Scope - What This Guide Covers
This field guide focuses on the operational response after unauthorized access to systems containing protected health information (PHI). It outlines the three core phases you'll encounter: from initial detection to final notification, with a specific focus on HIPAA Security Rule obligations under 45 CFR §§ 164.308, 164.310, and 164.312, plus breach notification requirements under 45 CFR § 164.404-414.
You'll find requirement breakdowns, implementation steps, and a reference table to keep near your incident response binder. This is practical guidance for when your monitoring alerts fire or a decommissioned server reveals compromised files.
Key Concepts and Definitions
Unauthorized Access: Any acquisition, access, use, or disclosure of PHI not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the information (45 CFR § 164.402). This includes both external threats and internal access beyond role-based permissions.
Protected Health Information (PHI): Individually identifiable health information in any form, including names combined with Social Security numbers, financial account information, medical diagnoses, treatment records, or health insurance details.
Breach Notification Timeline: You have 60 days from discovery to notify affected individuals. Discovery means the date you knew or should have known about the breach through reasonable diligence. If the breach affects 500+ individuals in a state, notify prominent media outlets. The HHS Office for Civil Rights must be notified within 60 days for breaches affecting 500+ individuals, or annually for smaller incidents.
Risk Assessment Window: The period between detecting suspicious activity and confirming unauthorized PHI access. Conduct forensic analysis to determine scope, duration, and data elements involved. This window determines your notification clock.
Third-Party Cybersecurity Experts: External forensic investigators who preserve evidence chains, conduct system imaging, analyze access logs, and provide technical findings that support your breach determination. Their reports become part of your regulatory documentation.
Requirements Breakdown
Phase 1: Detection and Containment (Days 0-14)
Within 24 hours of detecting suspicious activity:
- Isolate affected systems while preserving forensic evidence.
- Engage third-party cybersecurity experts to begin investigation.
- Document the detection timeline and initial scope assessment.
- Activate your Computer Security Incident Response Team.
- Preserve all system logs, access records, and authentication data.
HIPAA Security Rule § 164.308(a)(6) requires you to identify and respond to suspected security incidents. Your incident response plan should define "suspicious activity" thresholds that trigger this protocol.
Phase 2: Investigation and Scope Determination (Days 15-90)
Your forensic team will establish:
- Entry and exit dates for unauthorized access.
- Systems and data repositories accessed.
- Specific data elements viewed or acquired.
- Whether encryption rendered data unusable (45 CFR § 164.402 exclusion).
Document every finding. You'll need this for your risk assessment under 45 CFR § 164.402(2), which evaluates four factors: nature of PHI, unauthorized person who accessed it, whether PHI was actually acquired, and extent of risk mitigation.
Phase 3: Notification and Remediation (Days 60-180)
Once you've confirmed PHI compromise, start your 60-day notification clock:
- Draft individual notices listing specific data elements exposed.
- Offer credit monitoring if Social Security numbers were involved (typically 12-24 months).
- File breach report with HHS OCR if 500+ individuals affected.
- Issue substitute notice via website and media if contact information is insufficient.
- Document all notification attempts and delivery confirmations.
Simultaneously, implement corrective actions:
- Decommission compromised systems completely.
- Review access controls on remaining systems.
- Update your risk analysis under § 164.308(a)(1)(ii)(A).
- Revise policies based on incident learnings.
Implementation Guidance
Decommissioning Legacy Systems Securely
Your decommissioning protocol must include:
- Pre-decommission data inventory: Document what PHI resides on the system before you touch it.
- Access restriction during transition: Disable network connectivity before beginning decommissioning.
- Secure data migration: Move necessary data to current systems with encryption in transit.
- Verification scanning: Confirm no unauthorized access occurred during the system's operational life.
- Physical destruction or cryptographic erasure: Follow NIST SP 800-88 media sanitization guidelines.
Engaging Third-Party Forensic Support
When you bring in external experts:
- Execute a Business Associate Agreement before they touch any systems.
- Define their scope: forensic imaging, log analysis, malware identification, or full incident response.
- Request daily status briefings during active investigation.
- Require written findings that support your breach determination.
- Keep their reports under attorney-client privilege when possible.
Managing Multi-Element Data Exposure
When your investigation confirms multiple data types were exposed, your notification letter must list each category. Specify what was in those files.
Your credit monitoring offer should match the risk. Social Security numbers warrant comprehensive identity protection services. Medical information alone might require different mitigation steps, like fraud alerts with health insurers.
Common Pitfalls
Pitfall 1: Starting the notification clock too early You've got 60 days from breach discovery, not from suspicious activity detection. Don't rush notifications before your investigation confirms PHI access.
Pitfall 2: Treating decommissioned systems as low-risk Servers being retired often contain years of unencrypted patient data. They're attractive targets because security teams stop monitoring them. Track systems through final destruction, not just through "operational retirement."
Pitfall 3: Conducting investigations without forensic expertise Your IT team can identify suspicious activity, but determining the exact scope of data access requires forensic tools and methodology. Attempting in-house investigation without proper evidence preservation can destroy the log data you need for accurate breach determination.
Pitfall 4: Assuming encryption solves everything Encryption renders data unusable only if the unauthorized party didn't acquire the decryption key. If your investigation reveals key compromise, the encryption exception under 45 CFR § 164.402 doesn't apply. Document your encryption implementation and key management practices thoroughly.
Pitfall 5: Neglecting business associate notification If the breach occurred at a business associate's systems, they must notify you within 60 days under 45 CFR § 164.410. Don't wait for them -- your BAA should require immediate notification of security incidents, not just confirmed breaches.
Quick Reference Table
| Milestone | Timeline | Key Actions | Documentation Required |
|---|---|---|---|
| Suspicious Activity Detected | Day 0 | Isolate systems, engage forensics, preserve logs | Detection report, initial scope assessment |
| Investigation Initiated | Days 1-3 | Execute BAA with forensic team, begin system imaging | Forensic engagement letter, evidence chain of custody |
| Unauthorized Access Confirmed | Days 15-90 | Complete data element review, determine PHI exposure | Forensic findings report, data inventory |
| Breach Discovery | Day investigation concludes | Start 60-day notification clock, draft notices | Risk assessment under § 164.402(2) |
| Individual Notifications Sent | Within 60 days of discovery | Mail notices, post substitute notice if needed, offer credit monitoring | Delivery confirmations, mailing lists |
| HHS OCR Notification | Within 60 days of discovery (if 500+) | Submit breach report via portal | OCR submission confirmation |
| Media Notification | Within 60 days of discovery (if 500+ in state) | Issue press release to prominent outlets | Media contact records |
| Corrective Actions Implemented | Days 60-180 | Decommission systems, update policies, revise risk analysis | Updated security risk analysis, policy revision log |
Keep this table accessible during your next tabletop exercise. When you're three days into an active incident, you won't remember whether HHS notification is 60 or 72 hours. You'll just check the table and keep moving.




