Running Head: HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 1
4-1 Final Project Milestone Two: Impacts
HIM422
SNHU
HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 2
A data breach in the healthcare domain can give rise to serious implications for a
healthcare organization. The report has been designed detailing the impact of the breach
incident on the organization. In the initial section of the report, the laws that are in place to
prevent such incidents have been identified. The communication plan that will be adopted to
notify the key stakeholders has been identified. The financial and non-financial impacts of
the breach on an entity have been identified. Ultimately, appropriate federally sponsored
initiatives have been identified that can ensure the provision of the highest level of
healthcare safety, quality and data security.
Impact – Laws to prevent data breach
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is one of
the most important federal laws that has been introduced to safeguard sensitive patient health
information from being disclosed to any unauthorized parties without their consent (Centers
for Disease Control and Prevention, 2018). According to HIPAA Breach Notification Rule it
is the responsibility of healthcare entities to notify patients in case their unprotected data has
been disclosed or breached in any manner (Hipaa Breach Notification Rule. American
Medical Association, 2021). Physicians need to play a proactive role while evaluating the
severity of a data breach incident by evaluating whether it meets HIPAA’s ‘low probability
of compromise’ threshold or not.
The Federal Trade Commission’s (FTC) Health Breach Notification Rule is another
important legal element that requires companies that have a mobile application, website or
similar technology that has sensitive customer health information to notify customers about a
breach incident. This law is applicable for most of the health apps as well as similar kinds
HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 3
of technologies. In the specific scenario involving the ABC hospital, the risk assessment that
was conducted revealed that both the laws were violated since the security of sensitive
patient information was compromised.
Impact – Communication plan
The implementation of a well-defined and transparent communication plan is vital to
make sure that the key stakeholders are made aware of the breach incident and its severity is
shared with them in an honest manner. The first step of the plan involves the identification
of suitable and appropriate communication channels to inform the stakeholders i.e., whose
data have been breached in the incident. In this case, direct phone calls, emails or letters can
be used as communication channels. The next step is to establish facts about what exact
information has been compromised and how the incident took place. Then the ABC hospital
must make sure to communicate directly and immediately with the stakeholder. An honest
and straightforward approach must be adopted and it is also necessary to show remorse.
Ultimately, an official statement must be released by the healthcare facility explaining the
steps that were in place and the consequences of the data breach incident (Seh et al., 2020).
The expectations that have been set to ensure that the people are notified in a timely
manner include conducting a thorough risk assessment process and correctly identifying the
medical coder who was responsible for disclosing sensitive patient information.
Impact – Financial and non-financial impacts
The key financial impact of the data breach on the organization includes the
reduction in revenue generation ability due to a decline in patient number, and the
imposition of penalties due to the violation of laws relating to data breach in the healthcare
HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 4
domain. The cost relating to IT infrastructure has also increased since the facility will have
to integrate new and effective cybersecurity instruments. The main non-financial impacts of
the data breach incident on the ABC Hospital include reputational damage and a
considerable decline in patient trust on the hospital and the professionals that work in it. A
data breach incident can impact the decision-making process, such as financial decisions. For
example, responsibilities must be allocated carefully to ensure no professional can abuse his
power or position. Similarly, decisions on employee training must be made to prevent such
incidents from recurring in the future (Health Sector Cybersecurity Coordination Center,
2019).
Impact – Sponsored initiatives
In order to ensure that there is a proper provision of top-level of healthcare safety,
quality and data security, the ABC Hospital can adopt several suitable federally sponsored
initiatives. For example, the knowledge, tools, and technologies offered by the Agency for
Healthcare Research and Quality (AHRQ) must be integrated. It will help to improve the
safety of care solutions provided by the facility (Kronick, 2016). The National Quality
Strategy (NQS) must be adopted to achieve better health by focusing on quality and safety
aspects.
HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 5
References
Centers for Disease Control and Prevention. (2018, September 14). Health Insurance
Portability and accountability act of 1996 (HIPAA). Centers for Disease Control and
Prevention. Retrieved May 28, 2022, from
https://www.cdc.gov/phlp/publications/topic/hipaa.html#:~:text=The%20Health%20Insura
nce%20Portability%20and,the%20patient's%20consent%20or%20knowledge.
Health Sector Cybersecurity Coordination Center. (2019). A Cost Analysis of Healthcare
Sector Data Breaches.
Hipaa Breach Notification Rule. American Medical Association. (2021). Retrieved May 28,
2022, from https://www.ama-assn.org/practice-management/hipaa/hipaa-breach-
notification-
rule#:~:text=HIPAA's%20Breach%20Notification%20Rule%20requires,and%20security%
20of%20the%20PHI.
Kronick, R. (2016). AHRQ's role in improving quality, safety, and health system
performance. Public health reports, 131(2), 229-232.
Seh, A. H., Zarour, M., Alenezi, M., Sarkar, A. K., Agrawal, A., Kumar, R., & Ahmad
Khan, R. (2020, June). Healthcare data breaches: insights and implications. In
Healthcare (Vol. 8, No. 2, p. 133). Multidisciplinary Digital Publishing Institute.
HEALTH CARE cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc c cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc
cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc cc 6
https://www.ahrq.gov/workingforquality/about/nqs-fact-sheets/fact-sheet.html