News
Do I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule UpdateDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule Update

Data Breach

How to Respond to a HIPAA Breach — A Step-by-Step Guide

TL;DR

When a potential HIPAA breach is discovered, your organization has 60 days to complete a four-factor risk assessment, determine whether notification is required, and notify affected individuals, HHS, and in some cases the media. The 60-day clock starts on the date of discovery — not when your investigation concludes. Acting immediately and documenting everything are the two most important things you can do.

When a potential HIPAA breach is discovered, your organization has 60 days to complete a four-factor risk assessment, determine whether notification is required, and notify affected individuals, HHS, and in some cases the media. The 60-day clock starts on the date of discovery — not when your investigation concludes. Acting immediately and documenting everything are the two most important things you can do.

A complete guide to HIPAA breach response — from the moment of discovery through notification to HHS, individuals, and media. Includes the four-factor risk assessment, deadlines, and role-specific responsibilities.

medcomply.ai editorial teamPublished May 11, 2026Updated May 11, 202612 min read

A potential HIPAA breach is one of the highest-pressure situations a healthcare organization faces. The steps you take in the first hours and days after discovery have direct consequences for your legal exposure, your patients, and your relationship with OCR. This guide walks through exactly what to do — in order.

The moment of discovery: what to do first

The most important thing to understand about breach response is that the 60-day clock starts the moment anyone at your organization knows or should have known about the incident — not when you confirm it is a breach, and not when your investigation concludes.

45 CFR §164.404(b)

When a potential breach is discovered — whether by a front desk employee, an IT administrator, or a clinical staff member — four things must happen immediately:

1. Report it internally. Every employee must know to report potential incidents to the privacy officer or designated security official immediately. A workforce member who sits on a potential breach out of fear of getting in trouble is creating a much worse situation. Document the exact date and time the incident was first discovered by anyone at your organization.

2. Contain the incident. Stop the bleeding before investigating the scope. If systems are compromised, disconnect affected devices from the network. If a physical document was improperly disclosed, attempt to retrieve it. If access credentials were compromised, disable them. Containment does not wait for investigation.

3. Preserve evidence. Do not delete logs, reset systems, or alter anything related to the incident before forensic review. Evidence preservation is critical for your four-factor risk assessment and for any OCR investigation that follows.

4. Engage your response team. Notify your privacy officer, legal counsel, and IT security immediately. For larger incidents consider engaging a HIPAA attorney before taking further action — communications made to and from legal counsel may be protected by attorney-client privilege, which can be valuable if OCR investigates.

Warning

Do not wait until you are certain it is a breach before starting your response. HIPAA presumes any impermissible use or disclosure of unsecured PHI is a breach. You must conduct a four-factor risk assessment to determine otherwise — and that assessment takes time. Every day you wait before starting is a day off your 60-day notification window.

Step 1: Determine if PHI was involved

Before conducting the full four-factor assessment, confirm that the incident involved Protected Health Information. If no PHI was involved — for example, a security incident that only touched systems containing general business data — the HIPAA Breach Notification Rule does not apply.

PHI includes any individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate. This includes paper records, electronic records, and verbal communications. It includes the fact that someone is a patient, not just their clinical information.

If PHI was involved, move to Step 2.

45 CFR §160.103

Step 2: Determine if the PHI was unsecured

HIPAA's Breach Notification Rule applies to unsecured PHI — PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption meeting NIST standards or through physical destruction.

45 CFR §164.402

If the PHI was encrypted with a valid encryption key that was not compromised, the safe harbor applies and notification is generally not required. This is one of the strongest arguments for encrypting all ePHI — a breach of encrypted data is not a notifiable breach.

If the PHI was not encrypted, move to Step 3.

The encryption safe harbor is one of the most powerful compliance tools available. If your organization encrypts all ePHI at rest and in transit, a stolen laptop or intercepted transmission does not trigger breach notification. This is why encryption investment pays off directly in breach response scenarios.

Step 3: Check for the three breach exceptions

Even if unsecured PHI was impermissibly used or disclosed, three exceptions to the breach definition exist. If any exception applies, breach notification may not be required — but the determination must be documented.

Exception 1 — Unintentional acquisition by authorized workforce member: An unintentional acquisition, access, or use of PHI by a workforce member acting in good faith within the scope of their authority, if the PHI is not further used or disclosed impermissibly. Example: a staff member who accidentally opens a misdirected email containing another patient's records and immediately closes it without reading or forwarding it.

Exception 2 — Inadvertent disclosure between authorized persons: An inadvertent disclosure between two people at the same organization who are both authorized to access PHI, if the PHI is not further used or disclosed impermissibly. Example: a nurse who accidentally sends a patient summary to the wrong provider within the same health system.

Exception 3 — Inability to retain: A disclosure to an unauthorized person where the covered entity has a good-faith belief that the unauthorized person could not have retained the information. Example: a fax sent to the wrong number where the recipient immediately confirmed by phone that they destroyed it without reading it.

