen Sebelius</a> the message was clear: remove the harm assessment that lawmakers rejected when writing the <a class="zem_slink" title="Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Privacy">privacy</a> regulations into <a title="American Recovery and Reinvestment Act of 2009" href="http://www.experiordata.com/images/american_recovery_reinvestment_act.pdf" target="_blank">ARRA</a>. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or not the breach can cause reputational, financial, and other types of harm.  This leaves open the possibility that a covered entity could decide to act in its own interest and make the decision not to follow the directives written into the <a title="Interim final ruling on breach notification" href="http://www.experiordata.com/images/interim_final_ruling.pdf" target="_blank">breach notification ruling</a>.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>There are, of course, two sides of the sword. On one hand it&#8217;s difficult to enforce a policy with subjective elements present, such as the harm assessment. It is unlikely that a covered entity would risk the substantial fines, now as high as $1.5 million, and the possibility of criminal prosecution to avoid notification in case a serious breach occurs. However, the harm assessment leaves that possibility open.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>A drawback to removing the harm assessment is that it is possible that, ironically, that too many breach notifications are sent to people, thereby creating a &#8220;boy that cries wolf&#8221; effect. In a perfect world breaches would never happen, so there would not need to be a reason to notify people. However, we all know that not to be the reality. Breaches do occur, intentional or not. And people need to be notified as soon as possible. Should covered entities be given the privilege of deciding the severity of the harm and potentially choosing not to notify people? We shall see the next steps Congress and HHS will take.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f109c045-b7ee-4c5f-b033-6660b8cf7572/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f109c045-b7ee-4c5f-b033-6660b8cf7572" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Media Notification Works (and how to avoid it)</title>
		<link>http://www.experiordata.com/blog/2009/09/09/how-media-notification-works/</link>
		<comments>http://www.experiordata.com/blog/2009/09/09/how-media-notification-works/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 03:16:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[media notification]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=121</guid>
		<description><![CDATA[



Image via Wikipedia



Media notification is required when a breach of more than 500 records has occurred.  The Interim Final Rule preamble discusses how the U.S. Department of Health and Human Services (HHS) expects the media to be notified in case a breach of over 500 records occurs. Note that HHS considers media notification to be [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:US-DeptOfHHS-Logo.svg"><img title="Logo of the United States Department of Health..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/1/15/US-DeptOfHHS-Logo.svg/300px-US-DeptOfHHS-Logo.svg.png" alt="Logo of the United States Department of Health..." width="300" height="300" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:US-DeptOfHHS-Logo.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Media notification is required when a breach of more than 500 records has occurred.  The <a title="Link to Experior Data Resources section " href="http://www.experiordata.com/resources.php" target="_blank">Interim Final Rule</a> preamble discusses how the <a class="zem_slink" title="United States Department of Health and Human Services" rel="homepage" href="http://www.hhs.gov/">U.S. Department of Health and Human Services</a> (HHS) expects the media to be notified in case a breach of <span style="text-decoration: underline;">over 500</span> records occurs. Note that HHS considers <span style="text-decoration: underline;">media notification to be relative to where the residents live, not the location of the covered entity or business associate.</span></p>
<ul>
<li>If the residents in the unsecured protected health information (PHI) live in a <span style="text-decoration: underline;">particular city </span> the breach notification should be sent to  the prominent media outlet serving that city. A prominent media outlet could be a television station or newspaper (no preference is given).</li>
<li>If the residents in the unsecured protected health information (PHI) are <span style="text-decoration: underline;">spread across a state</span> the prominent media outlet must <span style="text-decoration: underline;">serve the entire state.</span></li>
<li>If the total amount of records breached is over 500 but the residents live in multiple states and <span style="text-decoration: underline;">not more than 500 are in any one state then media notification is not required</span>.  Although media notification is not required, notification to the individuals is still required.</li>
<li>If the total amount of records breached is <span style="text-decoration: underline;">over 500 in more than one state</span> media notification is required to the<span style="text-decoration: underline;"> prominent media outlet in each state.</span></li>
</ul>
<p>The content in the media notification is identical to the content required for individual notification:</p>
<ul>
<li>A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known.</li>
<li>A description of the types of unsecured protected health information that were involved in the breach (such as whether full name, <a class="zem_slink" title="Social Security number" rel="wikipedia" href="http://en.wikipedia.org/wiki/Social_Security_number">social security number</a>, date of birth, home address, account number, diagnosis, disability code, or other types of information were involved);</li>
<li>Any steps individuals should take to protect themselves from potential harm resulting from the breach.</li>
<li>A brief description of what the covered entity involved is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches.</li>
<li>Contact procedures for individuals to ask questions or learn additional information, which shall i<span style="text-decoration: underline;">nclude a toll-free telephone number, an e-mail address, web address, or postal address.<br />
 </span></li>
</ul>
<p><span><span style="color: #c0c0c0;">..</span><br style="text-decoration: underline;" /></span></p>
<p>HHS expects the notification to the media to be in form of a press release.</p>
<p><span style="color: #c0c0c0;">..</span></p>
<p>It should be noted that you can <strong>avoid</strong><strong> media notification and notification to individuals by <a title="Encrypting Protected Health Information (PHI)" href="http://www.experiordata.com/phi_security.php" target="_blank">encrypting protected health information (PHI)</a></strong><strong> </strong><strong>.</strong></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/8c6c8f69-fa59-4034-bafb-0bbd62910381/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=8c6c8f69-fa59-4034-bafb-0bbd62910381" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/09/09/how-media-notification-works/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
