Notify Yale IMMEDIATELY of all events that might be potential breaches! if you believe ePHI/PHI might have been lost, stolen, compromised, misdirected, etc. Yale HIPAA professionals will work with you to determine the next steps, and whether the event requires notification. To report to Information Security click here.
Anyone else wishing to report a HIPAA concern should call 203.432.5919.
Safe Harbor: It won’t apply to most
If an environment has established ‘Safe Harbor,’ notification is not required. Safe Harbor is defined by the HITECH Act as either:
- Securely remove PHI from Yale strage devices including hard drives, storage media, portable devices and Email
OR - Encryption procedure: https://your.yale.edu/policies-procedures/procedures/1607-pr01-endorsed-encryption-implementation-procedure.
- Sending an encrypted email: https://cybersecurity.yale.edu/emailencryption
You are responsible for complying with these policies.