Breach Notification Laws Impose High Penalties

Data Breach

When there is a data security breach, there are state and federal data breach notification laws that places time limits on when those who are affected must be notified. A failure to make a timely notification of the data breach can be quite costly. Several state data breach notification laws and some federal data breach notification laws, such as the Health Insurance Portability and Accountability Act (HIPAA), impose civil fines for untimely notification.

It is important for data breaches to be reported to those who may have been affected in a timely manner, so that those with exposed personal data can take steps to protect themselves from further harm. The sooner a person with compromised data learns about a privacy breach, the sooner steps can be taken to mitigate any possible repercussions of the data exposure, such as checking credit reports and obtaining credit or identify theft monitoring services.

An Illinois Health System Slammed With Settlement for Slow Notification

According to a recent article on Bloomberg BNA, an Illinois Health System was recently saddled with a hefty settlement after taking too long to report a data breach to the proper entities under the breach notification laws of HIPAA. Presence Health learned that it had been subject to a data breach involving paper records in October of 2013, but waited until early February 2014 before reporting the data breach to those who were affected. This nearly four-month delay well exceeded the 60-day window to make notifications under the breach notification laws of HIPAA.

Data breaches are not to be taken lightly in Illinois, particularly when the data breach involves confidential patient information. Presence Health claims that the notification delay was due to a miscommunication and made no admission of liability when it agreed to pay $475,000 in its recent HIPPA settlement. In addition to the money, Presence Health also agreed to provide a two-year corrective action plan.

The HIPAA Breach Notification Rule, codified as 45 CFR §§ 164.400414, requires HIPAA covered entities and their business associates to issue notifications to those affected by a data breach within 60 days of the discovery of the data breach. The notification must further include:

  • An explanation of the breach, identification of the type of data that was compromised in the breach,
  • Information on how those affected by the breach can take steps to protect themselves,
  • An explanation of what the HIPAA covered entities or the business associates is doing to address and correct the data breach, and
  • Contact information so that those who are affected by the breach can learn more information.  

Consult With a Data Breach Lawyer

There is no time to lose once a data security breach has been identified. A majority of states have data breach notification laws that set forth specific timeframes in which notifications need to be made. There are costly consequences for those entities who do not take notification of data breach situations seriously. 

Extra, Extra!
Recent Posts

Does the AI-Copyright Legal Fight Represent a National Security Threat?

Does the AI-Copyright Legal Fight Represent a National Security Threat?

Copyright

The holders of copyrights for newspapers, magazines, books, and other publications are involved in numerous legal battles with owners of AI modules over alleged copyright infringement. The plaintiff copyright owners claim that the AI large language modules have been trained on huge quantities of copyrighted materials without permission and — most importantly — without payment. […]

Read more about Does the AI-Copyright Legal Fight Represent a National Security Threat?

How Does Buy-Sell Insurance Work For An Owners’ Agreement?

How Does Buy-Sell Insurance Work For An Owners’ Agreement?

Corporate

The owners of most small, closely-held businesses negotiate and sign some form of an “Owner’s Agreement.” An important part of such Agreements is the “Buy-Sell” provisions. These are often some of the most difficult to negotiate. The gist of the buy-sell part of the Owners’ Agreement is to establish the rules for what happens if […]

Read more about How Does Buy-Sell Insurance Work For An Owners’ Agreement?

Status on Social Media Moderation Statutes and Cases

Status on Social Media Moderation Statutes and Cases

Internet Law

Social media content moderation by technology platforms was one of the “hot” legal topics in 2023-2024. Three States — California, Texas, and Florida — passed different statutes to either require more content moderation (California) or to limit such moderation (Texas and Florida). All the statutes, in one way or another, demanded more transparency and information […]

Read more about Status on Social Media Moderation Statutes and Cases

Put Revision Legal on your side