We think we may have had a data breach

Treat it as a breach until proven otherwise. The 60-day clock is running.

  1. 1

    Contain the incident immediately

    Stop the bleeding first. If systems are compromised, disconnect affected devices. If it was a misdisclosure, document what was shared and with whom.

  2. 2

    Assemble your response team

    Notify your privacy officer, IT support, and consider engaging a HIPAA attorney immediately for attorney-client privilege over the investigation.

  3. 3

    Conduct the four-factor risk assessment

    HIPAA requires a specific four-factor analysis to determine if this is a reportable breach. Use our Breach Notification Checker tool to walk through this.

  4. 4

    Notify your cyber insurance carrier

    If you have cyber insurance, notify them now. Many policies have strict notice requirements and they can provide breach response resources.

  5. 5

    Prepare for notification if required

    If the breach is reportable, you must notify affected individuals, HHS, and potentially the media within 60 days of discovery.

Important

The 60-day notification clock runs from the date of discovery — not the date you finish your investigation. Do not delay.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.