{"id":24495,"date":"2020-09-22T06:56:28","date_gmt":"2020-09-22T06:56:28","guid":{"rendered":"https:\/\/www.process.st\/templates\/hipaa-security-breach-reporting-checklist\/"},"modified":"2024-02-29T02:55:12","modified_gmt":"2024-02-29T02:55:12","slug":"hipaa-security-breach-reporting-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/hipaa-security-breach-reporting-checklist\/","title":{"rendered":"HIPAA Security Breach Reporting Checklist"},"content":{"rendered":"<section id=\"introduction\">\n<h2>Introduction:<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/hDT6SXOoQkgXbR-H-hdIYQ.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/hDT6SXOoQkgXbR-H-hdIYQ.png\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Security <strong>breaches in the healthcare industry<\/strong> are, unfortunately, <strong>all too common.<\/strong><\/p>\n<p><em>\"Between 2009 and 2019 there have been 3,054 healthcare data breaches involving more than 500 records. Those breaches have resulted in the loss, theft, exposure, or impermissible disclosure of 230,954,151 healthcare records. That equates to more than 69.78% of the population of the United States. In 2019, healthcare data breaches were reported at a rate of 1.4 per day.\"<\/em> - <a href=\"https:\/\/www.hipaajournal.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal<\/a>, <a href=\"https:\/\/www.hipaajournal.com\/healthcare-data-breach-statistics\/\" rel=\"nofollow noopener\" target=\"_blank\">Healthcare Data Breach Statistics<\/a><\/p>\n<p>With the risk of breach being so high, its imperative that both covered entities and business associates take the appropriate measures to<strong> identify and report breaches as early as possible.<\/strong><\/p>\n<p>Currently, the figures suggest that not enough is being done.<\/p>\n<p><em>\"What\u2019s worse is that it took the breached US organizations an average of 245 days to identify and contain a breach. However, the report tied breach response directly to cost saving. Organizations that detected and contained the breach in less than 200 days spent $1.2 million less on total breach costs.\" - <\/em><a href=\"https:\/\/twitter.com\/jf_davis_?lang=en\" rel=\"nofollow noopener\" target=\"_blank\">Jessica Davis<\/a>,&nbsp;<a href=\"https:\/\/healthitsecurity.com\/news\/data-breaches-cost-healthcare-6.5m-or-429-per-patient-record\" rel=\"nofollow noopener\" target=\"_blank\">Data Breaches Cost Healthcare $6.5M, or $429 Per Patient Record<\/a><\/p>\n<p>This checklist template has been built to help you identify and report data breaches as efficiently as possible.<\/p>\n<p>Our <a href=\"https:\/\/www.process.st\/help\/docs\/dynamic-due-dates\/\" rel=\"nofollow noopener\" target=\"_blank\">dynamic due dates<\/a> feature will ensure that you file a notice to the secretary of the HHS within 60 days, while <a href=\"https:\/\/www.process.st\/help\/docs\/conditional-logic\/\" rel=\"nofollow noopener\" target=\"_blank\">conditional logic<\/a> will <strong>automatically customize the checklist<\/strong> depending on whether you are the covered entity or a business associate, and whether the breach affected more or less than 500 individuals.<\/p>\n<p>Lets get going!<\/p>\n<h4>A little info about Process Street<\/h4>\n<p>Process Street is&nbsp;<strong>superpowered checklists<\/strong>. By using our software to document your processes, you are instantly creating an actionable workflow in which tasks can be assigned to team members, automated, and monitored in real-time to ensure they are being executed as intended, each and every time.<\/p>\n<p>The point is to&nbsp;<strong>minimize human error, increase accountability<\/strong>, and&nbsp;<strong>provide employees with all of the tools and information necessary<\/strong>&nbsp;to complete their tasks as effectively as possible.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"enter-basic-details\">\n<h2>Enter basic details<\/h2>\n<div class=\"text-content\">\n<p>First, enter some <strong>basic details regarding your organization <\/strong>and the<strong> individual responsible for managing IT security.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Company Address <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Head of IT Security - Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Are you the covered entity or a business associate? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"identification\">\n<h2>Identification:<\/h2>\n<\/section>\n<section id=\"provide-a-summary-of-how-the-breach-was-discovered\">\n<h2>Provide a summary of how the breach was discovered<\/h2>\n<div class=\"text-content\">\n<p>In the form field below, provide a <strong>concise summary of how the breach was initially discovered.&nbsp;<\/strong><\/p>\n<p class=\"style-info\">This should be written by the individual who discovered the breach, or transcribed as it is described verbally.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Summary of how the breach was discovered <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"state-the-nature-and-extent-of-the-phi-involved\">\n<h2>State the nature and extent of the PHI involved<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/j7kyX6TZBtw8H2ZyLD9I4w.jpg\" alt=\"State the nature and extent of the PHI involved\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/j7kyX6TZBtw8H2ZyLD9I4w.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Detail the<strong> nature and extent of the PHI involved.<\/strong>&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Nature and extent of the PHI involved <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"detail-the-unauthorized-person-to-whom-the-disclosure-was-made\">\n<h2>Detail the unauthorized person to whom the disclosure was made<\/h2>\n<div class=\"text-content\">\n<p>Provide basic details regarding the <strong>unauthorized individual<\/strong> who <strong>used the PHI or to whom the disclosure was made.