Demo environment — fictional staff and data. Do not enter PHI.

Evelyn Marchetti-Sung

Quality Assurance Director · QCR-0057

Back to library
HIP-003Privacy & Security Incident Response and Breach Notificationv3.0EffectiveEffective Feb 23, 2026HIPAA Compliance
0% read Signed

1. Purpose

To ensure privacy and security incidents are reported, contained, assessed and, where they constitute a breach of unsecured protected health information, notified to affected individuals, the Secretary of Health and Human Services and the media within the required timeframes.

2. Scope

Applies to all suspected or confirmed incidents involving protected health information in any form, including lost or stolen devices, misdirected email or fax, unauthorised access, ransomware, improper disposal, verbal disclosure and incidents at business associates.

3. Responsibilities

  • All Workforce Members: Report any suspected incident to the HIPAA Privacy Officer or HIPAA Security Officer immediately, and never attempt to conceal or independently resolve it.
  • HIPAA Privacy Officer: Leads the risk assessment, breach determination, notification content and the incident log.
  • IT Director & HIPAA Security Officer: Leads technical containment, forensic preservation and system remediation.
  • Chief Executive Officer: Approves external notifications and any public statement.

4. Definitions

Security incident
The attempted or successful unauthorised access, use, disclosure, modification or destruction of information, or interference with system operations.
Breach
The acquisition, access, use or disclosure of protected health information in a manner not permitted by the Privacy Rule which compromises its security or privacy.
Unsecured PHI
PHI that is not rendered unusable, unreadable or indecipherable to unauthorised persons through encryption or destruction meeting HHS guidance.
Four-factor risk assessment
The documented assessment of the nature and extent of the PHI involved, the unauthorised person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.

5. Procedure

  1. Report any suspected privacy or security incident to the HIPAA Privacy Officer or HIPAA Security Officer immediately upon discovery, by telephone and in writing, regardless of the day or hour.
  2. Record the incident in the incident log with a unique identifier, the date and time of discovery, the reporter, and the initial description; the discovery date starts the regulatory clock.
  3. Contain the incident at once: disable compromised accounts, isolate affected devices from the network, recall misdirected email where possible, and secure or retrieve lost records.
  4. Preserve evidence, including logs, devices and email headers, before remediation, and do not wipe or re-image a device until the Security Officer authorises it.
  5. Determine whether the information involved was protected health information and whether it was unsecured; PHI encrypted to HHS standards, or properly destroyed, is not unsecured and does not trigger breach notification.
  6. Identify the specific individuals affected and the specific data elements involved, and quantify the number of individuals.
  7. Perform and document the four-factor risk assessment to determine the probability that the protected health information has been compromised, considering the nature and extent of the information including identifiers and likelihood of re-identification, the unauthorised person involved, whether the information was actually acquired or viewed, and the extent of mitigation.
  8. Presume a breach unless the four-factor assessment demonstrates a low probability of compromise, or an exception applies such as an unintentional good-faith acquisition by a workforce member acting within scope, an inadvertent disclosure between authorised persons at the same entity, or a disclosure where the recipient could not reasonably have retained the information.
  9. Notify affected individuals in writing by first-class mail, or by email where the individual has agreed to electronic notice, without unreasonable delay and in no case later than sixty calendar days after discovery of the breach.
  10. Include in the individual notice a brief description of what happened, the date of the breach and date of discovery, the types of information involved, steps individuals should take to protect themselves, what the site is doing to investigate and mitigate, and contact procedures including a toll-free number, an email address, a website or a postal address.
  11. Use substitute notice where contact information is insufficient or out of date: a website posting or major print or broadcast media notice, with a toll-free number active for at least ninety days, when ten or more individuals cannot be reached.
  12. Where the breach affects five hundred or more individuals, notify prominent media outlets serving the state or jurisdiction without unreasonable delay and no later than sixty calendar days after discovery, and notify the Secretary of Health and Human Services contemporaneously through the HHS portal.
  13. Where the breach affects fewer than five hundred individuals, log it and notify the Secretary through the HHS portal no later than sixty calendar days after the end of the calendar year in which the breach was discovered.
  14. Where the incident occurred at a business associate, obtain the associate's written notification and assessment, and determine the site's own notification obligations; a business associate must notify the covered entity without unreasonable delay and no later than sixty calendar days after discovery.
  15. Notify the IRB and sponsor where research subjects or study data are affected, and process the event as a deviation under CON-002 and, if applicable, as an unanticipated problem under REG-002.
  16. Open a CAPA under QA-002 for every confirmed breach and for any incident with a systemic root cause, and verify effectiveness of the corrective action.
  17. Never retaliate against a person for reporting an incident or filing a complaint, and never require an individual to waive their rights as a condition of service.
  18. Retain all incident documentation, risk assessments, notifications and proof of mailing for at least six years from the date of the record or its last effective date.

6. References

  • 45 CFR Part 164, Subpart D — Notification in the Case of Breach of Unsecured PHI
  • 45 CFR 164.404 — Notification to individuals
  • 45 CFR 164.406 — Notification to the media
  • 45 CFR 164.408 — Notification to the Secretary
  • 45 CFR 164.410 — Notification by a business associate
  • 45 CFR 164.530 — Administrative requirements, complaints and sanctions
  • HIP-001 HIPAA Privacy Rule in Research
  • HIP-002 HIPAA Security Rule Safeguards

7. Revision History

  • v2.0 · Mar 28, 2023 — Added detailed four-factor assessment template and substitute notice rules.
  • v3.0 · Feb 23, 2026 — Added business associate notification handling and evidence preservation requirements.

