Security Risk Analysis

HIPAA Breach Response Timeline

Hour-by-hour and day-by-day procedures for responding to PHI breaches, including notification requirements within 60 days.

Quick Answer: HIPAA's 60-Day Notification Rule

Upon discovery of a PHI breach affecting 500+ individuals, you must notify affected individuals, media, and HHS within 60 days. Breaches affecting fewer than 500 individuals require notification within 60 days but media notification is state AG reporting only. The 60-day clock starts from discovery, not from when the breach occurred.

CRITICAL: Time-Sensitive Requirements

Failure to notify within 60 days results in significant OCR fines. Average breach notification costs exceed $400 per individual. Immediate action is required upon breach discovery.

Phase 1: Immediate Response (Hour 0-4)

1
Initial Detection & Containment
First 4 hours after discovery
Timeframe Action Responsible Party
Hour 0 Activate breach response team. Notify Privacy & Security Officer immediately. IT/Security Staff
Hour 0-1 Isolate affected systems and/or accounts. Stop unauthorized access immediately. IT Manager
Hour 1 Notify organization leadership and legal counsel. Brief CEO/Executive Director. Privacy Officer
Hour 1-2 Preserve all evidence. Do not delete logs or evidence. Secure physical devices. IT & Security Team
Hour 2-3 Determine scope: How many records affected? What data was exposed? Who had access? Privacy Officer & IT
Hour 3-4 Initial assessment: Determine if notification is required (low probability assessment). Privacy Officer & Legal

Phase 2: Investigation (Days 1-7)

2
Comprehensive Breach Investigation
Days 1-7 after discovery
Day Investigation Task Deliverable
Day 1 Forensic analysis begins. Determine breach scope and nature of exposed data. Preliminary scope report
Day 2-3 Identify all affected individuals. Compile list of SSNs, names, dates of birth, addresses. Master breach list (encrypted)
Day 3-4 Determine low probability of compromise (if applicable). Can breach risk be ruled out? Low probability assessment memo
Day 4-5 Complete forensic investigation. Root cause analysis. Identify unauthorized access proof. Forensic investigation report
Day 5-7 Determine notification requirement. Notification type (individual, media, state AG). Notification decision document

Phase 3: Notification (Days 8-40)

3
Notify Affected Individuals & Authorities
Days 8-40 (must complete by Day 60)
Deadline Notification Type Requirements
Day 30 Individual Notification (if required) Mail or email to affected individuals. Include breach description, data elements involved, mitigation steps.
Day 30 Media Notification (if 500+) Prominent media in affected state(s). Include names of affected individuals (optional in some cases).
Day 30 State Attorney General (if 500+) Written notification with same information as media. Documentation of breach response steps.
Day 60 HHS Notification (if 500+) File report on HHS Breach Notification Portal with affected count, data elements, discovery date, notification date.
Day 10-60 Credit Monitoring (if SSN exposed) Offer 12-24 months of free credit monitoring to affected individuals. Provide enrollment instructions.

Phase 4: Post-Breach Activities (Days 41-365)

4
Remediation & Long-Term Actions
Days 41 through 1 year post-breach
Key Notification Thresholds

Documentation Checklist

Maintain complete records for OCR compliance: