You had a data breach
A misdirected email, a lost laptop, a hacked mailbox. What to do, in order, in the first days — and the deadlines that start running when you discover it.
At a glance
After a suspected HIPAA breach, contain it, preserve evidence and work out what protected health information was involved. Unless a documented four-factor assessment shows a low probability of compromise, treat it as a breach: notify affected individuals within 60 days of discovery, report to HHS, and notify the media if more than 500 residents of a state are affected. Properly encrypted PHI is not unsecured and may not require notification.
| Clock starts | When the breach is discovered |
|---|---|
| Notify individuals | No later than 60 days after discovery |
| Report to HHS | With individual notices if 500+; annual log if fewer |
| Decide with | A documented four-factor risk assessment |
| Vendors | Business associates must report breaches to you within 60 days |
What to do, in order
- Contain it: recall or follow up on the misdirected message, lock or wipe the device, reset passwords and revoke sessions on the affected account.
- Preserve evidence: keep logs, emails and notes on what happened and when you found out — the 60-day clock starts at discovery.
- Work out what PHI was involved, whose, and who could have seen it.
- If the PHI was properly encrypted and the key was not compromised, document that — notification duties apply to unsecured PHI.
- Run and document the four-factor risk assessment to decide whether there is a low probability the PHI was compromised.
- If a vendor was involved, get their written account — business associates must report breaches to you.
- If it is a breach, notify affected individuals without unreasonable delay and within 60 days of discovery.
- Report to HHS: immediately alongside individual notices for 500+ people, or in your annual log for fewer. Notify media if more than 500 residents of a state are affected.
- Fix the cause and update your risk analysis.
Most breaches in small practices are not hacks — they are an email sent to the wrong address, an unencrypted laptop left in a car, or a staff member opening records they had no reason to see. HIPAA treats any impermissible use or disclosure of PHI as a breach unless you can document a low probability that the information was compromised.
That is why the documentation matters as much as the response: if you decide an incident was not a breach, your written four-factor assessment is what shows OCR why. State breach-notification laws may add their own requirements and deadlines, so check those alongside HIPAA.
If the incident is large, involves a cyberattack, or you are unsure how to assess it, this is the moment to bring in an incident response specialist or a healthcare privacy attorney.
Who can help
Nothing here yet.
Relevant requirements
- Notifying patients of a breach →§ 164.402
- Encryption of ePHI →§ 164.312(a)(2)(iv)
- Business associate agreements (BAAs) →§ 164.502(e)
- Security risk analysis →§ 164.308(a)(1)(ii)(A)
Applies to
Frequently asked questions
What should a small practice do first after a breach?
Contain it — recall the message, lock or wipe the device, reset passwords — and write down what happened and when you discovered it.
Do I have to report a small breach to HHS?
Yes. Breaches affecting fewer than 500 people are logged and reported to HHS no later than 60 days after the end of the calendar year.