There appears to be a technical error in paragraph 164.408(c) “Breaches involving less than 500 individuals”, which states: “… not later than 60 days after the end of each calendar year, provide the notification required by paragraph (a) of this section for breaches occurring during the preceding calendar year …” Please note that a covered entity might not become aware of a breach until several months after it occurred. As it currently reads, the regulation might require a covered entity to notify the Secretary before becoming aware of the breach. I recommend revising that paragraph to read “… not later than 60 days after the end of each calendar year, provide the notification required by paragraph (a) of this section for breaches of which the covered entity became aware during the preceding calendar year …”
Comment on FR Doc # E9-20169
This is comment on Rule
Breach Notification for Unsecured Protected Health Information
View Comment
Related Comments
View AllPublic Submission Posted: 08/25/2009 ID: HHS-OCR-2009-0010-0002
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/25/2009 ID: HHS-OCR-2009-0010-0003
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/26/2009 ID: HHS-OCR-2009-0010-0004
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/26/2009 ID: HHS-OCR-2009-0010-0005
Oct 23,2009 11:59 PM ET
Public Submission Posted: 08/31/2009 ID: HHS-OCR-2009-0010-0008
Oct 23,2009 11:59 PM ET