hipaa.systems
Event · Act now

You had a data breach

A misdirected email, a lost laptop, a hacked mailbox. What to do, in order, in the first days — and the deadlines that start running when you discover it.

Steps 9Checked 2026-10-05

At a glance

After a suspected HIPAA breach, contain it, preserve evidence and work out what protected health information was involved. Unless a documented four-factor assessment shows a low probability of compromise, treat it as a breach: notify affected individuals within 60 days of discovery, report to HHS, and notify the media if more than 500 residents of a state are affected. Properly encrypted PHI is not unsecured and may not require notification.

Clock startsWhen the breach is discovered
Notify individualsNo later than 60 days after discovery
Report to HHSWith individual notices if 500+; annual log if fewer
Decide withA documented four-factor risk assessment
VendorsBusiness associates must report breaches to you within 60 days

What to do, in order

  1. Contain it: recall or follow up on the misdirected message, lock or wipe the device, reset passwords and revoke sessions on the affected account.
  2. Preserve evidence: keep logs, emails and notes on what happened and when you found out — the 60-day clock starts at discovery.
  3. Work out what PHI was involved, whose, and who could have seen it.
  4. If the PHI was properly encrypted and the key was not compromised, document that — notification duties apply to unsecured PHI.
  5. Run and document the four-factor risk assessment to decide whether there is a low probability the PHI was compromised.
  6. If a vendor was involved, get their written account — business associates must report breaches to you.
  7. If it is a breach, notify affected individuals without unreasonable delay and within 60 days of discovery.
  8. Report to HHS: immediately alongside individual notices for 500+ people, or in your annual log for fewer. Notify media if more than 500 residents of a state are affected.
  9. Fix the cause and update your risk analysis.

Most breaches in small practices are not hacks — they are an email sent to the wrong address, an unencrypted laptop left in a car, or a staff member opening records they had no reason to see. HIPAA treats any impermissible use or disclosure of PHI as a breach unless you can document a low probability that the information was compromised.

That is why the documentation matters as much as the response: if you decide an incident was not a breach, your written four-factor assessment is what shows OCR why. State breach-notification laws may add their own requirements and deadlines, so check those alongside HIPAA.

If the incident is large, involves a cyberattack, or you are unsure how to assess it, this is the moment to bring in an incident response specialist or a healthcare privacy attorney.

Who can help

Nothing here yet.

Relevant requirements

Applies to

Frequently asked questions

What should a small practice do first after a breach?

Contain it — recall the message, lock or wipe the device, reset passwords — and write down what happened and when you discovered it.

Do I have to report a small breach to HHS?

Yes. Breaches affecting fewer than 500 people are logged and reported to HHS no later than 60 days after the end of the calendar year.