All Courses HIPAA HIPAA for Leaders Training How to Handle a Data Breach and Violations

How to Handle a Data Breach and Violations

Video 21 of 26
4 min 51 sec
English
English

When a data breach or HIPAA violation occurs, leaders must move quickly, act in the proper sequence, and maintain thorough documentation. To ensure your organization's breach response remains legally defensible, you must follow three core steps and include every record in your Book of Evidence.

Step 1: Report and Contain the Incident

The moment a potential breach is discovered, immediate containment is critical to prevent further Protected Health Information (PHI) from being compromised. Follow your organization's established policies and procedures to notify the designated compliance authorities.

  • Immediate Containment: Act swiftly to halt any ongoing exposure of PHI as soon as an incident is identified.
  • Notify Leadership: Report the event directly to your Privacy Officer or Compliance Officer so official response protocols can begin.
  • Log the Initial Report: Record specific details about what was discovered and the exact time of discovery to establish the start of your official documentation trail.

Step 2: Conduct a Breach Risk Assessment

Once reported, you must evaluate whether the incident meets the legal definition of a breach. An incident is presumed to be a breach unless a risk assessment demonstrates a low probability that PHI was compromised, or an official exclusion applies.

First, evaluate if any of the three statutory breach exclusions apply:

  • Unintentional Access: Good-faith, unintentional acquisition or access of PHI by a workforce member acting within the scope of their authority.
  • Inadvertent Disclosure: Inadvertent sharing of PHI between two authorized persons at the same covered entity or business associate.
  • Inability to Retain: Situations where the covered entity has a good-faith belief that the unauthorized recipient could not have retained the information.

If no exclusion applies, conduct a formal four-factor risk assessment to determine if the information was compromised:

  • Nature and Extent of PHI: Evaluate the types of identifiers and the likelihood of re-identification.
  • Unauthorized Recipient: Determine who used the PHI or to whom the disclosure was made.
  • Actual Viewing or Acquisition: Check whether the PHI was actually viewed, acquired, or accessed.
  • Mitigation Efforts: Measure the extent to which the risk to the data has been reduced.

Pro Tip: Document, Document, Document: Always log every risk assessment and its findings in writing. This decision record serves as crucial proof inside your Book of Evidence during regulatory audits.

Step 3: Execute Required Breach Notifications

If the risk assessment confirms a breach, you must issue formal notifications to affected individuals, the Department of Health and Human Services (HHS), and media outlets when applicable.

  • Affected Individuals: Send written notice without unreasonable delay and no later than 60 days following breach discovery (the federal outer limit). Always check state laws, as several jurisdictions enforce stricter deadlines, such as Wisconsin and Vermont (45 days) or states with 30-day requirements. Reference the downloadable State Breach Notification Guide (updated August 2026) and adhere to the shortest applicable state deadline where affected individuals reside.
  • HHS Reporting (500+ Individuals): For breaches impacting 500 or more people, notify HHS simultaneously with individual notices.
  • HHS Reporting (Under 500 Individuals): Log smaller breaches and submit them to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.
  • Media Notification: If a breach affects 500 or more residents of a single state or jurisdiction, issue a notice to prominent media outlets serving that area.
  • Substitute Notice: If contact information is out of date or insufficient for 10 or more individuals, provide substitute notice by posting a warning on your website for at least 90 days or publishing it in major print/broadcast media.

All individual and media notifications must contain the following core details:

  • Event Description: A brief description of what occurred, including relevant dates.
  • PHI Types Involved: Specific categories of compromised personal or health information.
  • Protective Actions: Recommended steps affected individuals should take to safeguard themselves.
  • Mitigation and Prevention: Details on what your organization is doing to investigate, minimize damage, and prevent future incidents.
  • Contact Information: Clear instructions on how individuals can reach your organization with questions.