We think we may have had a data breach
Treat it as a breach until proven otherwise. The 60-day clock is running.
- 1
Contain the incident immediately
Stop the bleeding first. If systems are compromised, disconnect affected devices. If it was a misdisclosure, document what was shared and with whom.
- 2
Assemble your response team
Notify your privacy officer, IT support, and consider engaging a HIPAA attorney immediately for attorney-client privilege over the investigation.
- 3
Conduct the four-factor risk assessment
HIPAA requires a specific four-factor analysis to determine if this is a reportable breach. Use our Breach Notification Checker tool to walk through this.
- 4
Notify your cyber insurance carrier
If you have cyber insurance, notify them now. Many policies have strict notice requirements and they can provide breach response resources.
- 5
Prepare for notification if required
If the breach is reportable, you must notify affected individuals, HHS, and potentially the media within 60 days of discovery.
Important
The 60-day notification clock runs from the date of discovery — not the date you finish your investigation. Do not delay.
Related
Not legal advice. Follow your organization's policies and consult counsel for legal questions.