When Calibrated Healthcare Systems discovered unauthorized network access on February 26, 2024, they triggered a sequence of obligations that led to a class action settlement affecting 34,562 individuals. The settlement included medical monitoring, identity theft insurance, and compensation up to $5,000 per claimant. Your organization's response in the first 72 hours determines whether you face a manageable incident or years of litigation.
This checklist guides you through the operational and regulatory requirements that activate the moment you detect unauthorized access to protected health information. Each item maps to specific Health Insurance Portability and Accountability Act (HIPAA) requirements and practices that reduce your exposure to negligence claims.
Prerequisites
Before executing an effective breach response, ensure these foundational elements are in place:
- Documented Incident Response Plan with Computer Security Incident Response Team roles, escalation paths, and communication templates
- Current asset inventory showing where protected health information resides, who has access, and what systems connect to those repositories
- Breach notification templates pre-cleared by legal counsel for patient notifications, Office for Civil Rights reporting, and media statements
- Cyber insurance policy with coverage limits and claims contact information readily accessible
- Legal counsel relationship with healthcare data breach experience
Without these prerequisites, you'll make decisions under pressure that create additional liability.
Breach Response Checklist
Detection and Containment Phase (Hours 0-24)
1. Document the initial discovery
Record who discovered the incident, when, what systems were affected, and what evidence exists. Create a forensic chain of custody for logs, alerts, and system snapshots. Aim for a timestamped incident ticket with screenshots and unaltered log files preserved.
2. Activate your Computer Security Incident Response Team
Notify the designated incident commander, technical leads, legal counsel, and communications lead. Establish a dedicated communication channel separate from potentially compromised systems. Assemble the team within two hours, using secure out-of-band communication.
3. Contain the incident without destroying evidence
Isolate affected systems while preserving forensic artifacts. Don't immediately wipe systems or revoke all access; you need evidence for root cause analysis and regulatory reporting. Apply network segmentation, disable affected accounts, and capture forensic images before remediation.
4. Assess the scope of unauthorized access
Identify which systems were accessed, what data resides on those systems, and whether data was viewed, copied, or exfiltrated. Document analysis of access logs showing specific files or databases accessed, with conservative estimates when evidence is incomplete.
Investigation Phase (Days 1-30)
5. Engage forensic investigators if warranted
For incidents involving potential criminal activity, sophisticated attacks, or high-volume data exposure, bring in third-party forensic specialists. Their independent findings strengthen your position in regulatory reviews. Engage them within 48 hours, working under attorney-client privilege.
6. Determine if protected health information was involved
Review the data elements on affected systems against HIPAA Privacy Rule definitions. Names, dates of birth, medical diagnoses, treatment information, and health insurance details all constitute protected health information. Map affected systems to data elements with HIPAA Privacy Rule citations for each determination.
7. Conduct breach risk assessment per HIPAA Breach Notification Rule
Evaluate four factors: nature and extent of information involved, unauthorized person who accessed the information, whether information was actually acquired or viewed, and extent to which risk has been mitigated. Document your analysis with a written risk assessment addressing all four factors, signed by privacy officer and legal counsel.
8. Calculate affected individual count
Use access logs, database queries, and system inventories to determine how many individuals' protected health information was potentially compromised. Estimate conservatively when evidence is incomplete, and document your methodology with assumptions clearly stated.
Notification Phase (Days 30-60)
9. Report to Office for Civil Rights if breach affects 500+ individuals
Submit the breach report through the OCR portal within 60 days of discovery. Include the information OCR requires: date of breach, date of discovery, number affected, types of information involved, and brief description. Save OCR submission confirmation with screenshots of all fields completed.
10. Notify affected individuals without unreasonable delay
Send written notification within 60 days of discovery. HIPAA Breach Notification Rule requires specific content: description of the breach, types of information involved, steps individuals should take, what you're doing to investigate and prevent recurrence, and contact information. Provide mailed letters with proof of mailing, staff a call center for inquiries, and set up a dedicated breach notification website.
11. Notify media if breach affects 500+ individuals in a jurisdiction
Provide notice to prominent media outlets serving the affected state or jurisdiction. Time this with individual notifications to avoid creating panic before affected individuals receive direct communication. Distribute a press release the same day individual notifications are mailed, with consistent messaging across channels.
12. Offer identity protection services
While not legally required, offering credit monitoring or identity theft insurance demonstrates good faith and may reduce claims in subsequent litigation. Provide service contracts, generate enrollment codes, and include instructions in breach notification letters.
Documentation and Defense Phase (Ongoing)
13. Create a comprehensive incident timeline
Document every action taken, every decision made, and every communication sent. This timeline becomes your primary defense in regulatory investigations and litigation. Use a spreadsheet with date, time, action, responsible party, and supporting documentation reference for every incident response activity.
14. Preserve all incident-related communications
Place legal hold on emails, chat logs, meeting notes, and documents related to the incident. Spoliation of evidence claims can be more damaging than the underlying breach. Notify IT to suspend auto-deletion policies for relevant custodians, and preserve backup systems.
15. Document your security program's reasonableness
Compile evidence showing your security measures before the breach were appropriate for your organization's size, complexity, and risk profile. HIPAA Security Rule requires addressable controls based on your specific circumstances. Include risk assessments from the prior 12 months, security policy documents, training records, and vendor management documentation.
Common Mistakes
Delayed legal counsel involvement: Organizations that wait to engage counsel until after OCR notification or individual letters go out lose attorney-client privilege protection for early investigative findings. Bring legal in during hour one, not week four.
Inconsistent affected individual counts: When your investigation reveals additional affected individuals after initial reporting, amend your OCR submission immediately. Unexplained discrepancies suggest inadequate investigation.
Inadequate documentation of the breach risk assessment: If you determine an incident doesn't require notification under the breach risk assessment exception, document your analysis thoroughly. OCR reviews these determinations, and insufficient documentation converts a non-reportable incident into a violation.
Generic breach notification letters: Patients receive form letters that don't explain what specific information about them was exposed or what they should do about it. Tailor your notification to the actual data elements compromised and provide specific, actionable guidance.
No post-incident remediation plan: Fixing the specific vulnerability that caused this breach isn't enough. Conduct a broader security program review to identify similar weaknesses. Regulators expect systemic improvements, not point solutions.
Next Steps
After completing this checklist, schedule a tabletop exercise within 90 days to test your team's ability to execute these steps under pressure. Use a scenario that involves ambiguous evidence and compressed timelines, because real breaches never follow your documented plan exactly.
Review your cyber insurance policy to confirm coverage for forensic investigations, legal defense, regulatory fines, and settlement costs. Many policies exclude fines and penalties, leaving you exposed to OCR's enforcement authority.
Update your vendor risk management program to ensure business associates have equivalent breach response capabilities. Your notification timeline starts when you discover the breach, regardless of whether it originated with a vendor.
The difference between a manageable breach response and a multi-year class action lawsuit often comes down to execution in the first 72 hours. This checklist gives you the structure to make defensible decisions when you're operating with incomplete information under regulatory deadlines.
HIPAA Breach Notification Rule
Cyber Insurance





