Breach Notification
Breach Notification. In the event of a breach of unsecured Protected Health Information (PHI), the Covered Entity shall notify each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of such breach, without unreasonable delay and in no case later than sixty (60) calendar days after the discovery of the breach, as required under 45 CFR 164.404. The notification shall include: (a) a brief description of what happened, including the date of the breach and the date of discovery; (b) a description of the types of unsecured PHI involved in the breach; (c) any steps the individual should take to protect themselves from potential harm resulting from the breach; (d) a brief description of what the Covered Entity is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches; and (e) contact procedures for individuals to ask questions, including a toll-free telephone number, e-mail address, website, or postal address. If a breach affects 500 or more individuals in a State or jurisdiction, the Covered Entity shall provide notice to prominent media outlets serving the State or jurisdiction and shall notify the Secretary of HHS contemporaneously with the individual notifications.