CompyMax

Incidents

An incident log that tracks the clock for you.

Record what happened, work through the four-factor risk assessment, and keep notification deadlines visible. Most incidents never become reportable breaches — the log is what shows you assessed them properly.

Last reviewed .

The four-factor assessment, structured

The rule sets out four factors for deciding whether an impermissible use or disclosure is a reportable breach. The log walks through each one and records your reasoning, which is the part an investigator asks about.

Deadlines tracked from discovery

Notification timing runs from the date of discovery, and the log counts it down rather than leaving it in someone's head. Thresholds that change the obligation are applied based on the number of individuals affected.

Small events recorded too

A misdirected fax that turned out fine still belongs in the log. A record of minor incidents assessed and closed is evidence of a functioning programme, not an admission.

Feeds remediation

An incident can raise tasks directly, so the corrective action is tracked in the same place as everything else and appears in the same evidence pack.

The four-factor assessment, worked through

An impermissible use or disclosure of unsecured patient information is presumed to be a reportable breach. The presumption is rebuttable, but only by a documented risk assessment showing a low probability that the information was compromised — and the burden of proof is on you, under 45 CFR 164.414(b).

The rule names four factors that assessment must consider. The log walks them in order and keeps what you concluded.

  1. The nature and extent of the information

    What types of identifiers were involved, and the likelihood of re-identification. A list of names and appointment dates sits differently from a record set including diagnoses, treatment or financial detail.

  2. Who the unauthorized person was

    Whether the recipient is themselves obliged to protect the information. An email misdirected to another covered entity is a materially different situation from one sent to a personal address.

  3. Whether the information was actually acquired or viewed

    This is the factor most often decided by evidence rather than argument — forensic logs, a returned device, a recipient's attestation. Absence of evidence that it was viewed is not the same as evidence that it was not.

  4. The extent to which the risk has been mitigated

    Confirmed deletion, a signed attestation from the recipient, a remotely wiped device. Mitigation is only as good as the record of it.

There are also express exclusions worth knowing before running the assessment at all — unintentional acquisition by a workforce member acting in good faith within their authority, inadvertent disclosure between authorized people at the same organization, and disclosure where there is a good-faith belief the recipient could not retain the information. Each is narrower than it first sounds, and each requires the same documentation as any other determination.

When the 60-day clock starts, and what it applies to

The single most consequential detail: deadlines run from discovery, not from occurrence. A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to anyone in your workforce other than the person who committed it. A laptop that went missing in March and was noticed in June starts its clock in June — but the question of whether reasonable diligence should have caught it sooner is a live one.

Verified against 45 CFR 164.404, 164.406, 164.408 and 164.410 (eCFR, 2026 edition).
Who you notifyWhenThreshold
Affected individualsWithout unreasonable delay, no later than 60 days from discoveryEvery reportable breach, any size
HHS — large breachWithin 60 days of discovery500 or more individuals in total
HHS — small breachWithin 60 days of the end of the calendar year in which it was discoveredFewer than 500 individuals
Prominent mediaWithout unreasonable delay, no later than 60 days from discoveryMore than 500 residents of a single state or jurisdiction
Your covered-entity customerWithout unreasonable delay, no later than 60 days from discovery — and often far sooner by contractYou are the business associate

Two thresholds sit close together and are easy to conflate: the media notice applies above 500 residents of one state, while the immediate HHS notice applies at 500 or more individuals in total. A breach affecting exactly 500 people spread across three states triggers the immediate HHS notice but not the media notice. The log computes each deadline separately for exactly this reason, and the arithmetic is unit-tested against the regulation.

If you are a business associate, your obligation is different

Business associates notify the covered entity, not individuals and not, in the ordinary case, HHS. That is a meaningfully smaller obligation, and it is frequently misunderstood in both directions — vendors who think they must notify patients, and vendors who think the whole thing is their customer's problem.

Your notice runs to your customer
Without unreasonable delay and no later than 60 days from discovery. Your agreement very likely shortens that; contractual windows of 24 to 72 hours are common and they govern.
You supply what they need to notify
The identity of each affected individual and any other information the covered entity needs for its own notice. Being able to produce that quickly is the practical test.
The covered entity's clock is what patients experience
Their 60 days runs from their discovery, which is generally when you tell them. Late notice from you compresses their timeline, which is why contracts shorten it.
Record it either way
Including incidents you assess and conclude are not reportable. The retention obligation covers the determination, not just the breaches — an assessment you cannot produce is an assessment you did not do.

Common questions

How soon after a breach must notification be given?
Individuals must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people are reported to HHS within the same 60 days; smaller ones go on an annual log submitted within 60 days of year end. A business associate notifies the covered entity on the same clock — the log counts all of it down from the date of discovery.
What is required in a breach notification?
A description of what happened and when, the types of information involved, steps individuals should take to protect themselves, what you are doing to investigate and mitigate, and how to contact you. Writing it is far faster when the incident record already holds the facts in order.
Who must be notified about a confidentiality breach?
The affected individuals, HHS, and — for breaches affecting 500 or more residents of a state — prominent media in that state. Not every incident is a reportable breach: an impermissible disclosure is presumed reportable unless the documented four-factor assessment shows a low probability the information was compromised, which is exactly what this log records. If it looks reportable, involve counsel; nothing here is legal advice.

Software and researched information, not legal advice. No product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules, and using this service does not establish that you comply with them.