Breach Notification Policy
Effective Date: March 5, 2026 | Last Updated: March 5, 2026
1. Purpose
This policy describes how Krasyn LLC ("Krasyn") detects, responds to, and notifies affected parties in the event of a breach of unsecured Protected Health Information ("PHI") or other personal data processed through the Krasyn EMR platform. This policy complies with the HIPAA Breach Notification Rule (45 CFR §§164.400-414), the HITECH Act, and applicable state breach notification laws.
2. Definitions
- Breach: The acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule which compromises the security or privacy of the PHI (45 CFR §164.402)
- Unsecured PHI: PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption or destruction meeting HHS guidance
- Security incident: The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations
3. Breach Risk Assessment
When a potential breach is identified, Krasyn will conduct a risk assessment considering the following factors (per 45 CFR §164.402(2)):
- Nature and extent of PHI involved: Types and amount of identifiers, likelihood of re-identification
- Unauthorized person: Who obtained or accessed the PHI
- Actual acquisition or viewing: Whether the PHI was actually acquired or viewed
- Mitigation: Extent to which the risk has been mitigated
If the risk assessment determines there is a low probability that the PHI has been compromised, notification may not be required. The assessment and its basis will be documented.
4. Notification to Covered Entities
As a Business Associate, Krasyn will notify affected Covered Entities of a breach of unsecured PHI without unreasonable delay and no later than thirty (30) days after discovery of the breach (our BAA standard, which is stricter than the HIPAA 60-day requirement). The notification will include:
- Nature of the breach, including types of PHI involved
- Date of the breach and date of discovery
- Description of the investigation and its findings
- Number of individuals affected (if known)
- Steps taken to mitigate harm and prevent recurrence
- Contact information for Krasyn's Security Officer
- Identity of each individual affected (if available)
5. Notification to Individuals
The Covered Entity is primarily responsible for notifying affected individuals under HIPAA. However, if requested or required by the BAA, Krasyn will assist with notifications. Individual notifications must:
- Be provided without unreasonable delay, no later than 60 days after discovery
- Be sent by first-class mail (or email if the individual has agreed to electronic notice)
- Include a description of what happened and when
- Describe the types of PHI involved
- Describe steps individuals can take to protect themselves
- Describe what is being done to investigate and mitigate harm
- Provide contact information for questions
6. Notification to HHS
- Breaches affecting 500+ individuals: The Covered Entity must notify the HHS Secretary contemporaneously with individual notifications (within 60 days)
- Breaches affecting fewer than 500 individuals: The Covered Entity must report to HHS within 60 days of the end of the calendar year in which the breach was discovered
Krasyn will provide all information necessary for the Covered Entity to fulfill these obligations.
7. Notification to Media
For breaches affecting 500 or more individuals in a single state or jurisdiction, the Covered Entity must provide notice to prominent media outlets in that state. Krasyn will assist the Covered Entity in preparing such notification.
8. State Law Requirements
In addition to HIPAA, many states have their own breach notification laws with varying requirements. Krasyn monitors and complies with state-specific requirements, including but not limited to:
- California (Cal. Civ. Code §1798.82): Notification to individuals and the Attorney General (if 500+ California residents affected)
- New York (SHIELD Act): Notification to individuals, Attorney General, and Department of State
- Texas (Tex. Bus. & Com. Code §521.053): Notification within 60 days, notice to Attorney General if 250+ residents affected
- Florida (Fla. Stat. §501.171): Notification within 30 days of determination
- Massachusetts (201 CMR 17.00): Notification to Attorney General and Director of Consumer Affairs
- Illinois (815 ILCS 530/): Notification to Attorney General if 500+ residents affected
Where state law imposes stricter requirements than HIPAA, we will comply with the stricter standard.
9. Breach Detection and Investigation
Krasyn employs the following measures to detect and investigate potential breaches:
- Tamper-proof audit trail: Cryptographic hash-chain audit logging of all data access
- Real-time monitoring: Automated alerts for anomalous access patterns
- Tenant isolation monitoring: Detection of cross-organization access attempts
- Authentication monitoring: Tracking of failed login attempts and credential compromise indicators
- Incident response team: Designated personnel trained in breach investigation and response
10. Documentation and Record Keeping
Krasyn will maintain documentation of all breach investigations, risk assessments, notifications, and corrective actions for a minimum of six (6) years as required by HIPAA (45 CFR §164.530(j)). All breach records are stored in an append-only format.
11. Contact Information
To report a suspected breach or security incident:
- Security incidents (urgent): security@krasyn.com
- Compliance inquiries: compliance@krasyn.com
Krasyn LLC
2489 N Side Saddle Lane
Post Falls, ID, United States