Few things create panic inside a medical practice faster than realizing protected health information may have been exposed. Whether it is a misdirected fax, a stolen laptop, a phishing email that compromised a staff account, or a vendor reporting an incident on their end, the first few hours and days after discovering a potential breach matter enormously. What you do immediately can determine whether the situation stays contained and well documented, or turns into a drawn-out compliance problem with regulators, patients, and payers all asking questions at once.
This guide lays out exactly what to do the moment you receive or discover a HIPAA breach notification, in the order it needs to happen, along with the documentation and deadlines that carry legal weight.
Under HIPAA, a breach is generally defined as the unauthorized acquisition, access, use, or disclosure of protected health information that compromises its security or privacy. Not every incident automatically qualifies. HIPAA allows for a risk assessment to determine whether an impermissible use or disclosure rises to the level of a reportable breach, based on factors such as the nature of the information involved, who received it, whether it was actually viewed, and whether the exposure has been mitigated.
This distinction matters because it shapes your very first decision: whether you are dealing with a confirmed breach that triggers notification obligations, or an incident that needs a documented risk assessment before you know for certain.
Before anything else, stop the ongoing exposure if it is still active. This might mean disabling a compromised user account, retrieving a misdirected fax or email, revoking access to a shared drive, or shutting down a compromised system. The goal at this stage is simple: stop any further access to the information, even before you fully understand the scope of what happened.
Start a written incident log the moment you become aware of the situation. Record the date and time you discovered the issue, who reported it, what systems or records were involved, and every action taken from that point forward. This log becomes the backbone of your risk assessment and, if notification is required, your documentation trail for regulators. Practices that wait to document until after the situation is “under control” often lose critical details about the actual timeline.
Every covered entity is required to designate a Privacy Officer under HIPAA, and this person needs to be looped in immediately, not after an internal investigation has already concluded. If your practice does not have a clearly designated Privacy Officer, or if that role has been informal up to this point, this is the moment that gap becomes a real liability.
HIPAA requires a documented risk assessment to determine the probability that protected health information was compromised. This assessment needs to evaluate the nature and extent of the information involved, the unauthorized person who accessed or received it, whether the information was actually viewed or acquired, and the extent to which the risk has been mitigated. The outcome of this assessment determines whether formal breach notification is legally required or whether the incident falls below that threshold.
Once you know what happened, determine exactly which patients’ information was involved. This requires pulling the specific records tied to the incident, not estimating the scope. Notification requirements are tied directly to the number of individuals affected, so an inaccurate count at this stage can lead to either under-notifying, which creates legal exposure, or over-notifying, which creates unnecessary panic and cost.
If your practice carries cyber liability insurance, most policies require notification within a specific window after discovering an incident, and delaying this call can jeopardize coverage. Legal counsel experienced in healthcare compliance can also help interpret whether state-level breach notification laws add additional requirements on top of HIPAA, since many states have their own rules that are stricter or faster than the federal baseline.
| Recipient | Deadline |
|---|---|
| Affected individuals | Without unreasonable delay, no later than 60 days from discovery |
| Department of Health and Human Services (HHS) | Within 60 days if 500 or more individuals are affected; annually if fewer than 500 |
| Media notification | Required if a breach affects 500 or more residents of a single state or jurisdiction |
| Business associates | Must notify the covered entity without unreasonable delay, generally within 60 days |
State laws may impose shorter deadlines than the federal HIPAA requirements, so it is important to check applicable state breach notification statutes in addition to the federal timeline.
The letter needs to include a brief description of what happened, including the date of the breach and the date it was discovered, along with the specific types of information involved, such as name, Social Security number, diagnosis, or treatment details. It should also outline the steps individuals should take to protect themselves from potential harm, such as monitoring accounts or placing a fraud alert where relevant.
Alongside this, the letter should describe what the practice is doing to investigate, mitigate, and prevent further incidents, so patients understand the situation is being taken seriously and addressed. It should close with clear contact information for questions, including a toll-free number, email address, or mailing address patients can use to follow up directly.
Conducting a HIPAA security risk assessment at least annually, rather than only after an incident occurs, is one of the most effective ways to catch vulnerabilities before they turn into a breach. This should go hand in hand with keeping an updated inventory of every system and vendor that touches protected health information, and training staff regularly on phishing recognition, since compromised credentials remain one of the most common causes of a breach in the first place.
It also helps to review and update business associate agreements regularly, confirming that each vendor’s breach notification obligations are clearly spelled out rather than assumed. Finally, maintaining a written incident response plan means the first hours after a breach are handled by a process everyone already understands, rather than being figured out under pressure in the moment.
A HIPAA breach is stressful enough without also worrying whether your billing partner’s own processes are contributing to the risk. At IPIRCM, every step of our medical billing and revenue cycle management process is handled under strict HIPAA-compliant protocols, so protected health information stays secure at every point it passes through our hands. This includes:
If you want a billing partner that takes data security as seriously as your own compliance team does, call IPIRCM at 877-422-7221 or visit our Medical Billing Services page to learn more about how we keep your patients’ information protected while keeping your revenue cycle running smoothly.
“We built IPIRCM to set standards, not follow trends — helping your practice move forward without limits.”
We didn't build these companies to follow trends — we built them to set standards. From IPIPAK's trusted BPO, to IPIRCM's full-cycle U.S. medical billing, to IPITECHNO's cutting-edge IT solutions, every company exists to move your business forward without limits.
Together we are more than three brands. We are one vision: to make business simpler, faster, and stronger for those who dare to grow. It is an honor to lead this group — and a greater honor to serve you.


