Swamped with your writing assignments? Take the weight off your shoulder!
As the Privacy and Security Officer for your facility, you are responsible for creating a breach notification letter. This letter is sent to patients whose PHI has been compromised in the breach. According to federal regulations, the breach notification letter must contain five required elements addressed in a customized manner according to the situational circumstances and consisting of:
1. A brief descriiption of what happened, including the date of the breach and the date of the discovery of the breach, if known.
2. A descriiption of the types of unsecured PHI that were involved in the breach (i.e., full name, Social Security number, date of birth, home address, account number, diagnosis, or disability code).
3. Any steps individuals should take to protect themselves from potential harm resulting from the breach.
4. A brief descriiption of what the organization is doing to investigate the breach, to mitigate harm to the individuals, and to protect against any further breaches.
5. Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Website, or postal address If appropriate. The organization may include other customized information, including:
-Information about steps the organization is taking to prevent future similar breaches
-Information about sanctions the organization imposed on workforce members involved in the breach; Identity of workforce members should be on a need-to-know basis according to organizational policy
-Consumer advice directing the individual to review account statements and monitor credit reports
-Recommendations that the individual place a fraud alert on their credit card accounts, or contact a credit bureau to obtain credit monitoring services, if appropriate
-Contact information for credit reporting agencies, including the information needed for reports for criminal investigation and law enforcement
-Contact information for national consumer reporting agencies.
Create a letter that incorporates the five require elements, and also include all six of the subcategories of information found in item #5.
***Your scenario is based on the actual breach case of the Affinity Health Plan in 2013 (Breach Case – FOR IMMEDIATE RELEASE.pdf Download Breach Case – FOR IMMEDIATE RELEASE.pdf).
*You will need to make up the specifics about your health care organization (email address, website, phone number, address…) but use the case for specifics about the breach event.
*Do not copy and paste information found on the internet or during your research. Include all references in APA format on a separate Reference Page in your document. Please review the rubric to ensure that your assignment meets criteria.
Breach Letter in Word or PDF format.