DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

AHIMA offers data breach toolkit to healthcare providers and suits their action to their advice

Posted on May 9, 2014 by Dissent

Over on HealthITSecurity.com, Patrick Ouellette notes that American Health Information Management Association’s (AHIMA) recently published a Breach Management Toolkit.

The tool requires an AHIMA membership, but the Journal of AHIMA detailed what the tool has to offer providers and a sample of required elements within a data breach notification letter.

Patrick reports that the toolkit discusses five critical pieces of information that AHIMA says should be included in any breach notification letter. Their five critical pieces, as summarized by Patrick, are consistent with what I have been advising for years:

  1. A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known
  2. A description of the types of unsecured PHI that were involved in the breach (i.e., full name, Social Security number, date of birth, home address, account number, diagnosis, or disability code)
  3. Any steps individuals should take to protect themselves from potential harm resulting from the breach
  4. A brief description of what the organization is doing to investigate the breach, to mitigate harm to the individuals, and to protect against any further breaches
  5. Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an e-mail address, Website, or postal address if appropriate.

Suiting their action to the word,  on April 2, AHIMA notified the Maryland Attorney General’s Office that a temporary worker employed between September 26, 2013 and January 27, 2014  had misused some customers’ credit card information in February that she had collected from their telephone orders for merchandise.  AHIMA had evidence that a few customers had their information misused and decided to notify all customers potentially affected, i.e., all customers who had orders taken on the phone by the now-former employee.

Their notification letter to customers, which you can read here (pdf), does include pretty much all the critical elements they describe in their toolkit. I would have preferred to see them offer an e-mail address in lieu of a postal address, as I think that would be more convenient for more customers, and they do not offer them a toll-free number or indicate the days and hours for which their phone support is available, but overall, it’s a good notification letter.

Perhaps the only thing they could have made clearer is that the former employee did not start misusing customer data until after her employment terminated (meaning that she took information with her, which is different than her misusing data she still had access to at work). In general, I find the phrase “former employee” is often confusing. Does it mean that the employee had already been terminated before the incident, or was the employee terminated after the incident or discovery of same? For this case, and because they did not tell those affected the employee’s dates of employment, it probably would have been clearer to write something like, “We learned that one month after the employee’s position was terminated, she misused three customers’ credit card information to make purchases” (or something like that).

Sometimes it’s easy to write a clear breach notification letter. Other times, it may seem clear to you but not to an uninformed reader. Having someone who doesn’t know the details of a case read the draft letter to see what questions they may have can help you write a more effective letter.  I don’t know if that’s in AHIMA’s toolkit, but it’s my advice to you.

Category: Health Data

Post navigation

← Target breach: 50,000 card numbers from Minn. for sale this week
Four more breaches reported by Baylor Health affiliates (updated) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Cyberattack pushes German napkin company into insolvency
  • WMATA Train Operators Arrested in Health Care Fraud Scheme
  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.