| | -
Reports of Suspected Violations -
All reports of suspected violations of DMH privacy-related policies or of the privacy safeguard practices by a Workforce Member or a Business Associate shall be forwarded immediately to the HIPAA Privacy Officer. -
The HIPAA Privacy Officer, or their designee, shall promptly investigate all DMH privacy-related allegations and document any findings and confirmed privacy violations and/or breaches identified during the investigative process. -
The designated HIPAA Privacy Officer, in consultation legal counsel as deemed appropriate, shall take steps, as reasonably practicable, to mitigate the harmful effects of such violation to the individual whose PHI is at issue. Such steps may include, but are not limited to, imposing sanctions against workforce members in accordance with the Workforce Sanctions Policy in a form that could inure to the benefit of the harmed individual, such as requiring specific types of restitution. To the extent that the individual harmed is aware of the harm, such as when the individual initiated a complaint, the designated HIPAA Privacy Officer shall discuss any proposed mitigation with the individual in accordance with the Complaint Policy. If the individual is not aware of the harm, the affected individual of the harm must be notified by mail (or email if agreed) via (Breach Notification Letter).1 However, in unusual circumstances where it seems that informing the individual of the harm could be more harmful than helpful to the individual, legal counsel should be consulted. -
The designated HIPAA Privacy Officer shall document all actions taken under this policy. -
When a privacy violation is caused by a Business Associate, it is the Business Associate's responsibility to notify the Privacy Officer immediately and mitigate the breach according to HIPAA regulations. -
Review of Complaints and Audits -
Violations identified through the designated HIPAA Privacy Officer’s review of all privacy-related complaints and/or internal audit reports shall be analyzed for mitigation according to this policy. 1 NOTE: The HIPAA Breach Notification Rule requires healthcare entities (Covered Entities and Business Associates) to report breaches of unsecured Protected Health Information (PHI) to affected individuals without unreasonable delay and within 60 days after discovery. | |