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\"> <label> Unauthorized Person - Name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Unauthorized Person - Other known details <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"determine-whether-the-phi-was-acquired-or-viewed\">\n<h2>Determine whether the PHI was acquired or viewed<\/h2>\n<div class=\"text-content\">\n<p>Determine whether the PHI was actually<strong> acquired or viewed<\/strong> by the unauthorized person.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Was the PHI acquired or viewed? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"determine-if-500-or-more-individuals-were-affected\">\n<h2>Determine if 500 or more individuals were affected<\/h2>\n<div class=\"text-content\">\n<p>A covered entity\u2019s breach notification <strong>obligations differ based on whether the breach affects 500 or more individuals<\/strong> or fewer than 500 individuals.&nbsp;<\/p>\n<p class=\"style-warning\">If the number of individuals affected by a breach is uncertain at the time of submission, the covered entity should provide an estimate.<\/p>\n<h4>Breaches affecting 500 or more individuals<\/h4>\n<p>If a breach of unsecured protected health information affects 500 or more individuals, a <strong>covered entity must notify the Secretary of the breach without unreasonable delay and in no case later than 60 calendar days<\/strong> from the discovery of the breach.<\/p>\n<h4>Breaches affecting fewer than 500 individuals<\/h4>\n<p>A covered entity <strong>must notify the Secretary of the breach within 60 days of the end of the calendar year<\/strong> in which the breach was discovered. (A covered entity is not required to wait until the end of the calendar year to report breaches affecting fewer than 500 individuals; a covered entity may report such breaches at the time they are discovered.)<\/p>\n<p>The covered entity <strong>may report all of its breaches affecting fewer than 500 individuals on one date<\/strong>, but the covered entity <strong>must complete a separate notice for each breach incident<\/strong>.<\/p>\n<hr>\n<p class=\"style-info\">Check out <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/breach-notification\/breach-reporting\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">this HHS.gob web page<\/a>&nbsp;for more information on submitting a notice of breach to the secretary<\/p>\n<\/p><\/div>\n<div class=\"select-field-content form-field-content\">\n<div class=\"form-group\"> <label> Did the breach affect more or less than 500 individuals? <\/label> <select disabled class=\"form-control\"><option value=\"An option will be selected here\">An option will be selected here<\/option><\/select>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-breach-correctly-identified\">\n<h2>Approval: Breach correctly identified<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Provide a summary of how the breach was discovered<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">State the nature and extent of the PHI involved<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Detail the unauthorized person to whom the disclosure was made<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Determine whether the PHI was acquired or viewed<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Determine if 500 or more individuals were affected<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"risk-mitigation-measures\">\n<h2>Risk mitigation measures:<\/h2>\n<\/section>\n<section id=\"detail-the-extent-to-which-the-risk-to-the-phi-has-been-mitigated\">\n<h2>Detail the extent to which the risk to the PHI has been mitigated<\/h2>\n<div class=\"text-content\">\n<p>In the form field below, detail the extent to which the risk to the PHI has been mitigated.&nbsp;<\/p>\n<p><em>What measures have been taken to minimize damage as a result of the breach?<\/em><\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Extent to which the risk of damage has been mitigated <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"reporting\">\n<h2>Reporting:<\/h2>\n<\/section>\n<section id=\"notify-the-covered-entity-within-60-days\">\n<h2>Notify the covered entity within 60 days<\/h2>\n<div class=\"image-content\">\n<figure> <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ldA3KQY2SM1oBY0uBiNCNA.jpg\" alt=\"Notify the covered entity within 60 days\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/ldA3KQY2SM1oBY0uBiNCNA.jpg\"> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>As a business associate, you have an<strong> obligation to notify the covered entity of the breach within 60 days<\/strong> of its discovery.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"text-content\">\n<p class=\"style-info\">Although the responsibility falls onto covered entities to notify affected individuals, <strong>they may assign their business associates, where appropriate, to inform the affected individuals.<\/strong> This is based on factors such as which organization deals directly with the individuals and what functions the business associate performs for the covered entity.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Details regarding how and when the covered entity was notified <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"file-the-notice-to-the-secretary-of-the-hhs\">\n<h2>File the notice to the Secretary of the HHS<\/h2>\n<div class=\"text-content\">\n<p>The covered entity <strong>must submit the notice electronically by clicking on the link below<\/strong> and completing all of the fields of the breach notification form.<\/p>\n<hr>\n<p class=\"style-success\">Link: <a href=\"https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_form.jsf\" rel=\"nofollow noopener\" target=\"_blank\"><strong>https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_form.jsf<\/strong><\/a><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"file-the-notice-to-the-secretary-of-the-hhs-within-60-days\">\n<h2>File the notice to the Secretary of the HHS (within 60 days)<\/h2>\n<div class=\"text-content\">\n<p>Due to the fact that the breach has <strong>affected more than 500 individual<\/strong>s, you have <strong>60 days to notify<\/strong> the Secretary.