Arizona’s breach notification law is stricter than HIPAA
If your Arizona medical practice experiences a data breach, you have two notification clocks running simultaneously. HIPAA gives you 60 days. Arizona’s ARS 18-552 gives you 45.
That 15-day difference matters. If you build your incident response plan around the federal 60-day timeline, you’ll miss the state deadline and face additional penalties from the Arizona Attorney General’s office.
What triggers ARS 18-552
ARS 18-552 applies when there’s unauthorized acquisition of, or access to, unencrypted personal information. For a medical practice, “personal information” includes a patient’s name combined with their Social Security number, driver’s license number, or financial account number.
Note: ePHI breaches are covered under both HIPAA and ARS 18-552 when they involve personal information as defined by the statute. You must comply with both.
The dual-track notification process
Within 45 days (ARS 18-552):
- Notify all affected Arizona residents in writing
- If more than 1,000 residents are affected, also notify the Arizona Attorney General
- If more than 1,000 residents are affected, notify the three major credit bureaus
- If more than 1,000 residents are affected, notify the Arizona Department of Homeland Security
Within 60 days (HIPAA Breach Notification Rule):
- Notify all affected individuals
- Notify HHS (immediately if 500+ individuals; annual log if fewer)
- Notify media outlets serving the affected area if 500+ individuals
- Notify the Secretary of HHS
Building an incident response plan that covers both
Your incident response plan needs to account for the tighter Arizona timeline. Here’s what that looks like:
Day 1-3: Contain and assess. Stop the breach, preserve evidence, determine the scope. Engage your IT provider and legal counsel immediately.
Day 3-10: Investigate. Determine what information was accessed, how many individuals are affected, and whether the data was encrypted (encryption is a safe harbor under ARS 18-552).
Day 10-30: Prepare notifications. Draft notification letters, compile affected individual lists, prepare AG notification if over 1,000 affected.
Day 30-45: Send notifications. Mail individual notices, submit AG notification, contact credit bureaus if required.
Day 45-60: Complete HIPAA notifications. Submit HHS breach report, issue media notifications if required.
Encryption as a safe harbor
Under ARS 18-552, if the breached data was encrypted using methods that make it unreadable without the encryption key, notification is not required. This is one of the strongest arguments for encrypting all patient data at rest and in transit. Your security risk assessment should identify everywhere ePHI exists and ensure encryption covers all of it.
Preparing before it happens
The worst time to build an incident response plan is during an incident. Your practice needs:
- A documented incident response plan that maps both ARS 18-552 and HIPAA timelines
- Pre-drafted notification letter templates
- Contact information for the Arizona AG’s office, credit bureaus, and HHS
- A relationship with legal counsel experienced in healthcare breaches
- An IT provider who can perform forensic analysis and containment
- Regular tabletop exercises to test the plan
Asteroid IT provides HIPAA-compliant IT support for Arizona medical practices, including incident response planning, encryption implementation, and breach preparation. We serve practices across Gilbert, Mesa, Chandler, and the greater Phoenix area.
Call us at 480-937-7021 or schedule a conversation.
