Breach response under HIPAA is a documentation race run on someone else’s clock. Discovery is imputed to your most junior employee’s inbox, the 60-day outer limit is the ceiling rather than the target, and every judgment call, the discovery date, the four factors, the individual count, must survive OCR review in writing, months later, with hindsight against you. Teams that pre-build the machinery (assessment template, notice letters, HHS portal access, BAA reporting deadlines mapped) run breaches; teams that improvise get run by them. And the quietest fact in the rule remains the loudest advice: encrypted PHI is not breachable PHI.
| Trigger | Impermissible use/disclosure of unsecured PHI (presumed breach) |
|---|---|
| Escape | Documented 4-factor low-probability assessment |
| Individuals | ≤60 days from discovery |
| HHS | Contemporaneous (500+) or annual log (<500) |
| Media | 500+ per state |
| Safe harbor | NIST-standard encryption |
Running the playbook
Pre-position the artifacts. Assessment template, notice drafts, HHS portal credentials, media contact plan, and a state-law clock matrix; the compliance roadmap sequences where these fit.
Compress vendor reporting contractually. The regulation gives business associates 60 days; your BAAs should give them days, not weeks, so their delay does not consume your clock.
Close incidents with a written no-breach memo. Every security incident that ends ‘no notification’ needs the four-factor analysis in the file, silence without paper is indistinguishable from concealment.
Feed root cause back into the risk analysis. OCR reads the breach against your risk assessment; a breach through an unassessed vector is the aggravating pattern in current enforcement.
Website trackers on patient portals have driven a wave of breach reports: find out what your pages disclose with a free scan.