Security News > 2020 > January > Health Data Breach Not Reported for Seven Months

Health Data Breach Not Reported for Seven Months
2020-01-27 21:03

Under HIPAA, covered entities are required to report breaches impacting protected health information within 60 days of discovering the breach.

In its breach notification statement, PIH Health says that on June 18, 2019, it learned that certain PIH Health employee email accounts had potentially been accessed without authorization as a result of a targeted phishing campaign.

"PIH Health then worked diligently to identify contact information for all potentially affected individuals in order to provide them with notice of the incident." The incident was then reported to HHS nearly two months later.

"We don't yet know why PIH Health took four months to understand the June attack was a breach of unsecured PHI, or took almost two more months to report the breach to OCR," notes independent HIPAA attorney Paul Hales.

The HITECH Act mandates that covered entities notify individuals of a health data breach without unreasonable delay but in no case later than 60 days from the discovery of the breach, except where law enforcement has requested a delay.


News URL

https://www.inforisktoday.com/health-data-breach-reported-for-seven-months-a-13652

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Health 2 1 6 1 0 8