SG SideGuy
Tech-Help · Clarity Before Cost
Text PJ

🛡️ COMPLIANCE · HIPAA BREACH RESPONSE

HIPAA breach — what to do, in order.

If you think PHI has been exposed, breathe — then move in order. Not every incident is a notifiable breach, and the steps below tell you which it is. But the notification clock starts at discovery, so don't sit on it. Work the triage.

Operator-honest tech-help · no jargon · no upsell to something you don't need.

The breach-response triage

Work these in order · steps 1–2 are the same hour; do not skip step 2

  • Contain it first. Before anything else, stop the exposure. Revoke the compromised credential, isolate the affected system, pull the bad access, rotate keys and passwords. Preserve the logs and evidence as you go — don't wipe the system. Containment and evidence both matter; rushing one destroys the other.
  • Run the four-factor risk assessment. Not every incident is a reportable breach. HIPAA says assess four things: what PHI was involved, who received or accessed it, whether it was actually acquired or viewed, and the extent it's been mitigated. Document this honestly — it determines whether notification is required, and it's the first thing a regulator reviews.
  • Scope it — whose PHI, how many people. Identify exactly which individuals' PHI was involved and what data elements (names, diagnoses, SSNs, etc.). The count matters: it changes the notification path. Get this number as accurate as you can — guessing low and revising up later looks far worse than getting it right.
  • If you're a Business Associate, notify the Covered Entity. A Business Associate (most SaaS and vendors) must notify the affected Covered Entity — your client — without unreasonable delay, and no later than 60 days from discovery. The Covered Entity generally handles individual notification, but they cannot start that clock until you tell them. Tell them early.
  • Notify the affected individuals. Affected individuals must be notified in writing, without unreasonable delay and within 60 days of discovery. The notice must say what happened, what data was involved, what they should do, and what you're doing about it. This is the Covered Entity's duty — but everyone in the chain should know the deadline.
  • Notify HHS — and document the whole response. Breaches affecting 500 or more individuals require notice to HHS (and the media in the affected area) without unreasonable delay, within 60 days. Smaller breaches are logged and reported to HHS annually. Either way: document every step, decision, and date — the response record is what proves you handled it correctly.

🛡️ The deeper fix · SideGuy builds it

A breach plan you have before you need it

SideGuy is the operator layer that writes your incident and breach response plan before the breach — who decides, who notifies whom, where the logs are, what the clock is — so a real incident is a checklist, not a panic. The difference between a contained incident and a penalty is almost always the plan you had on day zero.

If you're in an incident right now, text PJ — the first hour is free and we'll help you work the steps. If you're reading this before a breach, a $250 Operator Audit gets you the plan and the gap list. Text PJ either way.

Common questions (answered honestly)

Is every HIPAA incident a reportable breach?
No. HIPAA's four-factor risk assessment exists precisely to determine whether an incident is a notifiable breach. If the assessment shows a low probability that PHI was compromised, it may not require notification — but you must document the assessment that reached that conclusion.
How long do I have to notify after a HIPAA breach?
Notification must happen without unreasonable delay and no later than 60 days from discovery. A Business Associate must notify the Covered Entity within that window; the Covered Entity notifies individuals, and HHS, within it. 'Discovery' includes when you should reasonably have known — so the clock can be running before you notice.
I'm a SaaS vendor, not a hospital — what's my duty?
As a Business Associate you must notify the affected Covered Entity (your client) of a breach without unreasonable delay, within 60 days of discovery, and provide the details they need to notify individuals. You may also have direct obligations depending on the BAA. Tell your client early — their clock depends on you.
What should I do right now if I think we're breached?
Contain it, preserve the logs, and run the four-factor assessment — then notify up the chain. If you want a second set of eyes while the clock runs, text PJ; the first hour is free.

Know an operator who'd be lost in a HIPAA breach? Send them the steps now — before they need them.

🏝️ More from NC SD
Encinitas· Cardiff-by-the-Sea· Solana Beach· Del Mar· Carlsbad· La Jolla· Compliance hub· AI Marketing Help
PJ Text PJ →858-461-8054