25+ Years Security Experience•Enterprise Security Leadership
Healthcare Incident Response

Healthcare Data Breach Response: What to Do in the First 72 Hours

A step-by-step operational framework for containing, investigating, and managing HIPAA breach notification obligations when a healthcare data incident occurs.

By Dan Pitre, Security Leadership & vCISO Practitioner · CMMC Registered Practitioner · Published April 2026•9 min read

72 Hours: Operational Framework, Not a HIPAA Deadline

The 72-hour timeline in this guide is an operational best-practice framework for initial breach response actions. It is not a HIPAA deadline. The HIPAA Breach Notification Rule requires individual notice without unreasonable delay, and no later than 60 calendar days from discovery of the breach. This guide focuses on what your team should do in the critical first 72 hours to position your organization for effective containment, investigation, and regulatory compliance.

Why Breach Readiness Matters for Healthcare

Healthcare remains one of the most targeted industries for data breaches. The HHS Office for Civil Rights (OCR) maintains a public breach portal — often called the "wall of shame" — listing every reported breach affecting 500 or more individuals. OCR enforcement actions, including the ongoing Risk Analysis Initiative, have resulted in significant penalties for organizations that lacked documented risk analysis and breach response procedures. Breach response is the last line; prevention economics still favor the defender who hardens the attack surface upstream, and that calculus is changing as AI-assisted vulnerability discovery compresses the window between disclosure and exploit, which means response playbooks now assume a faster adversary. The shift toward distributed telehealth delivery has expanded that attack surface significantly — providers operating across video, audio, and messaging workflows face compliance obligations that extend well beyond platform selection.

725+

Major healthcare breaches reported to OCR in 2024

Source: HHS Breach Portal

168M+

Individual records affected by healthcare breaches in 2024

Source: HHS Breach Portal

$10.93M

Average cost of a healthcare data breach (2025 report)

Source: IBM Cost of a Data Breach Report 2025

The 72-Hour Action Plan

1
Hour 0–4

Contain and Assess

Isolate affected systems from the network to prevent further unauthorized access — consult forensic guidance before powering down, as preserving volatile memory may be critical to the investigation

Activate the incident response team and designated security official

Document the timeline: when the incident was discovered, by whom, and initial scope indicators

Preserve all logs, access records, and system images — do not alter or delete evidence

Engage forensic expertise if the breach appears to involve sophisticated attack vectors

2
Hour 4–24

Investigate and Scope

Determine what electronic protected health information (ePHI) was involved — types of data, volume, and sensitivity

Identify affected individuals and the systems that stored, processed, or transmitted the compromised ePHI

Conduct the 4-factor breach risk assessment to determine whether there is a low probability the PHI has been compromised

Map the unauthorized access — who, when, from where, and what actions were taken

Assess whether the incident is ongoing or fully contained

3
Hour 24–48

Legal and Regulatory Assessment

Engage legal counsel experienced in HIPAA and state breach notification law

Evaluate notification obligations under the HIPAA Breach Notification Rule based on the risk assessment findings

Identify applicable state breach notification requirements — many states impose additional or shorter timelines

Prepare documentation of the risk assessment process, findings, and rationale

If the organization is a business associate, notify the covered entity of the breach

4
Hour 48–72

Notification Preparation

Draft individual notification letters meeting HIPAA content requirements

Prepare HHS/OCR breach report inputs — the report must be submitted within 60 days for breaches affecting 500+ individuals

Prepare media response framework if the breach may affect more than 500 residents of a state or jurisdiction

Establish a call center or FAQ page for affected individuals

Document all response actions for regulatory defense and post-incident review

HIPAA Breach Notification Rule: Who Must Be Notified

The HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) establishes specific notification requirements when unsecured protected health information is breached. The obligations differ depending on whether the breaching entity is a covered entity or a business associate. For context on the proposed Security Rule modifications, see our HIPAA 2026 analysis.

