Identify client notification protocols related to data breaches.

Identification should include notification methods such as

  • first-class mail
  • email, if appropriate
  • posting notice on entity’s website for 90 days
  • toll-free number
  • time requirements.

Teacher Resource: Breach Notification Rule (https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html Links to an external site.), U.S. Department of Health and Human Services

Process/Skill Questions:

  • What is the life cycle of a data breach? When and how does client notification take place?
  • How can one develop a matrix to determine whether outsourcing the client notification process is more cost-effective than performing client notifications in house?