HIPAA Breach Response Checklist: the 60-day clock and the 4-factor assessment
When PHI may have been exposed, the job is not to panic or guess. The job is to preserve facts, contain the incident, run the risk assessment, decide whether notification is required, and document the file as if OCR will read it later.
Disable access, preserve logs, snapshot systems, stop additional PHI exposure.
Run the 4-factor risk assessment and scope affected people, data, and vendors.
Individuals, HHS, covered entities, and media when thresholds require it.
Keep the decision file, notices, mitigation, and the final operator memo.
The response checklist
Discovery and containment
- Record when the incident was discovered and who discovered it.
- Stop the exposure without destroying evidence.
- Preserve logs, access records, messages, files, exports, and vendor tickets.
- Identify whether PHI was involved, not just personal information generally.
The HIPAA 4-factor risk assessment
- Nature and extent of PHI involved.
- Who used or received the PHI.
- Whether PHI was actually acquired or viewed.
- How much the risk was mitigated.
Notification thresholds
Notifications must happen without unreasonable delay and no later than 60 days after discovery when a breach is reportable. Breaches affecting 500 or more people trigger faster public visibility: individual notice, HHS notice, and media notice for the affected area. Smaller breaches still get logged and reported to HHS annually.
The documentation trail
Keep one incident file: timeline, evidence preserved, affected data, vendors involved, BAA chain, 4-factor assessment, notification decision, copies of notices, mitigation work, and final closure memo. The file is the proof that the response was rational.