Blog

Suspected HIPAA Breach? What to Do in the First 72 Hours

A practical hour-by-hour plan for a suspected HIPAA breach: contain, assess, run the four-factor analysis, and start the notification clocks correctly.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

The worst breach responses share a pattern: not malice, but drift. Someone notices something odd on a Tuesday, mentions it on Thursday, IT looks at it the following week, and by the time leadership hears the word “breach,” the regulatory clock has been running for twelve days and nobody wrote anything down. The first 72 hours after a suspected breach determine whether you run a controlled process or spend the next year explaining a chaotic one.

This is the hour-by-hour playbook. It assumes you are a covered entity or business associate under 45 CFR Parts 160 and 164, and that something bad may have just happened: a phishing click, a stolen laptop, a misdirected email, an odd login from another continent, a vendor calling with bad news.

First, know what starts the clock

Under the Breach Notification Rule (45 CFR 164.400–414), a breach is “discovered” on the first day it is known — or would have been known by exercising reasonable diligence — by any workforce member or agent other than the person who committed it. Not the day legal confirms it. Not the day forensics finishes. The day your receptionist noticed the weird email counts.

From discovery, the deadlines are:

  • Individuals: notice without unreasonable delay, and in no case later than 60 calendar days after discovery.
  • HHS, 500+ individuals: notice within the same 60 days, plus notice to prominent media outlets in the affected state or jurisdiction.
  • HHS, under 500 individuals: log it and report within 60 days after the end of the calendar year.
  • Business associates to covered entities: the rule says without unreasonable delay, no later than 60 days — but most business associate agreements shorten this dramatically, often to 72 hours or less. Read your BAA before you need it.

Sixty days sounds like a long time. It is not. Investigation, four-factor analysis, legal review, letter drafting, mailing logistics, call-center setup, and HHS portal submission all have to fit inside it. The organizations that make the deadline comfortably are the ones that treat the first 72 hours as the sprint.

Hour 0–2: Stop the bleeding

Containment comes before analysis. The moment an incident is suspected:

  • Isolate affected systems. Disconnect the compromised machine from the network — do not power it off if you can avoid it, because memory and logs are evidence.
  • Kill compromised credentials. Reset the phished user’s password, revoke active sessions and tokens, and check for attacker-created inbox rules (auto-forwarding rules are a classic persistence trick after email compromise).
  • Recall what can be recalled. For a misdirected email inside your own tenant, recall it and contact the recipient. For a fax to a wrong number, call the receiving office and request destruction with written confirmation.
  • Preserve evidence. Start a log — timestamped, boring, factual. Who noticed what, when, and what was done. This log becomes the backbone of your documentation and your best friend if OCR ever asks.

One more thing to do in the first two hours: name an incident commander. One person owns the timeline, the log, and the decisions. Committees discover breaches; individuals respond to them.

Hour 2–12: Assemble the facts

Now build the factual picture, because every downstream decision depends on it.

  • What data was involved? Names, SSNs, diagnoses, financial data, or just internal identifiers?
  • Whose data? How many individuals, from which states (state breach laws stack on top of HIPAA and some have shorter clocks)?
  • Was the PHI “unsecured”? This is the pivotal question. PHI encrypted consistent with HHS guidance (NIST-aligned encryption at rest) is not “unsecured PHI,” and its loss is generally not a reportable breach. A stolen laptop with verified full-disk encryption and no compromised key is usually a non-event, regulatorily. A stolen laptop where nobody can prove encryption was on is a breach investigation. This is why encryption evidence belongs in your Security Rule documentation before anything is ever stolen.
  • What was the window of exposure? First malicious login to containment, or send-time to recall.
  • Is it ongoing? Email compromise in particular tends to be wider than it first appears — check other mailboxes for the same lure.

If the incident involves a vendor, get their facts in writing and check the BAA’s notification clause. If you are the business associate, notify the covered entity early with what you know, flagged as preliminary — most BAAs require prompt notice, and sitting on it to “finish the investigation” is how partnerships and defenses both collapse.

Hour 12–24: Decide who’s in the room

By the end of day one, you should have activated the response team your incident response policy names (and if it names nobody, that is a gap worth fixing this quarter — our templates library includes an incident response plan for a reason):

  • Privacy/security officer — process owner
  • Leadership — resourcing and sign-off
  • IT or your MSP — technical investigation
  • Legal counsel — privilege, state-law analysis, and whether to engage outside breach counsel
  • Cyber insurance carrier — call them early; many policies require prompt notice and offer approved forensics and notification vendors at negotiated rates

A note on communication discipline: route sensitive analysis through counsel where appropriate, keep speculation out of email, and give staff a one-line holding statement (“we’re investigating an IT incident; direct any questions to X”). Do not announce conclusions before you have them — internally or externally.

