How do you compare to your peers?
If you pride yourself on your spotless HIPAA record, you may want to reconsider.
In announcing increased scrutiny of small breach report cases (see story, p. 281), the HHS Office for Civil Rights also states that its regional offices may consider whether or not a Covered Entity (CE) or Business Associate (BA) has any breach reports impacting fewer than 500 individuals when compared with other CEs or BAs, according to Chicago-based attorney Valerie Breslin Montague of Nixon Peabody. “This implies that it is not only breach reports that may trigger an investigation, but, likely for large systems or organizations, the lack thereof as compared to peer entities.”
“In other words, if everyone else like you reports breaches and you don’t, why not?” points out Jim Sheldon-Dean, founder and director of compliance services for Lewis Creek Systems.
Another layer to this change is that OCR has noted that it may consider the lack of breach reports for a region, suggesting that OCR is interested in investigating the possibility of under-reporting, notes New York City-based attorney Lindsay Borgeson of Epstein Becker & Green.