HIPAA Breach Response Timeline
Hour-by-hour and day-by-day procedures for responding to PHI breaches, including notification requirements within 60 days.
Quick Answer: HIPAA's 60-Day Notification Rule
Upon discovery of a PHI breach affecting 500+ individuals, you must notify affected individuals, media, and HHS within 60 days. Breaches affecting fewer than 500 individuals require notification within 60 days but media notification is state AG reporting only. The 60-day clock starts from discovery, not from when the breach occurred.
CRITICAL: Time-Sensitive Requirements
Failure to notify within 60 days results in significant OCR fines. Average breach notification costs exceed $400 per individual. Immediate action is required upon breach discovery.
Phase 1: Immediate Response (Hour 0-4)
1
Initial Detection & Containment
First 4 hours after discovery
| Timeframe | Action | Responsible Party |
|---|---|---|
| Hour 0 | Activate breach response team. Notify Privacy & Security Officer immediately. | IT/Security Staff |
| Hour 0-1 | Isolate affected systems and/or accounts. Stop unauthorized access immediately. | IT Manager |
| Hour 1 | Notify organization leadership and legal counsel. Brief CEO/Executive Director. | Privacy Officer |
| Hour 1-2 | Preserve all evidence. Do not delete logs or evidence. Secure physical devices. | IT & Security Team |
| Hour 2-3 | Determine scope: How many records affected? What data was exposed? Who had access? | Privacy Officer & IT |
| Hour 3-4 | Initial assessment: Determine if notification is required (low probability assessment). | Privacy Officer & Legal |
-
Activate Incident Response Plan Execute pre-established breach response protocol. Notify all team members listed in response plan.
-
Document Time of Discovery Record exact date and time breach was discovered. This starts the 60-day clock for notifications.
-
Secure Legal Representation Engage healthcare attorney experienced in HIPAA breaches immediately for guidance.
-
Notify Insurance Carrier Alert malpractice and cyber liability insurance carriers within first hours for coverage assessment.
Phase 2: Investigation (Days 1-7)
2
Comprehensive Breach Investigation
Days 1-7 after discovery
| Day | Investigation Task | Deliverable |
|---|---|---|
| Day 1 | Forensic analysis begins. Determine breach scope and nature of exposed data. | Preliminary scope report |
| Day 2-3 | Identify all affected individuals. Compile list of SSNs, names, dates of birth, addresses. | Master breach list (encrypted) |
| Day 3-4 | Determine low probability of compromise (if applicable). Can breach risk be ruled out? | Low probability assessment memo |
| Day 4-5 | Complete forensic investigation. Root cause analysis. Identify unauthorized access proof. | Forensic investigation report |
| Day 5-7 | Determine notification requirement. Notification type (individual, media, state AG). | Notification decision document |
-
Conduct Forensic Analysis Engage forensic investigators if needed. Determine exactly what was accessed and by whom.
-
Create Affected Individual List Compile complete list with names, contact information, and specific data elements exposed for each person.
-
Assess Low Probability of Compromise Document evidence that information was accessed without reasonable cause to believe unauthorized use occurred.
-
Determine Notification Requirements Decide: Individual notification needed? Media notification? State AG notification? Credit monitoring required?
Phase 3: Notification (Days 8-40)
3
Notify Affected Individuals & Authorities
Days 8-40 (must complete by Day 60)
| Deadline | Notification Type | Requirements |
|---|---|---|
| Day 30 | Individual Notification (if required) | Mail or email to affected individuals. Include breach description, data elements involved, mitigation steps. |
| Day 30 | Media Notification (if 500+) | Prominent media in affected state(s). Include names of affected individuals (optional in some cases). |
| Day 30 | State Attorney General (if 500+) | Written notification with same information as media. Documentation of breach response steps. |
| Day 60 | HHS Notification (if 500+) | File report on HHS Breach Notification Portal with affected count, data elements, discovery date, notification date. |
| Day 10-60 | Credit Monitoring (if SSN exposed) | Offer 12-24 months of free credit monitoring to affected individuals. Provide enrollment instructions. |
-
Draft Individual Notification Letters Create template with required elements: what happened, data involved, steps taken, credit monitoring info, contact details.
-
Prepare Media Statement Write press release summarizing breach, affected individuals, response measures, and contact information for inquiries.
-
State Attorney General Notification Send written notification to AG offices in all states where individuals reside. Include forensic details and mitigation plan.
-
HHS Breach Notification Report File official report with HHS Office for Civil Rights within 60 days. Include all required data elements.
-
Arrange Credit Monitoring Contract with credit monitoring service. Provide beneficiaries access codes and enrollment instructions.
Phase 4: Post-Breach Activities (Days 41-365)
4
Remediation & Long-Term Actions
Days 41 through 1 year post-breach
-
Implement Corrective Actions Execute all remediation steps identified in forensic investigation. Patch vulnerabilities, strengthen access controls, update policies.
-
Conduct Follow-Up Risk Assessment Verify that breach vulnerability has been eliminated. Test systems to confirm fix effectiveness.
-
Update Breach Response Plan Document lessons learned. Update incident response procedures based on actual breach response experience.
-
Conduct Staff Training Train all staff on what went wrong and how to prevent similar breaches. Emphasize individual accountability.
-
Monitor Credit Monitoring Compliance Verify credit monitoring services are properly offered. Address any individual complaints or issues with service.
-
Prepare for OCR Investigation Maintain complete documentation of breach investigation, notifications, and corrective actions for potential OCR audit.
-
Review Business Associate Agreements If breach involved vendor, evaluate BA agreement for breach notification requirements and liability provisions.
Key Notification Thresholds
- 500+ affected: Media notification required + State AG notification + HHS notification
- Fewer than 500: Individual notification + State AG (if required by state law) + HHS notification
- Low probability of compromise: May not require notification if assessment is documented and defensible
- Encrypted data: Generally not considered breach unless encryption key was also compromised
Documentation Checklist
Maintain complete records for OCR compliance:
- Date and time breach was discovered (documentation of discovery time)
- Date and time breach likely occurred (if different from discovery)
- Complete forensic investigation report with findings
- List of all affected individuals with SSNs, names, dates of birth
- Specific data elements involved in breach
- Evidence and determination regarding low probability of compromise (if applicable)
- Copies of all notification letters sent to individuals
- Media notification statement and distribution records
- State Attorney General notification copies
- HHS Breach Notification Portal submission confirmation
- Credit monitoring service agreement and enrollment details
- Corrective action plan with implementation timeline
- Staff training records