You are the HIPAA privacy official of a hospital or health plan (a covered entity under HIPAA). You receive an email from a vendor that handles protected health information (a business associate), ...
Members of the healthcare industry are generally aware of the HIPAA breach notification requirements. Those HIPAA requirements include (if the breach affects the PHI of more than 500 individuals) ...
So you just discovered that protected health information (“PHI”) from your organization was improperly accessed or disclosed. Are you required to self-report the violation to the affected individual ...