HIPAA requires you have breach notification policies and procedures to ensure proper handling of a breach of unsecured protected health information (PHI). Do you have breach notification policies and procedures that comply with HIPAA, including the latest changes that went into effect in 2013? Are you training your staff about how to handle suspected breaches? If not, you could end up like Skagit County in Washington, which agreed to a settlement with HHS that includes a $215,000 penalty and a three-year corrective action plan…