Executive summary. Incident response and breach determination run on different evidence and different clocks. Keep them as separate records.

Definition

A HIPAA breach is generally an impermissible use or disclosure of protected health information presumed to be a breach unless a documented risk assessment demonstrates a low probability that the PHI has been compromised.

Triage facts without deciding too early

Preserve logs, identities, systems, data categories, timing, and containment actions. Early facts change, so keep observations distinct from conclusions.

An incident can require response without becoming a reportable breach. Technical containment, contractual notice, and regulatory analysis do not belong in one status field.

Make the assessment reviewable

The risk assessment addresses the nature and extent of the PHI, the unauthorized person involved, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. Record the source and rationale behind each finding.

Legal, privacy, security, and customer obligations can run on different timelines. Calculate and track each clock inside the workflow instead of relying on a calendar reminder.

Frequently asked questions

Does encryption always end a breach inquiry?

HHS guidance sets out exceptions and factors. Preserve the facts and apply the applicable rule and agreements to the specific event.

Referenced standards and further reading

Related articles

HIPAA Security Rule risk analysis: scope, evidence, decisions →

The minimum necessary standard in operational design →

Business associate relationships: map the work, not the logo →

Revision history

2026-08-05 · 1.0, initial public reference · Published by Ryan Stringer.