By Matt Fisher, Healthcare Attorney
LinkedIn: Matthew Fisher
X: @matt_r_fisher
Host of Healthcare de Jure – #HCdeJure
Revealing a data breach can be a hard action for an organization to take. The ongoing stream of notifications still generates attention, which is typically not positive when a security breakdown is revealed. At the same time, the notification is (or should be) unavoidable since the HIPAA breach notification rule is clear about what action is necessary.
The Breach Notification Rule
At this point in time, the requirements of the breach notification rule should be well understood. The basics are that an organization needs to provide notification to impacted individuals within 60 days of discovering the breach. Discovery is a defined term, which is realistically offers a little bit of wiggle room as some colorable arguments have been presented as to when the breach is really first known.
The 60 day clock also applies to notifications to the HHS Office for Civil Rights if the breach impacts 500 or more individuals. If that threshold is hit, then notice also needs to go to the local media. If a breach impacts fewer than 500 individuals, then OCR can be told at the time of the breach or within 60 days of the end of the calendar year when the breach occurred. Fewer than 500 also does not require sending a notice to the media.
The Breach Notification Rule also provides clear detail on what information needs to be included in the notice. Admittedly, it may take time to fully know all of the details, but that also does not need to mean delaying the initial notice since details can be filled in over time if the notice is worded well.
A Warning Settlement
Why was it necessary to summarize the key points of the Breach Notification Rule? Because debates come up somewhat frequently as to when notice should actually be sent and whether a breach happened. As suggested at the start, notification of a breach can be a painful process for an organization and some may go to significant lengths to develop a justification for not doing the notice.
However, failing to give notice when a breach occurred is an instance of non-compliance with the regulations. The most recent settlement announced by OCR provides that lesson and reminder. The settlement with MMG Fusion (MMG) stems from a complete failure to provide notice of a breach. MMG is a software company providing marketing, management, and growth services for oral healthcare professionals, so in other words a business associate that likely supports a decent number of covered entities.
As reported by OCR, MMG allegedly suffered some form of cyberattack that started on December 21, 2020. As part of the attack, an unauthorized individual gained access to MMG’s systems, which included the ability to view patient information. Not only was the PHI accessed, but it was also reportedly posted and available for sale on the Dark Web. Despite these actions occurring, nothing happened on the MMG side.
Instead, a complaint was filed with OCR on January 6, 2023. No information is provided as to why it took so long for a complaint to be filed or even who filed the complaint. Regardless, the complaint prompted an investigation by OCR, which likely quickly revealed the complete lack of a breach notification.
As a result of the investigation, OCR determined that MMG did ot meet expectations under HIPAA in at least a few areas. First, PHI was allowed to be used or disclosed outside the requirements of the Privacy Rule. Second, MMG had not done its required risk analysis (the broken record part of settlements). Third, and the issue that probably caused the investigation, MMG did not provide any notification of the breach.
What was the penalty for all of these failures? Only $10,000. As is so often the case, why was this dollar amount imposed? Is the amount enough to drive compliance by other entities or could this potential penalty be seen as a better alternative to the cost of a full breach notification? All good and thorny questions.
What to Do Next?
Despite the shortcomings of the settlement, the next steps are clear. Organizations must comply with breach notification requirements. Instead of viewing a breach notification as a negative event, it can be seen as an opportunity to get in front of a bad situation and begin re-establishing trust with impacted individuals. Even if an investigation is ongoing, at least letting potentially impacted individuals know about the problem as well as the start of ongoing efforts to improve protections can be impactful. Silence and stonewalling just enable speculation to run wild without any checks. A well worded notice cab help calm fears even if the full impact is not know.
When the perception of a situation is flipped, it can really change behavior. When reputation is involved it is especially important to use all efforts to control a narrative. If that is not done, then others will tell your story.
This article was originally published on The Pulse blog and is republished here with permission.