Executive summary. Incident response and breach determination run on different evidence and different clocks. Keep them as separate records.
Definition
A HIPAA breach is generally an impermissible use or disclosure of protected health information presumed to be a breach unless a documented risk assessment demonstrates a low probability that the PHI has been compromised.
Triage facts without deciding too early
Preserve logs, identities, systems, data categories, timing, and containment actions. Early facts change, so keep observations distinct from conclusions.
An incident can require response without becoming a reportable breach. Technical containment, contractual notice, and regulatory analysis do not belong in one status field.
Make the assessment reviewable
The risk assessment addresses the nature and extent of the PHI, the unauthorized person involved, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. Record the source and rationale behind each finding.
Legal, privacy, security, and customer obligations can run on different timelines. Calculate and track each clock inside the workflow instead of relying on a calendar reminder.
Frequently asked questions
Does encryption always end a breach inquiry?
HHS guidance sets out exceptions and factors. Preserve the facts and apply the applicable rule and agreements to the specific event.
Referenced standards and further reading
- HHS OCR: Breach Notification Rule ↗U.S. Department of Health and Human Services
Related articles
HIPAA Security Rule risk analysis: scope, evidence, decisions →
The minimum necessary standard in operational design →
Business associate relationships: map the work, not the logo →