Get Appointment
5600 Palm Lake Circle, Orlando Fl. 32819
info@ipircm.com
877-422-7221

Blog Details

What to Do Immediately After a HIPAA Breach Notification
July 22, 2026

What to Do Immediately After a HIPAA Breach Notification

Few things create panic inside a medical practice faster than realizing protected health information may have been exposed. Whether it is a misdirected fax, a stolen laptop, a phishing email that compromised a staff account, or a vendor reporting an incident on their end, the first few hours and days after discovering a potential breach matter enormously. What you do immediately can determine whether the situation stays contained and well documented, or turns into a drawn-out compliance problem with regulators, patients, and payers all asking questions at once.

This guide lays out exactly what to do the moment you receive or discover a HIPAA breach notification, in the order it needs to happen, along with the documentation and deadlines that carry legal weight.

First, Understand What Counts as a Breach

Under HIPAA, a breach is generally defined as the unauthorized acquisition, access, use, or disclosure of protected health information that compromises its security or privacy. Not every incident automatically qualifies. HIPAA allows for a risk assessment to determine whether an impermissible use or disclosure rises to the level of a reportable breach, based on factors such as the nature of the information involved, who received it, whether it was actually viewed, and whether the exposure has been mitigated.

This distinction matters because it shapes your very first decision: whether you are dealing with a confirmed breach that triggers notification obligations, or an incident that needs a documented risk assessment before you know for certain.

Immediate Steps to Take Right Away

Step 1: Contain the Exposure

Before anything else, stop the ongoing exposure if it is still active. This might mean disabling a compromised user account, retrieving a misdirected fax or email, revoking access to a shared drive, or shutting down a compromised system. The goal at this stage is simple: stop any further access to the information, even before you fully understand the scope of what happened.

Step 2: Document Everything as You Learn It

Start a written incident log the moment you become aware of the situation. Record the date and time you discovered the issue, who reported it, what systems or records were involved, and every action taken from that point forward. This log becomes the backbone of your risk assessment and, if notification is required, your documentation trail for regulators. Practices that wait to document until after the situation is “under control” often lose critical details about the actual timeline.

Step 3: Notify Your Privacy or Security Officer Immediately

Every covered entity is required to designate a Privacy Officer under HIPAA, and this person needs to be looped in immediately, not after an internal investigation has already concluded. If your practice does not have a clearly designated Privacy Officer, or if that role has been informal up to this point, this is the moment that gap becomes a real liability.

Step 4: Conduct a Formal Risk Assessment

HIPAA requires a documented risk assessment to determine the probability that protected health information was compromised. This assessment needs to evaluate the nature and extent of the information involved, the unauthorized person who accessed or received it, whether the information was actually viewed or acquired, and the extent to which the risk has been mitigated. The outcome of this assessment determines whether formal breach notification is legally required or whether the incident falls below that threshold.

Step 5: Identify Everyone Affected

Once you know what happened, determine exactly which patients’ information was involved. This requires pulling the specific records tied to the incident, not estimating the scope. Notification requirements are tied directly to the number of individuals affected, so an inaccurate count at this stage can lead to either under-notifying, which creates legal exposure, or over-notifying, which creates unnecessary panic and cost.

Step 6: Loop In Legal Counsel and Your Cyber Liability Insurer

If your practice carries cyber liability insurance, most policies require notification within a specific window after discovering an incident, and delaying this call can jeopardize coverage. Legal counsel experienced in healthcare compliance can also help interpret whether state-level breach notification laws add additional requirements on top of HIPAA, since many states have their own rules that are stricter or faster than the federal baseline.

Notification Timelines You Cannot Miss

Recipient Deadline
Affected individuals Without unreasonable delay, no later than 60 days from discovery
Department of Health and Human Services (HHS) Within 60 days if 500 or more individuals are affected; annually if fewer than 500
Media notification Required if a breach affects 500 or more residents of a single state or jurisdiction
Business associates Must notify the covered entity without unreasonable delay, generally within 60 days

State laws may impose shorter deadlines than the federal HIPAA requirements, so it is important to check applicable state breach notification statutes in addition to the federal timeline.

What the Patient Notification Letter Must Include

The letter needs to include a brief description of what happened, including the date of the breach and the date it was discovered, along with the specific types of information involved, such as name, Social Security number, diagnosis, or treatment details. It should also outline the steps individuals should take to protect themselves from potential harm, such as monitoring accounts or placing a fraud alert where relevant.

Alongside this, the letter should describe what the practice is doing to investigate, mitigate, and prevent further incidents, so patients understand the situation is being taken seriously and addressed. It should close with clear contact information for questions, including a toll-free number, email address, or mailing address patients can use to follow up directly.

Common Mistakes Practices Make After a Breach

  • Waiting too long to start the risk assessment while trying to fully understand the incident first
  • Notifying patients with vague, generic language instead of the specific details HIPAA requires
  • Failing to check state-specific breach notification laws that may impose shorter deadlines
  • Not documenting the investigation and decision-making process, which becomes critical if HHS later asks for records
  • Overlooking business associate agreements that may require the vendor to notify the practice within a specific window

How to Reduce the Risk of a Future Breach

Conducting a HIPAA security risk assessment at least annually, rather than only after an incident occurs, is one of the most effective ways to catch vulnerabilities before they turn into a breach. This should go hand in hand with keeping an updated inventory of every system and vendor that touches protected health information, and training staff regularly on phishing recognition, since compromised credentials remain one of the most common causes of a breach in the first place.

It also helps to review and update business associate agreements regularly, confirming that each vendor’s breach notification obligations are clearly spelled out rather than assumed. Finally, maintaining a written incident response plan means the first hours after a breach are handled by a process everyone already understands, rather than being figured out under pressure in the moment.

We Handle PHI With the Care It Deserves

A HIPAA breach is stressful enough without also worrying whether your billing partner’s own processes are contributing to the risk. At IPIRCM, every step of our medical billing and revenue cycle management process is handled under strict HIPAA-compliant protocols, so protected health information stays secure at every point it passes through our hands. This includes:

If you want a billing partner that takes data security as seriously as your own compliance team does, call IPIRCM at 877-422-7221 or visit our Medical Billing Services page to learn more about how we keep your patients’ information protected while keeping your revenue cycle running smoothly.

Tag Here
Farhan Shah, President & CEO
A Message From Our President Farhan Shah

“We built IPIRCM to set standards, not follow trends — helping your practice move forward without limits.”

877-422-7221