Every PHI-involved incident needs a finalized breach review, every notification obligation carries a deadline, and the annual HHS log for sub-500 breaches has a March 1 date on it.
The rule runs on a presumption and a burden of proof. An incident is a breach unless you can show otherwise, which means the assessment is not optional and neither is writing it down.
Your breach notification policy covers what counts as a breach, notifying families, notifying HHS with the concurrent requirement at five hundred or more, media notice above five hundred in a state, vendor-discovered breaches, who leads the four-factor assessment, and the documentation and burden of proof that sits behind all of it.
Nine requirements:
The annual log requirement is the one clinics forget entirely. Small breaches get handled individually and then never aggregated, and the March 1 filing passes unnoticed.
The system tracks that a finalized breach review exists for each incident and what it determined. It does not check the four factors individually, that analysis lives in your policy and in the content of the review someone wrote. It also does not send notifications or confirm they arrived. It tracks the obligation, its deadline, and whether the record says it was met.
An incident log where every PHI-involved entry has a documented breach determination. Notification obligations with deadlines and evidence attached. An annual HHS log for the small breaches. Under a rule built on burden of proof, a record that carries the burden.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.