HIPAA Breach Notification Rule
What is HIPAA Breach Notification Rule?
Requirements under HIPAA for covered entities and business associates to notify affected individuals, HHS, and media of breaches of unsecured PHI.
Terms that appear alongside hipaa breach notification rule
Each of these is named in at least one of the same controls as hipaa breach notification rule. The number is how many controls name both.
- breach notification 6 shared controls
- hipaa 6 shared controls
- nist 3 shared controls
- security incident 2 shared controls
- incident response 2 shared controls
- health data 2 shared controls
Frameworks that govern hipaa breach notification rule
What the standards actually require on hipaa breach notification rule
Requirements naming hipaa breach notification rule across 5 standards, quoted from the control text.
16 CFR 318.1 purpose + scope. APPLICABILITY: applies to (1) VENDORS OF PERSONAL HEALTH RECORDS (PHR) - entities offering PHR product or service to consumers + that obtain consumer health information from other sources (e.g. cross-source aggregation);
HBNR-Scope-PHR-Vendor · Scope, PHR Vendor and PHR-Related Entity Applicability (16 CFR 318.1) →Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
164.308(a)(6)(ii) · Response and Reporting (Required) →Implement NIST 800-53 IR Incident Response family + breach notification process integrated across HIPAA + ACA + IRS Pub 1075. Incident response capability with 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident response plan + tabletop and...
MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT · MARS-E Incident Response + Breach Notification + IR Family + 45 CFR 164.400-414 + IRS Pub 1075 + CMS IRT →Implement HIPAA Security Rule Administrative Safeguards for incident response + contingency + evaluation. Security Incident Procedures per 45 CFR 164.308(a)(6): identify and respond to suspected or known security incidents + mitigate harmful effects + document...
NISTSP66-3 · Security Incident Procedures, Contingency Plan, and Evaluation →Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
164.308(a)(6)(ii) · Response and Reporting (Required) →Questions people ask about hipaa breach notification rule
What is HIPAA Breach Notification Rule?
Why is HIPAA Breach Notification Rule important for compliance?
Which compliance frameworks address HIPAA Breach Notification Rule?
Where can I learn more about HIPAA Breach Notification Rule?
See how HIPAA Breach Notification Rule applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.