Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
So, your worst nightmare has just happened. There has been a data breach or a HIPAA violation, and you need to take action. Let’s now go over the steps that you must take now that the breach has occurred. Because, as a leader, your job is to move quickly, in the right order, and to document every step as you go, because your organization's breach response has to be defensible later. Here are the 3 steps: Step one, report the incident. Step two, complete a risk assessment to determine whether it is a breach. Step three, notify the affected individuals and notify HHS and/or the media if required. Lastly, be sure to document as you go through each step. Now let's review each so you or your compliance team knows what to do. Step one: report the incident. The moment a possible breach is discovered, contain it to avoid further PHI being breached, and report it to your privacy or compliance officer following your organization's policies and procedures. Nothing else happens correctly until the right people know. Log the report itself, including what was found and when, because that report is the start of your documentation trail. Step two: Complete a risk assessment to determine whether it is a breach. First, check whether the incident is excluded from the definition of a breach. There are three exclusions: a good-faith, unintentional access by a workforce member acting within their role; an inadvertent disclosure between two people at your organization who are both authorized to access PHI; and a case where you reasonably believe the information could not have been retained. If an exclusion applies, and the information is not further used or disclosed improperly, it is not a breach. If none applies, the incident is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised. That assessment weighs four factors: the nature and extent of the information, who used or received it, whether it was actually acquired or viewed, and how well the risk was reduced. Be sure to document the assessment and its finding. It is your decision record and part of your Book of Evidence. Step three: notify the affected individuals and HHS within the required timelines. If it is a breach, notify the affected individuals without unreasonable delay, and no later than 60 days after the breach is discovered. That 60 days is a federal outer limit. Some states require faster notice. For example, Wisconsin and Vermont require notice within 45 days; others require notice within 30 days. Please reference our downloadable State Breach Notification Guide, which is accurate as of August 2026. Always follow the shortest deadline that applies among the federal limit and every state where an affected person lives. Keep a record of who was notified, when, and how. You will also need to notify HHS, and the media when it applies. For HHS, the timing depends on the size of the breach. For a breach affecting 500 or more people, notify HHS at the same time you notify individuals. For a breach affecting fewer than 500 people, log it and report it to HHS no later than 60 days after the end of the calendar year in which it was discovered. For the media, if a breach affects 500 or more residents of a single state or jurisdiction, you must also notify prominent media serving that area. Keep copies of every notice you send. A few details that apply across the notifications. Whether a notice goes to an individual or to the media, it must include the same core information: a brief description of what happened, the types of information involved, the steps affected individuals should take to protect themselves, what your organization is doing to investigate and mitigate the breach and prevent future ones, and how people can reach you with questions. And if you have insufficient or out-of-date contact information for ten or more individuals, you must provide substitute notice, either by posting the notice on your website for at least 90 days, or by providing it in major print or broadcast media where the affected individuals likely live. So, to recap, the 3 steps are: one, report the incident. Two, complete a risk assessment to determine if it was a breach. Three, notify the affected individuals and HHS and, when it applies, the media. Document every step along the way. Time is critical, so know these 3 steps before you ever need them, and keep your response defensible by making it part of your Book of Evidence.
When a data breach or HIPAA violation occurs, leaders must move quickly, act in the proper sequence, and maintain thorough documentation. To ensure your organization's breach response remains legally defensible, you must follow three core steps and include every record in your Book of Evidence.
The moment a potential breach is discovered, immediate containment is critical to prevent further Protected Health Information (PHI) from being compromised. Follow your organization's established policies and procedures to notify the designated compliance authorities.
Once reported, you must evaluate whether the incident meets the legal definition of a breach. An incident is presumed to be a breach unless a risk assessment demonstrates a low probability that PHI was compromised, or an official exclusion applies.
First, evaluate if any of the three statutory breach exclusions apply:
If no exclusion applies, conduct a formal four-factor risk assessment to determine if the information was compromised:
Pro Tip: Document, Document, Document: Always log every risk assessment and its findings in writing. This decision record serves as crucial proof inside your Book of Evidence during regulatory audits.
If the risk assessment confirms a breach, you must issue formal notifications to affected individuals, the Department of Health and Human Services (HHS), and media outlets when applicable.
All individual and media notifications must contain the following core details: