1 / 5100%
Running Head: HEALTH CARE d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 1
4-1 Final Project Milestone Two: Impacts
HIM422
SNHU
May 29,2022
HEALTH CARE d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 2
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach incident
on the organization. In the initial section of the report, the laws that are in place to prevent such
incidents have been identified. The communication plan that will be adopted to notify the key
stakeholders has been identified. The financial and non-financial impacts of the breach on an
entity have been identified. Ultimately, appropriate federally sponsored initiatives have been
identified that can ensure the provision of the highest level of healthcare safety, quality and data
security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of the
most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centers for
Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it is the
responsibility of healthcare entities to notify patients in case their unprotected data has been
disclosed or breached in any manner (Hipaa Breach Notification Rule. American Medical
Association, 2021). Physicians need to play a proactive role while evaluating the severity of a
data breach incident by evaluating whether it meets HIPAA’s ‘low probability of compromise’
threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about a
breach incident. This law is applicable for most of the health apps as well as similar kinds of
HEALTH CARE d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 3
technologies. In the specific scenario involving the ABC hospital, the risk assessment that was
conducted revealed that both the laws were violated since the security of sensitive patient
information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity is
shared with them in an honest manner. The first step of the plan involves the identification of
suitable and appropriate communication channels to inform the stakeholders i.e., whose data
have been breached in the incident. In this case, direct phone calls, emails or letters can be used
as communication channels. The next step is to establish facts about what exact information has
been compromised and how the incident took place. Then the ABC hospital must make sure to
communicate directly and immediately with the stakeholder. An honest and straightforward
approach must be adopted and it is also necessary to show remorse. Ultimately, an official
statement must be released by the healthcare facility explaining the steps that were in place and
the consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the reduction in
revenue generation ability due to a decline in patient number, and the imposition of penalties due
to the violation of laws relating to data breach in the healthcare domain. The cost relating to IT
HEALTH CARE d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 4
infrastructure has also increased since the facility will have to integrate new and effective
cybersecurity instruments. The main non-financial impacts of the data breach incident on the
ABC Hospital include reputational damage and a considerable decline in patient trust on the
hospital and the professionals that work in it. A data breach incident can impact the decision-
making process, such as financial decisions. For example, responsibilities must be allocated
carefully to ensure no professional can abuse his power or position. Similarly, decisions on
employee training must be made to prevent such incidents from recurring in the future (Health
Sector Cybersecurity Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety, quality
and data security, the ABC Hospital can adopt several suitable federally sponsored initiatives.
For example, the knowledge, tools and technologies offered by the Agency for Healthcare
Research and Quality (AHRQ) must be integrated. It will help to improve the safety of care
solutions provided by the facility (Kronick, 2016). The National Quality Strategy (NQS) must be
adopted to achieve better health by focusing on quality and safety aspects.
HEALTH CARE d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d d 5
References
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance Portability
and accountability act of 1996 (HIPAA). Centers for Disease Control and Prevention.
Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare Sector
Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system performance.
Public health reports, 131(2), 229-232.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad Khan, R.
(2020, June). Healthcare data breaches: insights and implications. In Healthcare (Vol. 8,
No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
https://www.ahrq.gov/workingforquality/about/nqs-fact-sheets/fact-sheet.html
Students also viewed