— End of document —

Document control
OwnerAna Lucía Restrepo
ApproverMarguerite Okonjo-Bell
EffectiveFeb 23, 2026
Next reviewFeb 23, 2027
Estimated read13 minutes
Applies toAll departments
My statusSigned
Signed this version (51)

Marguerite Okonjo-Bell

Approved · Sep 25, 2026, 09:57 AM UTC

Ingrid Halvorsen, MD

Read and understood · Jul 16, 2026, 10:57 AM UTC

Thaddeus Moreau, MD

Read and understood · Jun 26, 2026, 02:57 PM UTC

Cornelius Abara, MD

Read and understood · Aug 15, 2026, 08:57 AM UTC

Rosalind Achterberg, DO

Read and understood · Sep 16, 2026, 09:57 AM UTC

Hyun-Woo Baek, MD

Read and understood · Sep 27, 2026, 10:57 AM UTC

Fatoumata Diallo, MD

Read and understood · Sep 16, 2026, 01:57 PM UTC

Silas Wentworth, PA-C

Read and understood · Jun 25, 2026, 09:57 AM UTC

Noor Al-Rashidi, NP

Read and understood · Sep 19, 2026, 10:57 AM UTC

Beatrix Calloway

Read and understood · Jul 09, 2026, 11:57 AM UTC

Sunniva Lindqvist, RN

Read and understood · Jul 27, 2026, 10:57 AM UTC

Tomasz Wierzbicki

Read and understood · Jun 22, 2026, 09:57 AM UTC

Anaya Bhattacharya

Read and understood · Aug 20, 2026, 10:57 AM UTC

Meredith Sowande

Read and understood · Jul 14, 2026, 12:57 PM UTC

Lucinda Ferreira-Mota

Read and understood · Jul 15, 2026, 12:57 PM UTC

Kwabena Asante-Mensah

Read and understood · Sep 20, 2026, 10:57 AM UTC

Delphine Rousseau

Read and understood · Jul 28, 2026, 08:57 AM UTC

Yusra Abdalla

Read and understood · Jun 17, 2026, 08:57 AM UTC

Milo Ferrante

Read and understood · Aug 12, 2026, 12:57 PM UTC

Saoirse MacLochlainn, RN

Read and understood · Sep 25, 2026, 01:57 PM UTC

Anneliese Brummer

Read and understood · Sep 10, 2026, 11:57 AM UTC

Jamal Whitfield

Read and understood · Jul 09, 2026, 01:57 PM UTC

Auberon Castellanos

Read and understood · Sep 23, 2026, 08:57 AM UTC

Ilse Vermeulen

Read and understood · Aug 17, 2026, 12:57 PM UTC

Chiamaka Eze

Read and understood · Aug 04, 2026, 08:57 AM UTC

Sebastián Duarte

Read and understood · Jul 05, 2026, 08:57 AM UTC

Viktor Salminen

Read and understood · Sep 26, 2026, 12:57 PM UTC

Rosalie Beauchamp

Read and understood · Aug 24, 2026, 10:57 AM UTC

Tallulah Winthrop

Read and understood · Sep 20, 2026, 10:57 AM UTC

Georgi Dimitrov

Read and understood · Aug 27, 2026, 02:57 PM UTC

Ayanna Prescott

Read and understood · Aug 09, 2026, 10:57 AM UTC

Bartholomew Ng'ang'a, PharmD

Read and understood · Aug 31, 2026, 11:57 AM UTC

Emil Kowalczyk

Read and understood · Jun 30, 2026, 11:57 AM UTC

Marisol Echeverría

Read and understood · Aug 21, 2026, 09:57 AM UTC

Desmond Achebe

Read and understood · Jun 29, 2026, 03:57 PM UTC

Ingrid Bäckström

Read and understood · Jun 17, 2026, 02:57 PM UTC

Nadia Boulahrouz

Read and understood · Aug 31, 2026, 08:57 AM UTC

Temperance Ajayi

Read and understood · Jul 25, 2026, 01:57 PM UTC

Evelyn Marchetti-Sung

Read and understood · Jul 29, 2026, 09:57 AM UTC

Obadiah Lindgren

Read and understood · Jun 08, 2026, 11:57 AM UTC

Farrukh Tashkentov

Read and understood · Sep 25, 2026, 02:57 PM UTC

Ravi Choudhury

Read and understood · Sep 19, 2026, 11:57 AM UTC

Birgitta Sjöberg

Read and understood · Jun 28, 2026, 08:57 AM UTC

Malachi Osei-Tutu

Read and understood · Sep 10, 2026, 08:57 AM UTC

Esperanza Villalobos

Read and understood · Sep 12, 2026, 02:57 PM UTC

Winston Ferraro-Kline

Read and understood · Jul 06, 2026, 02:57 PM UTC

Adaeze Okafor

Read and understood · Jul 30, 2026, 08:57 AM UTC

Jasper Lindholm

Read and understood · Aug 26, 2026, 09:57 AM UTC

Lorelei Krasnova

Read and understood · Jun 28, 2026, 08:57 AM UTC

Ezekiel Barrantes

Read and understood · Aug 04, 2026, 11:57 AM UTC

Miriam Sandoval-Reyes

Read and understood · Sep 28, 2026, 02:57 PM UTC