The document summarizes new rules issued by the Department of Health and Human Services regarding breach notification requirements under HIPAA. Key points include:
1) The rules apply to unsecured protected health information and require covered entities like health plans and their business associates to provide notification if unsecured PHI is improperly used or disclosed.
2) Encryption and destruction are specified as methods to secure PHI to avoid a breach.
3) A breach is defined as an unauthorized disclosure of unsecured PHI that poses a significant risk of financial or reputational harm. Covered entities must assess risks to determine if a breach occurred.