29
Navigating States & HIPAA Breach Notification Compliance March 17, 2020 11:00 am PT / 2:00 pm ET

Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

  • Upload
    others

  • View
    4

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Navigating States & HIPAA Breach Notification Compliance

March 17, 202011:00 am PT / 2:00 pm ET

Page 2: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Today’s Speakers:

Welcome & Introductions

Doug KrugerVP Business Development

RadarFirst

Adam GreenePartner

Davis Wright Tremaine, LLP

Page 3: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Agenda

● Keeping up with complexities of breach notification regulations● 2019 state breach notification regulatory trends● OCR & State AGs enforcement trends● Unified framework for incident response lifecycle● Healthcare benchmarking stats● Automation in incident response● Questions & Answers

Page 4: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Complex regulatory landscape

Specified and reduced timelines for breach notifications worldwide

Page 5: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Growing breach regulations - 2019 U.S. activity

● 15 new laws or amendments went into effect that impacted breach notification obligations

○ 4 new, 11 amendments

● 4 additional laws or amendments went into effect Jan 1, 2020

Page 6: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

State breach notification law trends

Expanding scope of personal info

Specifiedtimeline

Specified contents

Attorney General

● Arkansas● Delaware● New Jersey● New York● Ohio● South Carolina● Virginia

● Delaware (60 days)

● Maine (30 days)

● Delaware● Massachusetts● New Jersey● New York● Ohio● South Carolina

● Arkansas● Massachusetts● New York● Maryland

Page 7: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Challenging interplay between state & federal

● State breach laws and HIPAA fall under three categories:○ Complete exemption from the state law○ Partial exemption○ No exemption

● Is AG notification required even if otherwise exempt?

● What is timing of notification to the state? Same as HIPAA or sooner?

● Legislative jurisdiction: When are you subject to a state’s notification law?

Page 8: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Breaches affecting 500+ Individuals

Source: U.S. Department of HHS OCR, 29th National HIPAA Summit, Update from HHS OCR

Page 9: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

500+ Breaches by Type of Breach

Source: U.S. Department of HHS OCR, 29th National HIPAA Summit, Update from HHS OCR

Page 10: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Breaches affecting 500+ - Reports involving hacking/IT incidents

Source: U.S. Department of HHS OCR, 29th National HIPAA Summit, Update from HHS OCR

Page 11: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

2019 OCR enforcement actions

4/2019 Touchstone Medical Imaging $3,000,000

4/2019 Medical Informatics Engineering $100,000

9/2019 Bayfront Health St. Petersburg $85,000

9/2019 Elite Dental Associates $10,000

10/2019 Jackson Health System (CMP) $2,154,000

10/2019 Texas Health and Human Services Commission (CMP) $1,600,000

10/2019 University of Rochester Medical Center $3,000,000

11/2019 Sentara Hospitals $2,175,000

12/2019 Korunda Medical $85,000

12/2019 West Georgia Ambulance $65,000

Source: U.S. Department of HHS OCR, 29th National HIPAA Summit, Update from HHS OCR

Page 12: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

OCR enforcement action

Source: U.S. Department of HHS OCR, Nov 26, 2019 Agreement, Sentara

● Understanding definition of PHI and knowing your notification obligations is critical

● “Sentara concluded, incorrectly, that unless the disclosure included patient diagnosis, treatment information or other medical information, no reportable breach of PHI had occurred.”

Page 13: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

OCR enforcement action

“HIPAA compliance depends on accurate and timely self-reporting of breaches because patients and the public have a right to know when sensitive

information has been exposed.” - Roger Severino, OCR Director.

“When health care providers blatantly fail to report breaches as required by law, they should expect vigorous enforcement action by OCR.”

Source: U.S. Department of HHS OCR, Nov 26, 2019 Agreement, Sentara

Page 14: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Mature incident response process

What does it mean to build an effective incident response program?

Defensible You must be able to show consistent, objective, multi-factor risk assessments and well-documented criteria for your decisions whether to notify or not.

Up-to-date & Comprehensive

Your risk assessment and response needs to take into account all laws and regulations that may be applicable to each separate incident.

Timely & CompliantYour team needs to consistently arrive at a compliant notification decision that is in time to meet compliance deadlines for all applicable regulation and jurisdiction.

Page 15: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Proactive incident response program

What does it mean to build a proactive incident response program?

● You’re thinking ahead, anticipating what will happen and taking action ahead of time.

● Document each step that will be taken and practice with all the key players involved.

● Practice practice practice - so everyone is very clear on what to do and when. Becomes muscle memory.

Page 16: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

The incident response lifecycle

Preparedness

Page 17: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Identify & Investigate

The clock begins ticking for the IR team to investigate the incident, involve appropriate stakeholders, and capture enough information to drive an accurate risk assessment.

Identify & Investigate

Assess Decide Notify Analyze

Page 18: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Risk Assess & Decide

The ability to demonstrate a consistent approach is a critical factor in making defensible notification decisions to regulators.

Identify & Investigate

Assess Decide

Notify Analyze

+

Page 19: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Notify

If you determine that notification is required, your privacy and legal teams have to be ready to quickly generate notification letters to individuals, regulatory agencies, and data protection authorities, as well as track responses and document their efforts.

Identify & Investigate

Assess Decide

Notify

Analyze

Page 20: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Analyze

The time after an incident is also the time before the next incident - time you can use to evaluate and improve your incident response process and to pinpoint and fix gaps.

Analyze

Identify & Investigate

Assess Decide Notify

Page 21: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Incident lifecycle time periods (days)

2019 BakerHostetler Report:

● Occurrence to discovery = 66 days

● Discovery to notify = 56 days

Page 22: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

% of on time notifications

Page 23: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Electronic vs Paper vs Verbal/Visual

Page 24: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Is there a reasonable notification rate?

• Sufficient risk mitigation is crucial in reducing risk of harm

• Consistent and objective multi-factor risk assessment provides the necessary proof of compliance.

Page 25: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Simplify compliance with automation

Radar provides consistency and efficiency by operationalizing incident response:1. Simplify incident escalation & details2. Quickly assess whether an incident requires notification3. Manage third party data processing notification obligations4. Monitor trends and measure program metrics5. Provide proof of compliance

Page 26: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Real-time trend analysis and dashboards

Benchmarking provides Radar users the ability to view and analyze a number of metricsin comparison to their industry.

Radar users can select a specific industry with predefined date ranges.

● Allows users to quickly establish internal metric-driven goals

● Helps organizations understanding and improve operational efficiencies

Page 27: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Stay current with changing breach laws

Free Law Overview Tool ● Access up to-date overview of global breach notification laws (including CCPA and GDPR)

● Remain informed of US federal and state incident risk assessment and reporting requirements for data breaches

radarfirst.com/breach-law-library

Page 28: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Today’s Speakers:

Questions & Answers

Doug KrugerVP Business Development

RadarFirst

Adam GreenePartner

Davis Wright Tremaine, LLP

Page 29: Navigating States & HIPAA Breach Notification Compliance · 2019 state breach notification regulatory trends OCR & State AGs enforcement trends Unified framework for incident response

Thank You