Breach notification

Breach notification, from incident to obligation

Every PHI-involved incident needs a finalized breach review, every notification obligation carries a deadline, and the annual HHS log for sub-500 breaches has a March 1 date on it.

The rule runs on a presumption and a burden of proof. An incident is a breach unless you can show otherwise, which means the assessment is not optional and neither is writing it down.

The policy is composed from your clinic’s facts

Your breach notification policy covers what counts as a breach, notifying families, notifying HHS with the concurrent requirement at five hundred or more, media notice above five hundred in a state, vendor-discovered breaches, who leads the four-factor assessment, and the documentation and burden of proof that sits behind all of it.

What gets tracked after the policy exists

Nine requirements:

  • Every in-scope incident has a finalized breach review on file, scored against the thirty and sixty day thresholds from discovery.
  • Every breach notification obligation meets its recorded deadline.
  • Completed obligations carry an attestation and supporting evidence.
  • Any sub-five-hundred breaches from the prior year appear on an annual HHS log filed by March 1.
  • Law enforcement delays are documented where claimed.
  • The policy is adopted, reviewed within twelve months, with facts that have not drifted.

The annual log requirement is the one clinics forget entirely. Small breaches get handled individually and then never aggregated, and the March 1 filing passes unnoticed.

What this is, and what it is not

The system tracks that a finalized breach review exists for each incident and what it determined. It does not check the four factors individually, that analysis lives in your policy and in the content of the review someone wrote. It also does not send notifications or confirm they arrived. It tracks the obligation, its deadline, and whether the record says it was met.

What an investigator gets

An incident log where every PHI-involved entry has a documented breach determination. Notification obligations with deadlines and evidence attached. An annual HHS log for the small breaches. Under a rule built on burden of proof, a record that carries the burden.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.