Individual Notice

Covered entities must notify affected individuals without unreasonable delay, and no later than 60 calendar days from discovery of the breach. Notice must include: a description of the breach, the types of information involved, steps individuals should take, what the entity is doing in response, and contact information.

60-day maximum from discovery

HHS / OCR Notice

For breaches affecting 500 or more individuals, the covered entity must notify the HHS Secretary within 60 days. For breaches affecting fewer than 500 individuals, the entity must maintain an annual log and submit it to HHS within 60 days of the end of the calendar year.

500+ individuals: 60-day report; <500: annual log

Media Notice

When a breach affects more than 500 residents of a state or jurisdiction, the covered entity must provide notice to prominent media outlets serving that state or jurisdiction. This threshold is per-state/jurisdiction — not 500 individuals total across all locations.

>500 residents of a single state or jurisdiction

State Attorney General Notice

Many states have their own breach notification statutes with independent requirements, timelines, and triggers. Some impose shorter notification windows than HIPAA's 60 days. Legal counsel should identify all applicable state requirements based on where affected individuals reside.

State laws may impose shorter timelines

Covered Entities vs. Business Associates

Business associates must notify the covered entity of a breach. The covered entity is responsible for individual notification, HHS reporting, and media notice — but it may delegate individual notification to the business associate. HHS has also stated that a business associate may submit the breach report to HHS on the covered entity's behalf. The BAA should specify notification responsibilities. If your organization operates as both (or is unsure of its designation), consult legal counsel to determine your specific notification obligations.

The 4-Factor Breach Risk Assessment

Not every security incident triggers HIPAA notification obligations. The Breach Notification Rule requires a risk assessment to determine whether there is a low probability that the PHI has been compromised. This is the standard established by the 2013 Omnibus Rule — it replaced the earlier pre-2013 standard. The burden is on the covered entity to demonstrate that there is a low probability of compromise; if the assessment is inconclusive, the incident is treated as a reportable breach.

1

Nature and Extent of the PHI Involved

What types of identifiers and clinical information were exposed? A breach involving names, Social Security numbers, and diagnoses carries higher risk than one involving names and appointment dates alone. Consider both the type and volume of PHI.

2

The Unauthorized Person

Who received or accessed the PHI? A misdirected fax to another healthcare provider carries different risk than data exfiltrated by an external attacker. Consider the recipient's obligations, intent, and ability to use the information.

3

Whether PHI Was Actually Acquired or Viewed

Was the information actually accessed, or was the opportunity for access the only exposure? For example, a misdirected email returned unopened presents lower risk than a database where query logs confirm data was exported. Note: if PHI was encrypted to HHS-specified standards and the encryption key was not compromised, HHS considers the information 'secured' and the Breach Notification Rule does not apply.

4

Extent of Risk Mitigation

What steps have been taken to reduce the risk? Obtaining attestations of destruction, recovering devices, or confirming that exposed data was not retained can support a finding of low probability of compromise.

Do Not Use the "Risk of Harm" Standard

The pre-2013 "risk of harm" breach assessment standard was replaced by the Omnibus Rule's "low probability of compromise" standard. Organizations that still apply the older standard risk underreporting breaches and face OCR enforcement action. The current standard asks whether there is a low probability that the PHI has been compromised — not whether actual harm is likely.

Common Breach Response Mistakes

Delayed Containment

Every hour of continued unauthorized access increases the scope of a breach. Organizations that prioritize investigation over containment often face significantly larger notification obligations and regulatory exposure.

Insufficient Documentation

OCR expects a documented risk assessment with specific findings for each of the four factors. Verbal assessments, summary conclusions without supporting analysis, or missing documentation weaken an organization's regulatory defense.

Premature Public Disclosure

Disclosing before the investigation is complete can create inaccurate public statements, hamper the forensic investigation, and expose the organization to additional liability. Notification obligations have defined timelines — use them.

