You think you had a breach. What now.

The first hour, the decision that determines everything, the four-factor assessment, and every notification clock, written for the day you actually need it.

Last verified: 2026-07-12

Something happened. A tablet is missing, an email went to the wrong family, a login looks wrong, a vendor just called. You searched, and you are here. Read the first section now and the rest when the immediate steps are done.

One reassurance before the law, because it is true and it matters: the rule does not punish you for having a bad day. It punishes silence, delay, and the absence of a record. Everything below is about being on the right side of those three.

The first hour

Contain it. Whatever is still happening, stop it. Remote-lock or remote-wipe the missing device. Disable the suspicious login. Recall the email if your system can. Ask the wrong recipient, politely and in writing, to delete it and confirm. Take the compromised machine off the network; do not wipe or reset it, because it is now evidence.

“The rule does not punish you for having a bad day. It punishes silence, delay, and the absence of a record.”

Write down what you know, with times. What happened, when it happened if known, when and how you learned of it, whose information may be involved, what kind of information, and what you have done so far. Rough notes now, cleaned up later. Every clock in this rule runs from discovery, and this record is where discovery gets its timestamp.

Tell the officer. Your privacy or security officer takes it from here (45 CFR 164.308(a)(6) is why you have an incident procedure). If that officer is you, you have just been told.

Do not delete anything. Not the phishing email, not the logs, not the mistaken message. The burden of proof in this rule is yours (45 CFR 164.414), and evidence you destroyed cannot carry it.

Loop in help proportionate to the event. A misdirected email to one family is handled in-house. A ransomware screen, a stolen laptop full of records, or anything involving law enforcement is a call to a lawyer and, if you have cyber insurance, to the carrier, today.

The question that decides everything

Once contained, the legal analysis starts, and it is one question with two parts: was there an impermissible acquisition, access, use, or disclosure of PHI, and was that PHI unsecured (45 CFR 164.402)?

The encryption off-ramp comes first. If the lost device or intercepted data was encrypted consistent with the standards in HHS guidance, and the key was not compromised with it, the PHI was not unsecured, and the breach notification machinery generally does not fire. This is the moment the encryption decision you made months ago pays for itself, or does not. A lost encrypted tablet with the passcode nowhere near it: document the encryption status and the assessment, and in most cases you are done. A lost unencrypted one: keep reading.

Then the exclusions. Three narrow situations are defined out of breach entirely: a workforce member’s unintentional, good-faith access within their job that goes no further; an accidental disclosure between two authorized people inside the organization that goes no further; and a disclosure where you have a good-faith belief the recipient could not reasonably have retained the information. The fax pulled back before anyone read it, the note handed to the wrong clinician who handed it straight back: these can qualify. Document why.

Then the presumption. Everything else is presumed to be a breach unless you demonstrate, through a documented risk assessment, a low probability that the PHI was compromised, weighing at least four factors: (1) the nature and extent of the PHI involved, including the identifiers and the likelihood of re-identification; (2) the unauthorized person who used it or received it; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk has been mitigated.

Be honest with the four factors, because they are evidence, not a form. A misdirected progress note to another HIPAA-covered clinic that confirmed deletion in writing scores very differently from a stolen laptop of session videos. If the assessment honestly lands at low probability, document it and keep it six years; that document is what stands between you and the presumption. If it does not land there, or you cannot honestly tell, it is a breach, and you notify. When in doubt, the safe and lawful answer is to treat it as one.

The clocks

All of them run from discovery: the first day anyone in your organization other than the person who caused it knew, or would have known with reasonable diligence (45 CFR 164.404(a)(2)). Not the day leadership was told. Not the day you finished investigating.

Individuals: without unreasonable delay, and no later than 60 calendar days from discovery (45 CFR 164.404(b)). Sixty is the ceiling, not the target; if you could reasonably notify in two weeks, waiting until day 59 is itself a violation. First-class mail to the last known address, or email where the family agreed to electronic notice. The notice says, in plain language: what happened and when, what information was involved, what they should do, what you are doing, and how to reach you. If contact information is bad for ten or more people, substitute notice applies: a 90-day website posting or media notice plus a toll-free number.

HHS: depends on the count (45 CFR 164.408). Five hundred or more individuals: notify HHS at the same time as the individuals, through the OCR breach portal. Fewer than 500: log it, and submit the log to HHS within 60 days after the calendar year ends. The under-500 annual log is the one small clinics forget; a five-family breach in March still gets reported, just on the annual cycle.

Media: only over 500 in one state or jurisdiction (45 CFR 164.406): prominent outlets serving the area, same 60-day outer limit, same content as the individual notice.

If a vendor had the breach: the business associate’s duty is to notify you, within 60 days of its discovery at the latest (45 CFR 164.410), and then every clock above is yours, running from your discovery. This is why your BAAs should require vendor reporting in days, not weeks.

If law enforcement asks you to hold: a written request specifying the time delays the notices for that period; an oral request, documented, delays them at most 30 days (45 CFR 164.412).

After the notices

Fix the thing that failed, and write down that you fixed it: the corrective action is part of the record, and under the penalty rules, violations corrected quickly are treated categorically better than ones left open. Feed the event back into your risk analysis, because an incident is an unscheduled, expensive discovery about your actual risks. Retain everything, the assessment, the notices, the dates, the fixes, for six years, because 45 CFR 164.414(b) puts the burden on you to prove you did all of this, and the proof is the paper.

And the honest postscript: a reported breach with a clean record behind it, fast containment, an honest assessment, timely notices, a documented fix, is a survivable event that OCR sees hundreds of times a year. The catastrophic version is the one discovered late, assessed never, and notified after the deadline. Which of those two stories you get to tell was mostly decided by what you had in place before the bad day. That is the whole argument for the boring work.

The short version

  • First hour: contain it, write down what you know with times, and tell your privacy or security officer. Do not delete anything, including the evidence of what happened.
  • The legal question is not was this bad; it is: was there an impermissible acquisition, access, use, or disclosure of unsecured PHI.
  • If the device or data was properly encrypted and the key is safe, it is not unsecured PHI and the notification machinery generally does not fire.
  • Otherwise it is presumed a breach unless a documented four-factor assessment shows a low probability of compromise; silence with no assessment is not an option.
  • Clocks: individuals within 60 days of discovery; HHS at the same time if 500 or more affected, or in the annual log if fewer; media if over 500 in one state. Discovery runs on what you should have known.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

The record you need is the one you kept before.

Breach response runs on evidence you already have: the device register, the encryption status, the access logs, the vendor list. WiseUpHIPAA keeps that record as your clinic operates, so the worst day starts with answers instead of archaeology.