Warning

These exceptions are interpreted narrowly by OCR. Exception 3 has been applied to paper faxes but is unlikely to apply to electronic disclosures — a recipient of an email containing PHI can retain it without any action. When in doubt, do not rely on an exception without legal review.

Step 4: Conduct the four-factor risk assessment

If no exception applies, you must conduct the four-factor risk assessment to determine whether there is a low probability that the PHI has been compromised. This is the analysis that determines whether notification is required.

45 CFR §164.402(2)

Factor 1 — Nature and extent of PHI involved

What types of identifiers were included? How many individuals are affected? What types of health information were involved? PHI that includes Social Security numbers, financial information, or particularly sensitive diagnoses (HIV status, mental health, substance use disorder) carries higher risk than PHI with fewer identifiers. The more sensitive the data, the higher the risk of compromise.

Factor 2 — Who accessed or could have accessed the PHI

Who is the unauthorized recipient? A misdisclosure to another covered entity carries lower risk than a disclosure to an unknown third party. A disclosure to a known individual who has provided written confirmation of destruction carries lower risk than a disclosure to a cybercriminal who specifically targeted your systems.

Factor 3 — Whether the PHI was actually acquired or viewed

Is there evidence that the unauthorized person actually accessed the PHI? For system intrusions, forensic analysis may be able to determine whether data was merely accessed versus actually exfiltrated. For a misdirected fax, did the recipient confirm they destroyed it unread? Evidence that PHI was not actually viewed significantly reduces the probability of compromise — but the burden of proof is on your organization.

Factor 4 — Extent to which risk has been mitigated

What steps have you taken to reduce the risk? Obtaining a signed confidentiality agreement from an unauthorized recipient, retrieving misdirected documents, or disabling compromised credentials all contribute to risk mitigation. Document every mitigation step with dates.

The outcome: If your four-factor assessment concludes there is a low probability that the PHI has been compromised, you are not required to send breach notifications — but you must document your assessment thoroughly. OCR may review it.

If your assessment cannot conclude low probability — or if you have any reasonable doubt — treat it as a notifiable breach and proceed to Step 5.

Step 5: Determine the scope and notify internally

Before sending external notifications, determine the full scope of the breach:

  • How many individuals are affected?
  • What specific PHI was involved for each individual?
  • What is the date of the breach and the date of discovery?
  • What systems, locations, or processes were involved?
  • Has the vulnerability been contained?

Assemble a complete list of affected individuals with their last known contact information. This list drives your notification process.

Step 6: Send notifications within 60 days

If the breach is notifiable, covered entities must complete three types of notification — all within 60 days of discovery.

Individual notification

45 CFR §164.404

Notify every affected individual by first-class mail to their last known address. If the individual has agreed to electronic communication, email may be used. For individuals whose contact information is insufficient or out of date, substitute notice is required.

What the notification must include:

  • A brief description of what happened and when
  • A description of the PHI that was involved
  • Steps individuals should take to protect themselves (credit monitoring, fraud alerts, etc.)
  • What you are doing to investigate and mitigate
  • Contact information including a toll-free phone number

Write the notification in plain language. Patients who receive breach notifications are often frightened and confused — clarity and empathy matter.

Substitute notice: If you have insufficient contact information for 10 or more individuals, post a conspicuous notice on your website for at least 90 days, or provide notice through major print or broadcast media in the geographic area where the affected individuals likely reside.

HHS notification

45 CFR §164.408

Breaches affecting 500 or more individuals: Report to HHS immediately — at the same time as individual notification — through the HHS breach portal at ocrportal.hhs.gov. These breaches are published publicly on the HHS "Wall of Shame."

Breaches affecting fewer than 500 individuals: Log the breach and include it in your annual breach report to HHS, submitted no later than 60 days after the end of the calendar year in which the breach occurred.

Media notification

45 CFR §164.406

For breaches affecting 500 or more residents of a state or jurisdiction, notify prominent media outlets serving that state or jurisdiction — at the same time as individual and HHS notification. The media notification must contain the same information as individual notification.

Step 7: Business associate responsibilities

If you are a business associate — not a covered entity — your breach notification obligation runs to the covered entity, not to individuals directly.

45 CFR §164.410

You must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your notification must include:

  • The identity of each individual whose PHI was involved (to the extent known)
  • A description of the PHI involved
  • A description of what happened
  • What mitigation steps you have taken

Check your BAA — it likely requires notification within a shorter timeframe than 60 days. Many BAAs require 72-hour or 30-day notification. Your contractual obligation may be stricter than the regulatory minimum.

