When the PHI of a patient has been breached or disclosed, the entity must notify the concerned patient about the breach. This action falls under the HIPAA Breach Notification Rule.
According to the Rule, any kind of breach is considered a breach unless the entity claims the probability of PHI being compromised is low.
Even if a particular breach meets the HIPAA’s low probability of compromise threshold, a physician should run a test to make sure that PHI has not been compromised.
They must perform the following steps:
These four steps are only required when an entity is not sure whether or not the PHI has been completely compromised. If the PHI is completely compromised, the Breach Notification Rule must be applied immediately.