Downloadable HIPAA Notifications
As of September 23, 2009, all businesses covered by the HIPAA Act and any business that offers products or services that interact with protected health information are required to:
- Notify individuals when their health information has been breached
- Update their HIPAA privacy and security policies and procedures
- Train employees on updated procedures (including what to do if a breach occurs)
- HIPAA Notice of Security Breach
Use this form to notify affected individuals in the event of a security breach of protected health information — notice must include certain information including steps taken to prevent future breaches
- Business Associate Notice of Breach
Business associates must notify covered entities within 60 days of a breach — use this form to provide notice to covered entities
Insurance companies, doctors' offices and hospitals have additional obligations not covered by these products, such as training on patient rights.