Step 8: Document everything

OCR's enforcement pattern makes one thing clear: organizations that cannot produce documentation of their breach response face far worse outcomes than those that can. Your breach response documentation should include:

  • The date and time of discovery and by whom
  • A complete timeline of response actions
  • The four-factor risk assessment with supporting evidence
  • Copies of all notifications sent with dates
  • Evidence of HHS portal submission
  • Corrective action steps taken to prevent recurrence
  • All legal and privacy officer communications

Retain all breach documentation for six years from the date of creation or the date it was last in effect — whichever is later.

45 CFR §164.316(b)(2)

Role-specific responsibilities

Privacy officer / compliance officer: Lead the four-factor risk assessment. Coordinate legal counsel engagement. Oversee notification drafting and delivery. File with HHS. Maintain the breach log. Direct corrective action.

IT / security team: Contain the incident immediately. Preserve forensic evidence. Conduct technical investigation. Identify scope of PHI accessed. Implement technical remediation.

Legal counsel: Advise on applicability of exceptions and exceptions. Review notification letters. Assess state law requirements. Advise on OCR response strategy if investigation follows.

Executive leadership: Authorize resources for response. Approve notification communications. Engage cyber insurance carrier immediately. Prepare for potential OCR inquiry.

Front desk / administrative staff: Report any suspected incidents immediately. Cooperate with the investigation. Do not discuss the incident with patients, media, or unauthorized personnel.

State law considerations

HIPAA breach notification requirements exist alongside — not instead of — state breach notification laws. Many states impose:

  • Shorter deadlines — California requires notification in the most expedient time possible. Several states require notification within 30 days or less.
  • Broader definitions — Some state laws cover categories of information beyond HIPAA PHI.
  • Additional requirements — Some states require credit monitoring offers, attorney general notification, or specific notification formats.

New Jersey specifically requires notification to the Division of State Police in addition to individuals for breaches of computerized records. If you operate in New Jersey or serve New Jersey residents, ensure your breach response procedures address this requirement.

What happens if OCR investigates

If your breach affects 500 or more individuals, OCR will receive your report and may open an investigation. OCR investigations typically request:

  • Your breach response documentation
  • Your most recent risk analysis
  • Evidence of risk management actions
  • Your policies and procedures
  • Workforce training records

Organizations with documented compliance programs — even imperfect ones — consistently receive more favorable treatment than those that have not been managing compliance proactively. A well-documented breach response that demonstrates good-faith action can be the difference between a corrective action plan and a significant civil money penalty.

Note

Use medcomply.ai's Breach Notification Checker tool to walk through the four-factor risk assessment for any specific incident. The tool generates a downloadable incident assessment report you can include in your breach response documentation.

The 60-day clock starts at discovery, not at the conclusion of your investigation. Document the discovery date immediately, contain the incident, engage legal counsel, and begin your four-factor assessment — all within the first 24-48 hours. Every action you take after that should be documented with dates and responsible parties. Your documentation is your defense.

Sources & citations

  • 45 CFR §§164.400-414 — Breach Notification RuleOpen
  • HHS OCR Breach Notification GuidanceOpen
  • 45 CFR §164.402 — Definition of BreachOpen
  • 45 CFR §164.404 — Individual NotificationOpen
  • 45 CFR §164.408 — HHS NotificationOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

When does the 60-day breach notification clock start?
The 60-day clock starts on the date the breach is discovered — not the date your investigation concludes, not the date you confirm the full scope, and not the date your legal team finishes reviewing. Discovery occurs when any member of your workforce knows or should have known of the breach. Document the exact date and time of discovery immediately.
What is the four-factor risk assessment?
The four-factor risk assessment is the analysis required to determine whether a breach has a low probability of compromising PHI — the standard for avoiding notification. The four factors are: (1) the nature and extent of PHI involved, (2) who accessed or could have accessed the PHI, (3) whether PHI was actually acquired or viewed, and (4) the extent to which risk has been mitigated.
Do we have to notify affected individuals even if we don't know who they all are?
Yes — you must notify to the extent possible. If you cannot reach some individuals through first-class mail, substitute notice is required. This includes posting on your website for 90 days or providing notice through major print or broadcast media in the affected area. You cannot delay or forgo notification simply because you lack complete contact information.
What is the difference between a breach and a security incident?
A security incident is any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations. A breach is a specific type of security incident involving unsecured PHI that meets the HIPAA definition. Not every security incident is a breach — but every incident must be assessed to determine whether it meets the breach definition.
Does a business associate have to notify patients directly?
No. A business associate must notify the covered entity of the breach within 60 days of discovery. The covered entity is then responsible for notifying affected individuals, HHS, and the media. The only exception is if the BAA specifically authorizes the business associate to provide notification on behalf of the covered entity.
What should our breach notification letter to patients include?
Individual notification must include: a brief description of what happened and the date of the breach and discovery, a description of the PHI involved, steps individuals should take to protect themselves, a brief description of what you are doing to investigate and mitigate harm, and contact information including a toll-free number. Write it in plain language.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.