1. Purpose
To ensure privacy and security incidents are reported, contained, assessed and, where they constitute a breach of unsecured protected health information, notified to affected individuals, the Secretary of Health and Human Services and the media within the required timeframes.
2. Scope
Applies to all suspected or confirmed incidents involving protected health information in any form, including lost or stolen devices, misdirected email or fax, unauthorised access, ransomware, improper disposal, verbal disclosure and incidents at business associates.
3. Responsibilities
- All Workforce Members: Report any suspected incident to the HIPAA Privacy Officer or HIPAA Security Officer immediately, and never attempt to conceal or independently resolve it.
- HIPAA Privacy Officer: Leads the risk assessment, breach determination, notification content and the incident log.
- IT Director & HIPAA Security Officer: Leads technical containment, forensic preservation and system remediation.
- Chief Executive Officer: Approves external notifications and any public statement.
4. Definitions
- Security incident
- The attempted or successful unauthorised access, use, disclosure, modification or destruction of information, or interference with system operations.
- Breach
- The acquisition, access, use or disclosure of protected health information in a manner not permitted by the Privacy Rule which compromises its security or privacy.
- Unsecured PHI
- PHI that is not rendered unusable, unreadable or indecipherable to unauthorised persons through encryption or destruction meeting HHS guidance.
- Four-factor risk assessment
- The documented assessment of the nature and extent of the PHI involved, the unauthorised person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
5. Procedure
- Report any suspected privacy or security incident to the HIPAA Privacy Officer or HIPAA Security Officer immediately upon discovery, by telephone and in writing, regardless of the day or hour.
- Record the incident in the incident log with a unique identifier, the date and time of discovery, the reporter, and the initial description; the discovery date starts the regulatory clock.
- Contain the incident at once: disable compromised accounts, isolate affected devices from the network, recall misdirected email where possible, and secure or retrieve lost records.
- Preserve evidence, including logs, devices and email headers, before remediation, and do not wipe or re-image a device until the Security Officer authorises it.
- Determine whether the information involved was protected health information and whether it was unsecured; PHI encrypted to HHS standards, or properly destroyed, is not unsecured and does not trigger breach notification.
- Identify the specific individuals affected and the specific data elements involved, and quantify the number of individuals.
- Perform and document the four-factor risk assessment to determine the probability that the protected health information has been compromised, considering the nature and extent of the information including identifiers and likelihood of re-identification, the unauthorised person involved, whether the information was actually acquired or viewed, and the extent of mitigation.
- Presume a breach unless the four-factor assessment demonstrates a low probability of compromise, or an exception applies such as an unintentional good-faith acquisition by a workforce member acting within scope, an inadvertent disclosure between authorised persons at the same entity, or a disclosure where the recipient could not reasonably have retained the information.
- Notify affected individuals in writing by first-class mail, or by email where the individual has agreed to electronic notice, without unreasonable delay and in no case later than sixty calendar days after discovery of the breach.
- Include in the individual notice a brief description of what happened, the date of the breach and date of discovery, the types of information involved, steps individuals should take to protect themselves, what the site is doing to investigate and mitigate, and contact procedures including a toll-free number, an email address, a website or a postal address.
- Use substitute notice where contact information is insufficient or out of date: a website posting or major print or broadcast media notice, with a toll-free number active for at least ninety days, when ten or more individuals cannot be reached.
- Where the breach affects five hundred or more individuals, notify prominent media outlets serving the state or jurisdiction without unreasonable delay and no later than sixty calendar days after discovery, and notify the Secretary of Health and Human Services contemporaneously through the HHS portal.
- Where the breach affects fewer than five hundred individuals, log it and notify the Secretary through the HHS portal no later than sixty calendar days after the end of the calendar year in which the breach was discovered.
- Where the incident occurred at a business associate, obtain the associate's written notification and assessment, and determine the site's own notification obligations; a business associate must notify the covered entity without unreasonable delay and no later than sixty calendar days after discovery.
- Notify the IRB and sponsor where research subjects or study data are affected, and process the event as a deviation under CON-002 and, if applicable, as an unanticipated problem under REG-002.
- Open a CAPA under QA-002 for every confirmed breach and for any incident with a systemic root cause, and verify effectiveness of the corrective action.
- Never retaliate against a person for reporting an incident or filing a complaint, and never require an individual to waive their rights as a condition of service.
- Retain all incident documentation, risk assessments, notifications and proof of mailing for at least six years from the date of the record or its last effective date.
6. References
- 45 CFR Part 164, Subpart D — Notification in the Case of Breach of Unsecured PHI
- 45 CFR 164.404 — Notification to individuals
- 45 CFR 164.406 — Notification to the media
- 45 CFR 164.408 — Notification to the Secretary
- 45 CFR 164.410 — Notification by a business associate
- 45 CFR 164.530 — Administrative requirements, complaints and sanctions
- HIP-001 HIPAA Privacy Rule in Research
- HIP-002 HIPAA Security Rule Safeguards
7. Revision History
- v2.0 · Mar 28, 2023 — Added detailed four-factor assessment template and substitute notice rules.
