Can you please define what actions qualify as "corrected" as it is used in Table 1. For example if a laptop containing unencrypted protected health information is recovered three days after being misplaced in a public location, has the violation been corrected? If an individual whose protected health information has been improperly mailed to the wrong patient is informed of the breach and the information has been retrieved, has the violation been corrected? What actions are necessary for a covered entity or business associate to correct a violation?
Comment on FR Doc # E9-26203
This is comment on Rule
HIPAA Administrative Simplification: Enforcement
View Comment
Attachments:
Comment on FR Doc # E9-26203
Title:
Comment on FR Doc # E9-26203
Related Comments
View AllPublic Submission Posted: 11/03/2009 ID: HHS-OCR-2009-0020-0002
Dec 29,2009 11:59 PM ET
Public Submission Posted: 01/04/2010 ID: HHS-OCR-2009-0020-0003
Dec 29,2009 11:59 PM ET
Public Submission Posted: 01/04/2010 ID: HHS-OCR-2009-0020-0004
Dec 29,2009 11:59 PM ET
Public Submission Posted: 01/04/2010 ID: HHS-OCR-2009-0020-0005
Dec 29,2009 11:59 PM ET
Public Submission Posted: 01/04/2010 ID: HHS-OCR-2009-0020-0006
Dec 29,2009 11:59 PM ET