Final answer:
In the event of a PHI breach, the Covered Entity is required to report the breach to the U.S. Department of Health and Human Services (HHS) within 60 days.
Step-by-step explanation:
In the event of any PHI breach, the Covered Entity is required to report the breach to the U.S. Department of Health and Human Services (HHS).
The Health Insurance Portability and Accountability Act (HIPAA) mandates that covered entities notify HHS within 60 days of discovering a breach of Protected Health Information (PHI) affecting 500 or more individuals. The notification must include details about the breach, the steps taken to mitigate the breach, and any additional information required by HHS.
For breaches affecting fewer than 500 individuals, covered entities must maintain a log and submit it annually to HHS.