Identify client notification protocols related to data breaches.
Identification should include notification methods such as
- first-class mail
- email, if appropriate
- posting notice on entity’s website for 90 days
- toll-free number
- time requirements.
Teacher Resource: Breach Notification Rule (https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html Links to an external site.), U.S. Department of Health and Human Services
Process/Skill Questions:
- What is the life cycle of a data breach? When and how does client notification take place?
- How can one develop a matrix to determine whether outsourcing the client notification process is more cost-effective than performing client notifications in house?