Skip to main content

Military Health System

Test of Sitewide Banner

This is a test of the sitewide banner capability. In the case of an emergency, site visitors would be able to visit the news page for addition information.

Breach Prevention and Response

What is a Breach?

According to the Department of Defense (DOD), a breach of personal information occurs when the information is lost, disclosed to, accessed by, or potentially exposed to unauthorized individuals, or compromised in a way where the subjects of the information are negatively affected.

Breach Reporting

The Defense Health Agency (DHA) Privacy and Civil Liberties Office (PCLO) coordinates breach reporting within the Military Health System (MHS). Email us if you have questions about breaches or breach reporting within the MHS.

Guidance tools for breach reporting:

You also may be interested in...

HITECH Act

Policy

The Health Information Technology for Economic and Clinical Health Act, abbreviated the HITECH Act, was enacted under Title XIII of the American Recovery and Reinvestment Act of 2009.

DODI 5200.48: Controlled Unclassified Information

Policy

This issuance establishes policy, assigns responsibilities, and prescribes procedures for CUI throughout the DOD in accordance with Executive Order (E.O.) 13556; Part 2002 of Title 32, Code of Federal Regulations (CFR); and Defense Federal Acquisition Regulation Supplement (DFARS) Sections 252.204-7008 and 252.204-7012. It also establishes the official DOD CUI Registry.

DOD Instruction 6025.18: Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DOD Health Care Programs

Policy

This issuance, in accordance with the authority in DOD Directive 5124.02, establishes policy and assigns responsibilities for DOD compliance with federal law governing health information privacy and breach of privacy; integrating health information privacy and breach compliance with general information privacy and security requirements in accordance with federal law and DOD issuances; health information technology, system interoperability, and exchange of electronic health information, in relation to federal law governing health information privacy and breach; and DOD contracting and procurement activities in relation to federal law governing health information privacy and breach.

DoD Instruction 8580.02: Security of Individually Identifiable Health Information in DoD Health Care Programs

Policy

This instruction establishes policy and assigns responsibilities for security of individually identifiable health information created, received, maintained, or transmitted in electronic form (referred to in this instruction as “electronic protected health information (ePHI)”).

TMA Guidelines on Protection of Sensitive Information in Electronic Mail

Policy

This Memorandum updates guidelines in Military Health System Chief Information Officer memorandum “Updated Guidelines on Protection of Sensitive Information in Electronic Mail” of September 19, 2008.

Reporting a Breach as Defined by the Health Information Technology for Economic and Clinical Health Act Provisions of the American Recovery and Reinvestment Act of 2009

Policy

This Memorandum outlines the procedures for the Services for reporting a breach as defined by the Health Information Technology for Economic and Clinical Health (HITECH) Act provisions of the American Recovery and Reinvestment Act of 2009.

Reporting a Breach as Defined by the Health Information Technology for Economic and Clinical Health Act Provisions of the American Recovery and Reinvestment Act of 2009

Policy

This Memorandum outlines the procedures for Contractors for reporting a breach as defined by the Health Information Technology for Economic and Clinical Health (HITECH) Act provisions of the American Recovery and Reinvestment Act of 2009.

Safeguarding Against and Responding to the Breach of PII

Policy

In accordance with the policies outlined in this Memorandum, a risk assessment must be conducted for every breach to determine whether notification to affected individuals is necessary.

TMA Facsimile Transmission Policy for Documents Containing Personally Identifiable Information and/or Protected Health Information

Policy

This Memorandum establishes policy for documents transmitted and/or received by facsimile that contain Personally Identifiable Information and/or Protected Health Information (PII/PHI).

Update to Using Digital Signature when Sending Electronic Mail

Policy

This Memorandum implements the recent Department of Defense (DoD) requirement on the use of digital signature for e-mail, and is in addition to my memorandum of June 13, 2007, “Use of Digital Signature on TRICARE Management Activity (TMA) Official Electronic Mail (e-mail).”

Encryption of Sensitive Unclassified Data at Rest on Mobile Computing Devices and Removable Storage Media

Policy

This Memorandum provides recommendations on means to protect sensitive unclassified information on portable computing devices used within DoD and advises that the suggestions are expected to become policy in the near future.

Safeguarding Against and Responding to the Breach of Personally Identifiable Information

Policy

This Memorandum outlines the framework within which Federal agencies must develop a breach notification policy while ensuring proper safeguards are in place to protect the information.

Recommendations for Identity Theft Related Data Breach Notification

Policy

This Memorandum provides recommendations for planning and responding to data breaches which could result in identity theft.

Protection of Sensitive Agency Information

Policy

This Memorandum addresses the efforts to properly safeguard information assets while using information technology by incorporating a checklist from the National Institute of Standards and Technology (NIST) for protection of remote information.

Safeguarding Personally Identifiable Information

Policy

This Memorandum reemphasizes responsibilities under law and policy to appropriately safeguard sensitive personally identifiable information (PII) and train employees on responsibilities in this area.

Page 1 of 1 , showing items 1 - 15
Last Updated: October 13, 2022
Follow us on Instagram Follow us on LinkedIn Follow us on Facebook Follow us on Twitter Follow us on YouTube Sign up on GovDelivery