Always a crowd favorite when negotiating Business Associate Agreements and Data Processing Agreements alike, breach notification periods almost always generate lively discussion. One party wants “immediate” notification of data breaches; one says it can only notify in five days, or some other longer period.
The US Department of Health and Human Services may be weighing in and moving the standard for us – at least as to covered breaches of PHI. The HHS provided a Notice of Proposed Rulemaking on December 27 – an end-of-year gift for privacy practitioners – which would require a business associate to notify a covered entity within 24 hours of “activation of its contingency plan” in response to “an emergency or other occurrence that adversely affects relevant electronic information systems.” Though the Proposed Rule indicates that “[t]his proposal, if finalized, would not alter the business associate’s breach reporting obligations under the Breach Notification Rule,” it’s likely that it would have the effect of changing the Breach Notification Rule.
The HHS goes on:
We recognize that when such an emergency or other occurrence transpires, the focus of the affected regulated entity must be on activating its contingency plan and restoring access to ePHI and the affected relevant electronic information systems. Similarly, when the contingency plan activation is in response to a successful security incident, it may take some time to investigate and determine the cause of the security incident. Thus, this proposal would not require reporting on the cause of the contingency plan activation; it would require reporting solely on the fact that it has activated the plan. Accordingly, we believe that 24 hours would provide a business associate with sufficient time to do all of the following: determine that there is an emergency or other occurrence adversely affecting the business associate’s relevant electronic information systems; determine that it needs to activate its contingency plan; identify any covered entities that need to be notified; and notify such covered entities.
Security professionals may read the last sentence with some doubt. What HHS appears to require is that a business associate analyze a security event to determine if it rises to the level of an event requiring activation of contingency plans. An event that requires activation of contingency plans is likely a data breach or security incident requiring notification to the covered entity. And more likely than not, 24 hours is less time than most business associates will need to conduct this analysis and make applicable notifications.
Practitioners should monitor development of these Proposed Rules to understand whether and how these new notification periods will be finalized.