Product tour. Sample data for a fictional 14-person billing company — including its overdue items, because that is what a real dashboard looks like. Start your own.

Incident log

Record what happened, work through the risk assessment, and keep the deadlines visible. Most entries never become reportable breaches — but the log is what shows you assessed them.

Open

1

Assessment in progress

Recorded this year

2

Determined reportable

0

Requiring notification

INC-2026-003

Statement mailed to wrong address

Discovered July 11, 2026 · 1 individual affected

Assessing
42 days until the notification deadlineTracked from the date of discovery.

INC-2026-002

Phishing email reported by staff, no credentials entered

Discovered May 2, 2026

Closed

How the assessment works

When an incident involves patient information, the log walks you through the four factors the Breach Notification Rule sets out — the nature and extent of the information, who received or accessed it, whether it was actually acquired or viewed, and how far the risk has been mitigated. Your answers and reasoning are recorded, which is the part an investigator asks to see.

Deadlines and thresholds shown here are configured against the published rule text. They are a scheduling aid, not legal advice — a reportable breach warrants talking to counsel.