<\/p>\n<p>The covered entity <strong>must submit the notice electronically by clicking on the link below<\/strong> and completing all of the required fields of the breach notification form.<\/p>\n<hr>\n<p class=\"style-success\">Link: <a href=\"https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_form.jsf\" rel=\"nofollow noopener\" target=\"_blank\"><strong>https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_form.jsf<\/strong><\/a><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"final-steps\">\n<h2>Final steps:<\/h2>\n<\/section>\n<section id=\"ensure-all-breach-documentation-is-safely-stored\">\n<h2>Ensure all breach documentation is safely stored<\/h2>\n<div class=\"text-content\">\n<p>Ensure all of the breach documentation is<strong> safely stored.&nbsp;<\/strong><\/p>\n<p class=\"style-danger\">This is critical as there may be <strong>investigations or legal proceedings in the future,<\/strong> for which the covered entity must be able to present documentation regarding the breach and how it was managed.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\"> <label> Description of measures taken to ensure safe storage of breach documentation <\/label> <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval-breach-report-filed\">\n<h2>Approval: Breach report filed<\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\"> <span class=\"title\">Ensure all breach documentation is safely stored<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/cloudapper.com\/\" rel=\"nofollow noopener\" target=\"_blank\">CloudApper<\/a> - <a href=\"https:\/\/cloudapper.com\/hipaa-breach-notification-checklist-ensure-compliance\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Breach Notification Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.hipaajournal.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Journal<\/a> - <a href=\"https:\/\/www.hipaajournal.com\/hipaa-compliance-checklist\/#:~:text=Breach%20notifications%20should%20include%20the,or%20viewed%20(if%20known).\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.hhs.gov\/\" rel=\"nofollow noopener\" target=\"_blank\">HHS<\/a> - <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/breach-notification\/breach-reporting\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">Submitting Notice of Breach to the Secretary<\/a><\/li>\n<li><a href=\"https:\/\/healthitsecurity.com\/\" rel=\"nofollow noopener\" target=\"_blank\">HealthITSecurity<\/a> - <a href=\"https:\/\/healthitsecurity.com\/features\/how-to-comply-with-the-hipaa-breach-notification-rule\" rel=\"nofollow noopener\" target=\"_blank\">How to Comply with the HIPAA Breach Notification Rule<\/a><\/li>\n<li><a href=\"https:\/\/www.cms.gov\/\" rel=\"nofollow noopener\" target=\"_blank\">Centers for Medicare &amp; Medicaid Services<\/a> - <a href=\"https:\/\/www.cms.gov\/outreach-and-education\/medicare-learning-network-mln\/mlnproducts\/downloads\/hipaaprivacyandsecuritytextonly.pdf\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Basics for Providers: Privacy, Security, and Breach Notification Rules<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist for HR<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-omnibus-rule-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Omnibus Rule Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-privacy-risk-assessment-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Privacy Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-business-associate-agreement-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Business Associate Agreement Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-data-backup-plan-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Data Backup Plan Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Medical Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Intake Checklist for a Dental Clinic<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist-for-hr\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-housekeeping-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Housekeeping Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/terminal-room-cleaning-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Terminal Room Cleaning Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hospital-safety-inspection-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Hospital Safety Inspection Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/general-infection-control-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">General Infection Control Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/patient-satisfaction-survey-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Patient Satisfaction Survey Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/home-visit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Home Visit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/mental-health-risk-assessment-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Mental Health Risk Assessment Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/who-surgical-safety-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">WHO Surgical Safety Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/hipaa-compliance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">HIPAA Compliance Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-isolation-area-management\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Isolation Area Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-covid-19-isolation-ward-area\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for COVID-19 Isolation Ward Area<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-lung-transplantation-pre-transplantation-assessment\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Lung Transplantation