News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

We think we may have had a data breach

Treat it as a breach until proven otherwise. The 60-day clock is running.

  1. 1

    Contain the incident immediately

    Stop the bleeding first. If systems are compromised, disconnect affected devices. If it was a misdisclosure, document what was shared and with whom.

  2. 2

    Assemble your response team

    Notify your privacy officer, IT support, and consider engaging a HIPAA attorney immediately for attorney-client privilege over the investigation.

  3. 3

    Conduct the four-factor risk assessment

    HIPAA requires a specific four-factor analysis to determine if this is a reportable breach. Use our Breach Notification Checker tool to walk through this.

  4. 4

    Notify your cyber insurance carrier

    If you have cyber insurance, notify them now. Many policies have strict notice requirements and they can provide breach response resources.

  5. 5

    Prepare for notification if required

    If the breach is reportable, you must notify affected individuals, HHS, and potentially the media within 60 days of discovery.

Important

The 60-day notification clock runs from the date of discovery, not the date you finish your investigation. Do not delay.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.