The checklist — and associated infographic — outlined four steps HIPAA-covered entities and their business associates should take following a cyberattack or data breach.
1. Respond. The organization should execute its mitigation procedures and contingency plans, such as fixing any technical issues or halting impermissible disclosure of protected health information.
2. Report crime. The organization should report the crime to law enforcement agencies, which may include local offices, the FBI and the Secret Service.
3. Share threat. The organization should report the cyberthreat to information sharing organizations, such as the Department of Homeland Security, the HHS Assistant Secretary for Preparedness and Response and relevant private-sector organizations.
4. Assess breach. The organization should investigate the incident to determine whether there was a breach of PHI. It must report any breaches affecting 500 or more individuals to OCR within 60 days.
Click to view the checklist and infographic.
More articles on health IT:
athenahealth to acquire Praxify
Mississippi Medicaid division notifies 5.2k individuals of privacy breach via unsecured online form
4 questions with Henry Ford Health System CIO Mary Alice Annecharico
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.