Incidents
An incident log that tracks the clock for you.
Record what happened, work through the four-factor risk assessment, and keep notification deadlines visible. Most incidents never become reportable breaches — the log is what shows you assessed them properly.
Last reviewed .
The four-factor assessment, structured
The rule sets out four factors for deciding whether an impermissible use or disclosure is a reportable breach. The log walks through each one and records your reasoning, which is the part an investigator asks about.
Deadlines tracked from discovery
Notification timing runs from the date of discovery, and the log counts it down rather than leaving it in someone's head. Thresholds that change the obligation are applied based on the number of individuals affected.
Small events recorded too
A misdirected fax that turned out fine still belongs in the log. A record of minor incidents assessed and closed is evidence of a functioning programme, not an admission.
Feeds remediation
An incident can raise tasks directly, so the corrective action is tracked in the same place as everything else and appears in the same evidence pack.
The four-factor assessment, worked through
An impermissible use or disclosure of unsecured patient information is presumed to be a reportable breach. The presumption is rebuttable, but only by a documented risk assessment showing a low probability that the information was compromised — and the burden of proof is on you, under 45 CFR 164.414(b).
The rule names four factors that assessment must consider. The log walks them in order and keeps what you concluded.
The nature and extent of the information
What types of identifiers were involved, and the likelihood of re-identification. A list of names and appointment dates sits differently from a record set including diagnoses, treatment or financial detail.
Who the unauthorized person was
Whether the recipient is themselves obliged to protect the information. An email misdirected to another covered entity is a materially different situation from one sent to a personal address.
Whether the information was actually acquired or viewed
This is the factor most often decided by evidence rather than argument — forensic logs, a returned device, a recipient's attestation. Absence of evidence that it was viewed is not the same as evidence that it was not.
The extent to which the risk has been mitigated
Confirmed deletion, a signed attestation from the recipient, a remotely wiped device. Mitigation is only as good as the record of it.
There are also express exclusions worth knowing before running the assessment at all — unintentional acquisition by a workforce member acting in good faith within their authority, inadvertent disclosure between authorized people at the same organization, and disclosure where there is a good-faith belief the recipient could not retain the information. Each is narrower than it first sounds, and each requires the same documentation as any other determination.
When the 60-day clock starts, and what it applies to
The single most consequential detail: deadlines run from discovery, not from occurrence. A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to anyone in your workforce other than the person who committed it. A laptop that went missing in March and was noticed in June starts its clock in June — but the question of whether reasonable diligence should have caught it sooner is a live one.
| Who you notify | When | Threshold |
|---|---|---|
| Affected individuals | Without unreasonable delay, no later than 60 days from discovery | Every reportable breach, any size |
| HHS — large breach | Within 60 days of discovery | 500 or more individuals in total |
| HHS — small breach | Within 60 days of the end of the calendar year in which it was discovered | Fewer than 500 individuals |
| Prominent media | Without unreasonable delay, no later than 60 days from discovery | More than 500 residents of a single state or jurisdiction |
| Your covered-entity customer | Without unreasonable delay, no later than 60 days from discovery — and often far sooner by contract | You are the business associate |
Two thresholds sit close together and are easy to conflate: the media notice applies above 500 residents of one state, while the immediate HHS notice applies at 500 or more individuals in total. A breach affecting exactly 500 people spread across three states triggers the immediate HHS notice but not the media notice. The log computes each deadline separately for exactly this reason, and the arithmetic is unit-tested against the regulation.
If you are a business associate, your obligation is different
Business associates notify the covered entity, not individuals and not, in the ordinary case, HHS. That is a meaningfully smaller obligation, and it is frequently misunderstood in both directions — vendors who think they must notify patients, and vendors who think the whole thing is their customer's problem.
- Your notice runs to your customer
- Without unreasonable delay and no later than 60 days from discovery. Your agreement very likely shortens that; contractual windows of 24 to 72 hours are common and they govern.
- You supply what they need to notify
- The identity of each affected individual and any other information the covered entity needs for its own notice. Being able to produce that quickly is the practical test.
- The covered entity's clock is what patients experience
- Their 60 days runs from their discovery, which is generally when you tell them. Late notice from you compresses their timeline, which is why contracts shorten it.
- Record it either way
- Including incidents you assess and conclude are not reportable. The retention obligation covers the determination, not just the breaches — an assessment you cannot produce is an assessment you did not do.
Common questions
- How soon after a breach must notification be given?
- Individuals must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people are reported to HHS within the same 60 days; smaller ones go on an annual log submitted within 60 days of year end. A business associate notifies the covered entity on the same clock — the log counts all of it down from the date of discovery.
- What is required in a breach notification?
- A description of what happened and when, the types of information involved, steps individuals should take to protect themselves, what you are doing to investigate and mitigate, and how to contact you. Writing it is far faster when the incident record already holds the facts in order.
- Who must be notified about a confidentiality breach?
- The affected individuals, HHS, and — for breaches affecting 500 or more residents of a state — prominent media in that state. Not every incident is a reportable breach: an impermissible disclosure is presumed reportable unless the documented four-factor assessment shows a low probability the information was compromised, which is exactly what this log records. If it looks reportable, involve counsel; nothing here is legal advice.
Keep reading
- HIPAA risk assessment softwareGuided assessment with remediation tracking and carry-forward.
- Policies and acknowledgementsVersioned policies your staff read and sign.
- Staff training and certificatesAnnual courses with dated certificates and chasing.
- Vendor and BAA registerWho touches patient data, what is signed, when it expires.
- Free BAA template generatorA plain-language agreement with every required provision, built in your browser.
Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.