🛡️ COMPLIANCE · HIPAA BREACH RESPONSE
HIPAA breach — what to do, in order.
If you think PHI has been exposed, breathe — then move in order. Not every incident is a notifiable breach, and the steps below tell you which it is. But the notification clock starts at discovery, so don't sit on it. Work the triage.
Operator-honest tech-help · no jargon · no upsell to something you don't need.
The breach-response triage
Work these in order · steps 1–2 are the same hour; do not skip step 2
- Contain it first. Before anything else, stop the exposure. Revoke the compromised credential, isolate the affected system, pull the bad access, rotate keys and passwords. Preserve the logs and evidence as you go — don't wipe the system. Containment and evidence both matter; rushing one destroys the other.
- Run the four-factor risk assessment. Not every incident is a reportable breach. HIPAA says assess four things: what PHI was involved, who received or accessed it, whether it was actually acquired or viewed, and the extent it's been mitigated. Document this honestly — it determines whether notification is required, and it's the first thing a regulator reviews.
- Scope it — whose PHI, how many people. Identify exactly which individuals' PHI was involved and what data elements (names, diagnoses, SSNs, etc.). The count matters: it changes the notification path. Get this number as accurate as you can — guessing low and revising up later looks far worse than getting it right.
- If you're a Business Associate, notify the Covered Entity. A Business Associate (most SaaS and vendors) must notify the affected Covered Entity — your client — without unreasonable delay, and no later than 60 days from discovery. The Covered Entity generally handles individual notification, but they cannot start that clock until you tell them. Tell them early.
- Notify the affected individuals. Affected individuals must be notified in writing, without unreasonable delay and within 60 days of discovery. The notice must say what happened, what data was involved, what they should do, and what you're doing about it. This is the Covered Entity's duty — but everyone in the chain should know the deadline.
- Notify HHS — and document the whole response. Breaches affecting 500 or more individuals require notice to HHS (and the media in the affected area) without unreasonable delay, within 60 days. Smaller breaches are logged and reported to HHS annually. Either way: document every step, decision, and date — the response record is what proves you handled it correctly.
🛡️ The deeper fix · SideGuy builds it
A breach plan you have before you need it
SideGuy is the operator layer that writes your incident and breach response plan before the breach — who decides, who notifies whom, where the logs are, what the clock is — so a real incident is a checklist, not a panic. The difference between a contained incident and a penalty is almost always the plan you had on day zero.
If you're in an incident right now, text PJ — the first hour is free and we'll help you work the steps. If you're reading this before a breach, a $250 Operator Audit gets you the plan and the gap list. Text PJ either way.