Pre-Transplantation Assessment<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-nursing-care-during-treatment-alss\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Nursing Care During Treatment (ALSS)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-protocol-for-donning-and-removing-ppe\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Protocol for Donning and Removing PPE<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-staff-management-workflow-and-health\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Staff Management (Workflow and Health)<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-daily-management-and-monitoring-of-ecmo-audit\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Daily Management and Monitoring of ECMO Audit<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-digital-support-for-epidemic-prevention-and-control\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Digital Support for Epidemic Prevention and Control<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-discharge-standards-and-follow-up-plan-for-covid-19-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Discharge Standards and Follow-up Plan for COVID-19 Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-of-covid-19-related-reusable-medical-devices\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection of COVID-19 Related Reusable Medical Devices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disinfection-procedures-for-infectious-fabrics-of-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disinfection Procedures for Infectious Fabrics of Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-covid-19-related-medical-waste\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for COVID-19 Related Medical Waste<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-disposal-procedures-for-spills-of-covid-19-patient-blood-fluids\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Disposal Procedures for Spills of COVID-19 Patient Blood\/Fluids<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-handling-bodies-of-deceased-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Handling Bodies of Deceased Suspected or Confirmed Patients<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-procedures-for-taking-remedial-actions-against-occupational-exposure-to-covid-19\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Procedures for Taking Remedial Actions against Occupational Exposure to COVID-19<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/covid-19-procedure-surgical-operations-for-suspected-or-confirmed-patients\/\" rel=\"nofollow noopener\" target=\"_blank\">COVID-19 Procedure: Surgical Operations for Suspected or Confirmed Patients<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: Security breaches in the healthcare industry are, unfortunately, all too common. \"Between 2009 and 2019 there have been 3,054 healthcare data breaches involving more than 500 records. Those breaches have resulted in the loss, theft, exposure, or impermissible disclosure of 230,954,151 healthcare records. That equates to more than 69.78% of the population of the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":24496,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"20","template_description":"Run this checklist to report a security breach at your medical institution","template_id":"s17vu5t7e78THVX7039J8w","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Enter basic details","task_slug_1":"enter-basic-details","task_2":"Identification:","task_slug_2":"identification","task_3":"Provide a summary of how the breach was discovered","task_slug_3":"provide-a-summary-of-how-the-breach-was-discovered","task_4":"State the nature and extent of the PHI involved","task_slug_4":"state-the-nature-and-extent-of-the-phi-involved","task_5":"Detail the unauthorized person to whom the disclosure was made","task_slug_5":"detail-the-unauthorized-person-to-whom-the-disclosure-was-made","task_6":"Determine whether the PHI was acquired or viewed","task_slug_6":"determine-whether-the-phi-was-acquired-or-viewed","task_7":"Determine if 500 or more individuals were affected","task_slug_7":"determine-if-500-or-more-individuals-were-affected","task_8":"Approval: Breach correctly identified","task_slug_8":"approval-breach-correctly-identified","task_9":"Risk mitigation measures:","task_slug_9":"risk-mitigation-measures","task_10":"Detail the extent to which the risk to the PHI has been mitigated","task_slug_10":"detail-the-extent-to-which-the-risk-to-the-phi-has-been-mitigated","task_11":"Reporting:","task_slug_11":"reporting","task_12":"Notify the covered entity within 60 days","task_slug_12":"notify-the-covered-entity-within-60-days","task_13":"File the notice to the Secretary of the HHS","task_slug_13":"file-the-notice-to-the-secretary-of-the-hhs","task_14":"File the notice to the Secretary of the HHS (within 60 days)","task_slug_14":"file-the-notice-to-the-secretary-of-the-hhs-within-60-days","task_15":"Final steps:","task_slug_15":"final-steps","task_16":"Ensure all breach documentation is safely stored","task_slug_16":"ensure-all-breach-documentation-is-safely-stored","task_17":"Approval: Breach report filed","task_slug_17":"approval-breach-report-filed","task_18":"Sources:","task_slug_18":"sources","task_19":"Related checklists:","task_slug_19":"related-checklists","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[29,7],"tags":[],"class_list":["post-24495","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-healthcare","category-miscellaneous"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=24495"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/24495\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/24496"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=24495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=24495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=24495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}