- v3.0 · Feb 23, 2026 — Added business associate notification handling and evidence preservation requirements.
— End of document —
Marguerite Okonjo-Bell
Approved · Sep 25, 2026, 09:57 AM UTC
Ingrid Halvorsen, MD
Read and understood · Jul 16, 2026, 10:57 AM UTC
Thaddeus Moreau, MD
Read and understood · Jun 26, 2026, 02:57 PM UTC
Cornelius Abara, MD
Read and understood · Aug 15, 2026, 08:57 AM UTC
Rosalind Achterberg, DO
Read and understood · Sep 16, 2026, 09:57 AM UTC
Hyun-Woo Baek, MD
Read and understood · Sep 27, 2026, 10:57 AM UTC
Fatoumata Diallo, MD
Read and understood · Sep 16, 2026, 01:57 PM UTC
Silas Wentworth, PA-C
Read and understood · Jun 25, 2026, 09:57 AM UTC
Noor Al-Rashidi, NP
Read and understood · Sep 19, 2026, 10:57 AM UTC
Beatrix Calloway
Read and understood · Jul 09, 2026, 11:57 AM UTC
Sunniva Lindqvist, RN
Read and understood · Jul 27, 2026, 10:57 AM UTC
Tomasz Wierzbicki
Read and understood · Jun 22, 2026, 09:57 AM UTC
Anaya Bhattacharya
Read and understood · Aug 20, 2026, 10:57 AM UTC
Meredith Sowande
Read and understood · Jul 14, 2026, 12:57 PM UTC
Lucinda Ferreira-Mota
Read and understood · Jul 15, 2026, 12:57 PM UTC
Kwabena Asante-Mensah
Read and understood · Sep 20, 2026, 10:57 AM UTC
Delphine Rousseau
Read and understood · Jul 28, 2026, 08:57 AM UTC
Yusra Abdalla
Read and understood · Jun 17, 2026, 08:57 AM UTC
Milo Ferrante
Read and understood · Aug 12, 2026, 12:57 PM UTC
Saoirse MacLochlainn, RN
Read and understood · Sep 25, 2026, 01:57 PM UTC
Anneliese Brummer
Read and understood · Sep 10, 2026, 11:57 AM UTC
Jamal Whitfield
Read and understood · Jul 09, 2026, 01:57 PM UTC
Auberon Castellanos
Read and understood · Sep 23, 2026, 08:57 AM UTC
Ilse Vermeulen
Read and understood · Aug 17, 2026, 12:57 PM UTC
Chiamaka Eze
Read and understood · Aug 04, 2026, 08:57 AM UTC
Sebastián Duarte
Read and understood · Jul 05, 2026, 08:57 AM UTC
Viktor Salminen
Read and understood · Sep 26, 2026, 12:57 PM UTC
Rosalie Beauchamp
Read and understood · Aug 24, 2026, 10:57 AM UTC
Tallulah Winthrop
Read and understood · Sep 20, 2026, 10:57 AM UTC
Georgi Dimitrov
Read and understood · Aug 27, 2026, 02:57 PM UTC
Ayanna Prescott
Read and understood · Aug 09, 2026, 10:57 AM UTC
Bartholomew Ng'ang'a, PharmD
Read and understood · Aug 31, 2026, 11:57 AM UTC
Emil Kowalczyk
Read and understood · Jun 30, 2026, 11:57 AM UTC
Marisol Echeverría
Read and understood · Aug 21, 2026, 09:57 AM UTC
Desmond Achebe
Read and understood · Jun 29, 2026, 03:57 PM UTC
Ingrid Bäckström
Read and understood · Jun 17, 2026, 02:57 PM UTC
Nadia Boulahrouz
Read and understood · Aug 31, 2026, 08:57 AM UTC
Temperance Ajayi
Read and understood · Jul 25, 2026, 01:57 PM UTC
Evelyn Marchetti-Sung
Read and understood · Jul 29, 2026, 09:57 AM UTC
Obadiah Lindgren
Read and understood · Jun 08, 2026, 11:57 AM UTC
Farrukh Tashkentov
Read and understood · Sep 25, 2026, 02:57 PM UTC
Ravi Choudhury
Read and understood · Sep 19, 2026, 11:57 AM UTC
Birgitta Sjöberg
Read and understood · Jun 28, 2026, 08:57 AM UTC
Malachi Osei-Tutu
Read and understood · Sep 10, 2026, 08:57 AM UTC
Esperanza Villalobos
Read and understood · Sep 12, 2026, 02:57 PM UTC
Winston Ferraro-Kline
Read and understood · Jul 06, 2026, 02:57 PM UTC
Adaeze Okafor
Read and understood · Jul 30, 2026, 08:57 AM UTC
Jasper Lindholm
Read and understood · Aug 26, 2026, 09:57 AM UTC
Lorelei Krasnova
Read and understood · Jun 28, 2026, 08:57 AM UTC
Ezekiel Barrantes
Read and understood · Aug 04, 2026, 11:57 AM UTC
Miriam Sandoval-Reyes
Read and understood · Sep 28, 2026, 02:57 PM UTC