Underscoping the Investigation

Investigating only the initially identified system while ignoring lateral movement, shared credentials, or connected business associate systems often results in discovering additional compromised data months later — triggering supplemental notifications.

Applying the Wrong Assessment Standard

Using the pre-2013 'risk of harm' standard instead of the current 'low probability of compromise' standard can lead to underreporting. The burden of proof is on the covered entity to demonstrate low probability — not on HHS to prove harm occurred.

Building Breach Readiness Before an Incident Occurs

The most effective breach response starts long before an incident occurs. A virtual CISO supports your designated security official in building and maintaining the organizational capabilities that determine whether a breach becomes a managed event or a crisis.

Pre-incident planning means developing and testing incident response plans tailored to healthcare ePHI scenarios, including role assignments, communication protocols, and decision trees for common breach types. Regular tabletop exercises test the organization's response capabilities across clinical, IT, legal, and administrative teams — revealing gaps that documentation alone cannot.

Effective breach response also requires clear team coordination: defined roles, escalation paths, and decision authority so the response team can operate under pressure without confusion about who owns containment, investigation, legal, and notification. And regulatory response preparation — ensuring documentation standards, risk assessment templates, and notification workflows are in place before they are needed — so the organization can meet OCR reporting requirements within required timelines.

A vCISO supports your organization's breach readiness capabilities and works alongside your designated HIPAA security official — not as a replacement for the legally required role. Not sure whether a full-time CISO or virtual model is the right fit? See our vCISO vs. full-time CISO comparison.

Frequently Asked Questions

Under HIPAA, a breach is the acquisition, access, use, or disclosure of unsecured protected health information in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. There are three exceptions: unintentional acquisition by a workforce member acting in good faith, inadvertent disclosure between authorized persons within the same organization, and situations where the recipient would not reasonably be able to retain the information. If none of these exceptions apply, the organization must conduct a risk assessment to determine whether notification is required.

HIPAA requires covered entities to notify affected individuals without unreasonable delay, and no later than 60 calendar days from the date the breach is discovered. Discovery occurs when the breach is known or should have been known through reasonable diligence. Some state laws impose shorter notification windows, so organizations must comply with whichever timeline is most restrictive.

A business associate that discovers a breach must notify the covered entity. The covered entity is responsible for individual notification, HHS reporting, and media notice — but it may delegate individual notification to the business associate. HHS has also stated that a business associate may submit the breach report to HHS on the covered entity's behalf. The business associate agreement should specify breach notification procedures, timelines, and the division of notification responsibilities between the parties.

If protected health information was encrypted in accordance with HHS guidance on encryption standards and the encryption key was not compromised, the information is considered 'secured' under HIPAA and the incident is not a reportable breach — regardless of the type of unauthorized access. This applies to data encrypted both at rest and in transit using NIST-recommended standards. However, if the encryption key was also exposed, the data is considered unsecured and breach analysis is required.

Media notification is required when a breach affects more than 500 residents of a single state or jurisdiction. The covered entity must notify prominent media outlets serving that state or jurisdiction without unreasonable delay, within 60 days of discovery. This threshold is per-state or per-jurisdiction — not 500 individuals total. A breach affecting 400 residents in Nevada and 300 in California would not trigger the media notice requirement for either state individually.

Build Your Breach Response Plan Before You Need It

Healthcare organizations that prepare incident response plans, conduct tabletop exercises, and establish notification workflows before a breach occurs respond faster, contain incidents more effectively, and face lower regulatory exposure. Start with a HIPAA security assessment.

This article is for informational purposes and does not constitute legal advice. HIPAA breach notification requirements are complex and vary based on individual circumstances. Consult legal counsel experienced in healthcare privacy law for guidance specific to your organization. Cloud Solutions Consulting provides virtual CISO advisory services to support healthcare organizations' cybersecurity programs. CSC does not serve as your organization's designated HIPAA security official or privacy official. Information reflects regulatory status as of April 2026.