1 / 5100%
Running Head: HEALTH CARE f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 1
4-1 Final Project Milestone Two: Impacts
HIM422
SNHU
May 29,2022
HEALTH CARE f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 2
A data breach in the healthcare domain can give rise to serious implications for a healthcare
organization. The report has been designed detailing the impact of the breach incident on the
organization. In the initial section of the report, the laws that are in place to prevent such incidents
have been identified. The communication plan that will be adopted to notify the key stakeholders
has been identified. The financial and non-financial impacts of the breach on an entity have been
identified. Ultimately, appropriate federally sponsored initiatives have been identified that can
ensure the provision of the highest level of healthcare safety, quality and data security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of the
most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centers for
Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it is the
responsibility of healthcare entities to notify patients in case their unprotected data has been
disclosed or breached in any manner (Hipaa Breach Notification Rule. American Medical
Association, 2021). Physicians need to play a proactive role while evaluating the severity of a data
breach incident by evaluating whether it meets HIPAA’s ‘low probability of compromise’
threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or similar
technology that has sensitive customer health information to notify customers about a breach
incident. This law is applicable for most of the health apps as well as similar kinds of technologies.
In the specific scenario involving the ABC hospital, the risk assessment that was conducted
HEALTH CARE f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 3
revealed that both the laws were violated since the security of sensitive patient information was
compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to make
sure that the key stakeholders are made aware of the breach incident and its severity is shared with
them in an honest manner. The first step of the plan involves the identification of suitable and
appropriate communication channels to inform the stakeholders i.e., whose data have been
breached in the incident. In this case, direct phone calls, emails or letters can be used as
communication channels. The next step is to establish facts about what exact information has been
compromised and how the incident took place. Then the ABC hospital must make sure to
communicate directly and immediately with the stakeholder. An honest and straightforward
approach must be adopted and it is also necessary to show remorse. Ultimately, an official
statement must be released by the healthcare facility explaining the steps that were in place and the
consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely manner
include conducting a thorough risk assessment process and correctly identifying the medical coder
who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the reduction in
revenue generation ability due to a decline in patient number, and the imposition of penalties due to
the violation of laws relating to data breach in the healthcare domain. The cost relating to IT
infrastructure has also increased since the facility will have to integrate new and effective
HEALTH CARE f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 4
cybersecurity instruments. The main non-financial impacts of the data breach incident on the ABC
Hospital include reputational damage and a considerable decline in patient trust on the hospital and
the professionals that work in it. A data breach incident can impact the decision-making process,
such as financial decisions. For example, responsibilities must be allocated carefully to ensure no
professional can abuse his power or position. Similarly, decisions on employee training must be
made to prevent such incidents from recurring in the future (Health Sector Cybersecurity
Coordination Center, 2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety, quality
and data security, the ABC Hospital can adopt several suitable federally sponsored initiatives. For
example, the knowledge, tools and technologies offered by the Agency for Healthcare Research
and Quality (AHRQ) must be integrated. It will help to improve the safety of care solutions
provided by the facility (Kronick, 2016). The National Quality Strategy (NQS) must be adopted to
achieve better health by focusing on quality and safety aspects.
HEALTH CARE f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f f 5
References
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance Portability
and accountability act of 1996 (HIPAA). Centers for Disease Control and Prevention.
Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare Sector
Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28, 2022,
from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system performance.
Public health reports, 131(2), 229-232.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad Khan, R.
(2020, June). Healthcare data breaches: insights and implications. In Healthcare (Vol. 8, No.
2, p. 133). Multidisciplinary Digital Publishing Institute.
https://www.ahrq.gov/workingforquality/about/nqs-fact-sheets/fact-sheet.html
Students also viewed