Hour 24–48: Run the four-factor risk assessment

Here is the legal core. Under 45 CFR 164.402, an impermissible use or disclosure of unsecured PHI is presumed to be a reportable breach unless you demonstrate a low probability that the PHI was compromised, based on at least these four factors:

Factor 1: Nature and extent of the PHI

What was in the data, and how identifiable and sensitive is it? A spreadsheet of names and appointment dates is different from one with SSNs, diagnoses, or substance-use treatment records. More sensitive and more identifiable pushes toward notification.

Factor 2: Who received or accessed it

An unauthorized recipient who is another HIPAA-regulated entity (the wrong doctor’s office) presents lower risk than an unknown criminal actor. A misdirected email to another covered entity that confirms deletion is a very different analysis from exfiltration by a ransomware crew.

Factor 3: Was the PHI actually acquired or viewed

Logs matter enormously here. If forensics shows the attacker never opened the folder containing PHI, or the misaddressed email bounced and was never delivered, probability of compromise drops. “We can’t tell” does not help you — absence of logging counts against a low-probability conclusion, which is another argument for turning on audit logging today.

Factor 4: Extent of mitigation

Did the wrong recipient sign an attestation of deletion? Were credentials revoked before any PHI access occurred? Effective, verifiable mitigation lowers risk; hopeful assumptions do not.

Weigh all four together, in writing, with a named decision-maker and a date. Two honest warnings. First, the presumption runs against you: if the analysis is a coin flip, notify. Second, this document is exactly what OCR asks for later — a two-line memo saying “we decided it was low risk” is worse than no analysis, because it shows you knew the obligation and shortcut it. If you conclude no notification is required, keep the analysis for six years.

Hour 48–72: Chart the notification path

If the assessment lands on “breach,” day three is for planning, not panicking:

  • Draft the individual notice. Required content is specified in 164.404(c): what happened, the types of information involved, steps individuals should take, what you are doing to investigate and mitigate, and contact procedures. Plain language is legally required — write it like a human.
  • Choose delivery. First-class mail to last known address is the default; email only if the individual agreed to electronic notice. If you have insufficient contact information for 10 or more people, substitute notice (website posting for 90 days plus a toll-free number, or media notice) comes into play.
  • Scope the count. The 500-person line changes everything: HHS notice within 60 days, media notice, and near-certain OCR follow-up. Getting an accurate count early prevents a painful re-notification later.
  • Map state overlays. Many states require notice to residents or attorneys general on their own timelines, some shorter than HIPAA’s. Counsel earns their fee here.
  • Keep investigating. Notification planning and forensics run in parallel, not in sequence.

Even when the four-factor analysis says “no breach,” close the loop: document the incident, the analysis, the mitigation, and any corrective actions. Non-breach incidents are still Security Rule incidents requiring response and documentation under 164.308(a)(6).

The mistakes that turn bad days into bad years

Patterns we see repeatedly, and that show up as aggravating factors in enforcement:

  • Waiting for certainty before starting the clock. Discovery starts at “should have known,” not “fully confirmed.”
  • No documentation until day 30. Reconstructed timelines look like reconstructed timelines.
  • Treating the four-factor test as a formality to reach “no breach.” Motivated reasoning is visible in hindsight.
  • Forgetting the BAA clock. Your contract deadline to notify a partner is often days, not weeks.
  • Punishing the reporter. If the employee who clicked the link gets fired loudly, the next click goes unreported for a month.
  • Fixing nothing afterward. OCR’s consistent theme in resolution agreements is not the breach itself but the years of unaddressed risk analysis findings behind it. Your corrective action plan matters as much as your notices.

Build the muscle before you need it

Everything above is ten times easier with three things in place beforehand: an incident response plan with names in it, evidence of encryption and logging, and a workforce trained to report fast — which is a training design question, covered in our post on building a HIPAA training program. Run a tabletop exercise once a year: pick a scenario, walk the 72 hours, find the gaps while they are free to find. And if an incident does escalate into a regulator conversation, our guide to OCR audit preparation covers what they ask for first.

If you are not sure whether your current documentation would survive contact with a real incident, start with our free HIPAA readiness assessment — it scores incident response and breach notification readiness specifically — or book a 20-minute call and walk through your scenario with someone who has run this clock before. The 60-day deadline is generous only to organizations that use the first three days well.

Questions

How long do I have to report a HIPAA breach?

Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more people must also be reported to HHS within that same 60-day window, plus media notice in the affected area. Smaller breaches go to HHS within 60 days after the end of the calendar year.

Does every security incident count as a reportable breach?

No. A breach is an impermissible acquisition, access, use, or disclosure of unsecured PHI. An incident is presumed to be a breach unless a documented four-factor risk assessment demonstrates a low probability that PHI was compromised. Many incidents — like a laptop encrypted to NIST standards being stolen — fall outside the definition entirely.

When does the 60-day clock actually start?

On the date of discovery — the first day the incident is known, or would have been known with reasonable diligence, by anyone in your workforce other than the person who caused it. It does not start when your investigation finishes, which is why the first 72 hours matter so much.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo