HIPAA Breach Notice
(Media)


Summary

This HIPAA breach notice is for use by a group health plan subject to HIPAA to notify prominent media outlets about the plan's unauthorized use or disclosure of protected health information (PHI) of 500 or more individuals living in the region served by the media outlet. This template includes practical guidance, drafting notes, and alternate and optional clauses. The Health Insurance Portability and Accountability Act (HIPAA) established breach notification rules for covered entities and their business associates obligating them to timely report missing participant PHI even if there is no indication that the information was improperly accessed. 45 C.F.R. §§ 164.400 to 164.414. For a breach involving 500 or more residents of a particular state or jurisdiction, the covered entity must notify prominent media outlets serving the area of the breach in addition to notifying affected individuals individually and the Department of Health and Human Services (HHS). Media reporting, like ...