No harm done? Assessing risk of harm under the federal breach notification rule
Dimick, C.
Journal of Ahima 81(8): 20-25
2010
ISSN/ISBN: 1060-5487 PMID: 20795525 Document Number: 646519
Provisions within the HITECH Act require that covered entities notify individuals if their protected health information is breached. However, the current regulation allows an exemption if the risk of harm is slight. Assessing risk can be subjective, and privacy officers have been working to create methods to conduct and document their analyses.