# Breach notification

To date, Redox hasn’t had any breaches of PHI data. Should this ever occur, we defer to the <u>Breach Notification Rule</u> from the U.S. Department of Health & Human Services (HHS) as the definitive source of information regarding how this must be reported. [Read about the Breach Notification Rule](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html).

In case of a breach, we'll notify affected customers within five business days of the breach discovery. _Please note this is significantly quicker than the_ <u>_Breach Notification Rule_</u> _requirement of notification within 60 calendar days after breach discovery._

## What a Redox notification includes

As the <u>**Business Associate**</u>, Redox _must_ notify covered entities if a breach occurs at or by the Business Associate.

A notification from us would include the following:

- brief description of the breach
- description of the type of information involved in the breach
- steps affected individuals should take to protect themselves from potential harm
- brief description of the investigation, mitigation, and prevention of further breaches
- contact information

## Your responsibility as a covered entity

Following a breach of unsecured <u>**protected health information**</u> (<u>**PHI**</u>), covered entities (i.e., you and your connections), _must_ provide notification of the breach to:

- any affected individuals
- the HHS secretary ([submit breach notifications to the secretary](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html))
- the media, in certain circumstances
