Regulation & Incentives

Breach Notification and Your EHR

Even well-run practices can experience a data incident — a lost laptop, a misdirected message, a ransomware attack, or unauthorized snooping in the EHR. The HIPAA Breach Notification Rule sets out what must happen when unsecured protected health information is breached. Understanding it in advance lets you respond calmly and correctly.

What counts as a breach

Under the rule, a breach is generally an impermissible use or disclosure of protected health information (PHI) that compromises its security or privacy. The rule presumes such an impermissible use or disclosure is a breach unless the entity demonstrates a low probability that the PHI has been compromised, based on a risk assessment of specified factors.

The risk assessment factors: The rule directs covered entities to consider at least the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.

Who must be notified

  • Affected individuals: Notice must be provided to each affected individual without unreasonable delay and within the timeframe the rule specifies.
  • HHS: The Secretary of HHS must be notified, with timing that depends on the number of individuals affected.
  • The media: For breaches affecting a large number of residents of a state or jurisdiction, media notification may be required.
  • Business associates: A business associate that discovers a breach must notify the covered entity.

How your EHR helps

EHR audit logs are central to both detecting and investigating incidents. They record who accessed which records and when, helping you determine whether PHI was actually viewed and the scope of an incident. Strong access controls, encryption, and monitoring reduce the chance of a breach and can affect the risk assessment.

Encryption matters: The rule's notification obligations apply to unsecured PHI. PHI rendered unusable, unreadable, or indecipherable through methods specified by HHS guidance — such as appropriate encryption — may fall outside breach notification obligations. This is one practical reason encryption is so valuable.

Steps to take now

  • Maintain and review EHR audit logs; investigate unusual access.
  • Encrypt ePHI at rest and in transit where feasible.
  • Have a written incident response and breach notification procedure.
  • Keep current business associate agreements with vendors handling PHI.
  • Train staff to report suspected incidents immediately.

Bottom line

The Breach Notification Rule rewards preparation: good audit logs, encryption, and a clear response plan make incidents manageable and notifications timely. Because exact timeframes and thresholds are set in regulation and updated guidance, confirm current specifics with the HHS Office for Civil Rights and involve qualified counsel for any real incident.

An incident response sequence

When something does happen, a calm, ordered response matters. A common sequence looks like this:

  1. Contain: Stop ongoing exposure — disable an account, isolate a device, or cut off an access path.
  2. Investigate: Use audit logs and interviews to determine what PHI was involved and who accessed it.
  3. Assess: Apply the rule's risk-assessment factors to decide whether notification is required.
  4. Notify: If required, notify affected individuals, HHS, and others within the applicable timeframes.
  5. Remediate: Fix the underlying weakness and update policies, training, or safeguards.
  6. Document: Keep a thorough record of the incident and your decisions.

Business associates and breaches

Many incidents originate with a vendor rather than inside the practice. Your business associate agreements should obligate vendors to notify you promptly when they discover a breach, and to cooperate in the investigation. When a cloud EHR or other service provider is involved, the BAA and the vendor's incident-handling practices become part of your own breach-response readiness.

Why this connects to everything else

Breach notification ties together the other themes on this site: HIPAA's safeguards, access controls, encryption, audit logs, and vendor agreements all reduce both the likelihood and the impact of an incident. Practices that take those measures seriously are not only less likely to suffer a breach — they are also better positioned to respond quickly and demonstrate good faith if one occurs.