agentsclimarketplace

Hipaa breach notify

Skill onfire7777/universal-ai-skills-library/skills/hipaa-breach-notify

Router-first AI skill system for Codex, Claude, Cursor, Hermes, Paperclip, OpenCode, and local AI stacks: search, preflight-route, and load 1,812 skills on demand without duplicating the corpus.

Install
npx -y skills add onfire7777/universal-ai-skills-library --skill hipaa-breach-notify

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 13 stars13 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Implements HIPAA breach notification requirements under 45 CFR §164.400-414. Covers individual notification within 60 days, HHS reporting thresholds (500+ immediate, under 500 annual), state attorney general notification, media notification for 500+ in a state, and breach risk assessment. Keywords: HIPAA breach notification, HHS reporting, OCR breach portal, individual notice, state attorney general.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

13.2 KB, as published. Nobody here has run it

HIPAA Breach Notification Rule — 45 CFR §164.400-414

Overview

The HIPAA Breach Notification Rule, added by the HITECH Act of 2009 and finalized in the Omnibus Rule of 2013 (78 FR 5566), requires covered entities and business associates to provide notification following a breach of unsecured protected health information (PHI). The rule establishes specific timeframes, content requirements, and reporting obligations that vary based on the number of individuals affected. Post-2013, the rule applies a presumption that any impermissible acquisition, access, use, or disclosure of PHI is a breach unless the covered entity demonstrates through a risk assessment that there is a low probability the PHI was compromised.

Definition of Breach — §164.402

What Constitutes a Breach

A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI.

Presumption of Breach

Under the 2013 Omnibus Rule, an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates through a four-factor risk assessment that there is a low probability that the PHI has been compromised.

Four-Factor Risk Assessment — §164.402(2)

FactorAssessment Questions
1. Nature and extent of PHI involvedWhat types of identifiers and clinical information were involved? Does the PHI include sensitive data (SSN, financial, substance abuse, mental health, HIV)? How many data elements were exposed?
2. Unauthorized person who used or received the PHIWho impermissibly accessed the PHI? Was it an unauthorized employee, an external attacker, an unintended recipient? Does the person have obligations to protect PHI (e.g., another covered entity)?
3. Whether the PHI was actually acquired or viewedWas the PHI actually accessed or viewed, or was there only an opportunity for access? Are there forensic logs demonstrating whether data was exfiltrated? Was an encrypted laptop stolen but the encryption verified as NIST-compliant?
4. Extent to which the risk has been mitigatedWere satisfactory assurances obtained from the recipient that the PHI will not be further used or disclosed? Was the PHI recovered? Was the recipient a covered entity that has agreed to destroy the information?

If the risk assessment demonstrates low probability of compromise across all four factors, the incident is not a breach and notification is not required. The assessment must be documented regardless of the conclusion.

Exceptions to the Breach Definition — §164.402(1)

Three circumstances are excluded from the definition of breach:

  1. Unintentional good-faith acquisition: PHI acquired unintentionally by a workforce member or person acting under the authority of the covered entity or BA, made in good faith and within the scope of authority, and the PHI is not further used or disclosed impermissibly
  2. Inadvertent disclosure between authorized persons: PHI inadvertently disclosed by a person authorized to access PHI to another person authorized to access PHI at the same covered entity, BA, or organized healthcare arrangement, and the information is not further used or disclosed impermissibly
  3. Good-faith belief of non-retention: The covered entity or BA has a good-faith belief that the unauthorized person to whom the disclosure was made would not reasonably have been able to retain the information

Unsecured PHI — §164.402

Breach notification obligations apply only to "unsecured PHI" — PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through one of the technologies specified by HHS:

Safe Harbor Technologies (HHS Guidance, 74 FR 19006)

TechnologySpecification
EncryptionNIST-validated encryption processes consistent with NIST Special Publication 800-111 (data at rest) and FIPS 140-2/140-3 validated modules. AES-128 or AES-256 for data at rest; TLS 1.2+ for data in transit
DestructionPaper: shredding or destruction such that PHI cannot be read or reconstructed. Electronic media: clearing, purging, or destroying consistent with NIST SP 800-88 Rev. 1

If PHI was properly encrypted and the encryption key was not compromised, or if PHI was properly destroyed, then it is "secured" and the breach notification provisions do not apply.

Notification Requirements

Individual Notification — §164.404

Who must notify: The covered entity (not the business associate directly, unless delegated by the BA agreement).

Timeframe: Without unreasonable delay, and no later than 60 calendar days from the date of discovery of the breach. Discovery occurs on the first day the breach is known or, by exercising reasonable diligence, would have been known. Knowledge of a workforce member or agent is imputed to the covered entity.

Method: Written notice by first-class mail to the individual's last known address (or next of kin if deceased). Email is permitted if the individual has agreed to electronic notice. If contact information is insufficient or out of date for 10 or more individuals, a conspicuous posting on the covered entity's website for 90 days or a notice in major print or broadcast media is required.

