As per CMS guidelines, if we receive PII or PHI on any patient via email, this breach must be reported to the sender and the facility administrator via email, and to CMS through the use of the CMS Incident Handling Actions. An investigation will be done by a designated CMS QualityNet (QNet) security staff member. Depending on the type and severity of the incident, internal procedures and/or external agencies will be notified as required by law. Upon receipt of our notice from the Network, it is your facility’s responsibility to notify your organization’s HIPAA compliance officer and to follow the guidelines established by your institution to comply with HIPAA mandates.
Security Breaches are Reported to CMS Print
Modified on: Tue, Jan 12, 2021 at 10:35 AM
Did you find it helpful? Yes No
Send feedbackSorry we couldn't be helpful. Help us improve this article with your feedback.