COMPLIANCE · FLORIDA
Florida’s 30-day breach notification rule and your intake system
HIPAA gives a practice sixty days to notify patients of a breach. Florida gives thirty, applies to personal information whether or not the practice is a HIPAA covered entity, and expects the practice to know what was taken. The intake system is where a good share of that information lives, and where the answer to “what was taken” either exists or does not.
A note on what this is: a description of one Florida statute as it touches intake systems, written by a technology firm. It is not legal advice, and a breach is precisely the moment to call counsel rather than read a blog post.
THE SHORT ANSWER
Two clocks
HIPAA’s Breach Notification Rule requires notice to individuals without unreasonable delay and no later than 60 days after discovery. Florida’s statute says 30 days after determination of the breach, with a possible 15-day extension for good cause shown in writing. A HIPAA covered entity in Florida is on the shorter clock in practice, because Florida’s deemed-compliance provision only applies if the federal-style notice actually goes out, and goes to the Department, within Florida’s window. A practice that is not a HIPAA covered entity has only the Florida clock, and it is the same 30 days.
What is in scope from intake
- Name plus any of: a government ID number, a financial account number, a medical history, health insurance policy or subscriber number, or an online account credential. Intake forms collect several of these on the first day.
- Form submissions, including the answers to “what brings you in.”
- Message threads, which patients fill with detail the practice never asked for.
- Call recordings and transcripts, if retained.
- The consent records themselves, which contain phone numbers and IP addresses.
None of that is exotic. It is the ordinary content of an intake system, and it is why “we only use it for scheduling” is not a defense.
Reasonable measures, as configuration
The statute asks for reasonable measures and does not list them. The technical safeguards a practice can point to are the ones the intake platform provides and the configuration applies: encryption at rest and in transit, one login per person with multi-factor authentication, role-based access on a minimum-necessary basis, an audit log of every access and send, retention limits on messages and recordings, and third-party connections kept outside the boundary unless documented. Those are described on the HIPAA page as the platform’s share of a three-way responsibility. Under Florida’s statute they are also the practice’s evidence of reasonableness.
The question the practice will be asked
After a breach the first question from counsel, and later from the Department, is what was accessed. A practice on a shared front-desk login cannot answer it; the log says the inbox was opened 340 times last month by a chair. A practice with named logins and a per-record audit trail can say which records were viewed by the compromised account, in what window, and which patients therefore need notice. That difference is the difference between notifying 40 people and notifying everyone, and it is decided by a configuration choice made months earlier.
The audit log is also how a practice discovers a breach at all. Access from an unfamiliar location at 3 AM is visible only if access is logged by user and the log is looked at. Most breaches at small practices are discovered by someone else.
What the intake system cannot do
It cannot decide whether an incident is a breach under either statute; that is a legal determination involving a risk assessment. It cannot send the notices, which have required contents and go from the practice. It cannot substitute for the practice’s own risk analysis, policies, and workforce training, which are the largest share of the responsibility and sit with the practice whatever vendor it uses. What it can do is make the technical facts available quickly and completely, which is the part that turns thirty days from a panic into a process.
Before anything happens
- Know which of your systems hold personal information as Florida defines it. The intake system is one; the practice-management system is another; the personal phones staff text from are a third, and that one has no audit log.
- Confirm every login is a named person and every departed staff member is disabled.
- Set retention on recordings and transcripts. Data you no longer hold cannot be breached.
- Ask each vendor, including us, what their incident notification obligation to you is under the BAA or the contract, and how fast.
- Keep counsel’s number somewhere that is not in the system that just went down.
Questions we get asked about this
How does Florida's rule differ from HIPAA's?
HIPAA allows up to 60 days after discovery. Florida requires notice within 30 days of determining a breach, applies to personal information whether or not the business is a HIPAA covered entity, and requires notice to the Department of Legal Affairs if 500 or more Floridians are affected.
Which intake data is in scope?
Names combined with dates of birth, insurance numbers, medical history from form answers, message threads, call recordings and transcripts, and the consent records themselves. Ordinary intake content.
What does the intake system give us after a breach?
The audit log: which records were viewed by which account, in what window. A practice on a shared login cannot answer that; a practice with named logins can, and it decides how many people need notice.
Can the intake system decide whether an incident is a breach?
No. That is a legal determination involving a risk assessment, and the notices themselves go from the practice with required contents. Call counsel.
Related
Could your intake system answer “what was accessed” today?
A 30-minute consultation walks through the audit log, access by role, and retention settings as they would be configured for your practice.