Content requirements (§164.404(c)):

  1. A brief description of what happened, including the date of the breach and the date of discovery
  2. A description of the types of unsecured PHI involved (e.g., name, SSN, date of birth, diagnosis, treatment information — do not include the actual PHI)
  3. Steps individuals should take to protect themselves from potential harm
  4. A brief description of what the covered entity is doing to investigate, mitigate harm, and prevent future breaches
  5. Contact procedures including a toll-free telephone number, email address, postal address, or website

Asclepius Health Network Individual Notice Template:

Asclepius Health Network maintains pre-approved breach notification letter templates reviewed by legal counsel, with variable fields for breach-specific details. The template includes:

  • Description of the incident
  • Types of information involved
  • Steps Asclepius has taken (investigation, remediation, enhanced safeguards)
  • Offer of complimentary credit monitoring and identity theft protection services (24 months for breaches involving SSN or financial data)
  • Toll-free call center number staffed by trained representatives
  • Instructions for placing fraud alerts and security freezes
  • Contact information for the Asclepius Privacy Office, HHS OCR, and relevant state attorney general

HHS Secretary Notification — §164.408

Breach SizeReporting RequirementTimeframeMethod
500+ individualsIndividual report to HHSWithout unreasonable delay, no later than 60 days from discovery (concurrent with individual notification)HHS breach reporting portal (ocrportal.hhs.gov)
Fewer than 500 individualsLog and report annuallyWithin 60 days of end of calendar year in which breach was discoveredHHS breach reporting portal — annual breach log submission

Breaches affecting 500 or more individuals are posted on the HHS "Wall of Shame" — the public breach reporting portal at ocrportal.hhs.gov/ocr/breach/breach_report.jsf.

HHS Portal Required Fields:

  • Covered entity name, address, contact information
  • Covered entity type (health plan, healthcare provider, healthcare clearinghouse, BA acting as agent)
  • Number of individuals affected
  • Date of breach, date of discovery
  • Type of breach (hacking/IT incident, unauthorized access/disclosure, theft, loss, improper disposal, other)
  • Location of breached information (email, electronic medical record, network server, paper/films, laptop, desktop, portable device, other)
  • Type of PHI involved
  • Description of breach
  • Safeguards in place at time of breach
  • Actions taken in response

State Attorney General Notification — §13402(e)(3) HITECH

For breaches affecting 500 or more residents of a state or jurisdiction, the covered entity must notify the state attorney general concurrent with individual notification.

Asclepius Health Network operates across 4 states. If a breach affects 500+ residents of any single state, the AG of that state must be notified. Many states have their own breach notification laws with additional requirements; Asclepius tracks requirements across all 50 states and files notifications as required.

Media Notification — §164.406

For breaches affecting 500 or more residents of a state or jurisdiction, the covered entity must provide notice to prominent media outlets serving the state or jurisdiction without unreasonable delay and no later than 60 days from discovery. This is typically accomplished through a press release distributed to major media outlets in the affected area.

Business Associate Breach Obligations — §164.410

Business associates must:

  1. Notify the covered entity of a breach without unreasonable delay and no later than 60 days from discovery (or shorter if specified in the BAA)
  2. Identify affected individuals to the extent possible
  3. Provide information the covered entity needs to fulfill its notification obligations

The covered entity retains responsibility for individual, HHS, state AG, and media notification unless the BAA delegates notification to the BA. Asclepius Health Network BAAs require BA breach notification within 5 business days of discovery and require the BA to bear notification costs when the breach results from the BA's acts or omissions.

Breach Response Timeline — Asclepius Health Network

DayActionResponsible Party
Day 0Incident detected or reportedWorkforce member, IT security, BA
Day 0-1Incident response team activated; containment initiatedCISO, Incident Response Team
Day 1-7Forensic investigation; scope and nature of PHI determinedForensic investigators (internal or third-party)
Day 7-14Four-factor risk assessment completed; breach determination madePrivacy Officer, Legal Counsel
Day 14-21If breach confirmed: notification letters drafted, reviewed by legal, call center preparedPrivacy Office, Legal, Communications
Day 21-30Notification letters mailed; HHS portal submission preparedPrivacy Office, Compliance
Day 30-45HHS notified; state AG notified (if 500+ in a state); media notified (if 500+ in a state)Compliance, Legal
Day 45-60Substitute notice posted if needed; call center operational; credit monitoring enrollment trackedPrivacy Office, Vendor Management
Within 60 daysAll individual notifications completed (hard deadline)Privacy Office
OngoingRemediation measures implemented; risk analysis updated; workforce re-trainedCISO, Privacy Office, Training

Documentation Requirements — §164.414(b)

Covered entities must maintain documentation of breach risk assessments, notifications, and related actions for a minimum of 6 years from the date of creation or the date when the document was last in effect, whichever is later. This includes:

  • Breach risk assessment and determination
  • Individual notification copies and mailing records
  • HHS notification records
  • State AG notification records
  • Media notification records
  • Remediation documentation
  • Workforce sanctions applied

Enforcement Actions for Breach Notification Failures

  • Presence Health (2017): $475,000 — delayed breach notification by over 100 days beyond the 60-day deadline for breach affecting 836 individuals
  • Cottage Health (2019): $3 million — failure to conduct thorough risk assessment prior to breach; inadequate security measures contributing to breach of 62,500 records
  • Lafourche Medical Group (2023): $480,000 — phishing breach affecting approximately 34,862 individuals; failure to conduct risk analysis and implement security measures; late breach notification

Integration Points

  • hipaa-privacy-rule: Breach is defined as impermissible use/disclosure under the Privacy Rule
  • hipaa-security-rule: Security safeguards determine whether PHI is "unsecured" for notification purposes
  • hipaa-risk-analysis: Post-breach risk analysis update required; breach risk assessment is related but distinct from Security Rule risk analysis
  • hipaa-baa-management: BAA breach notification provisions define BA obligations
  • hitech-act-privacy: HITECH established the breach notification requirement and penalty tiers

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.