Your employee just sent a file with patient records. The voice on the phone seemed legitimate, perhaps the IT director or a vendor contact. Minutes later, your security team flags the activity. You're now in the first hour of a vishing incident.
This checklist guides you through immediate response steps when social engineering compromises protected health information (PHI). It's designed for healthcare GRC teams to act quickly while maintaining HIPAA Security Rule compliance and preserving forensic evidence.
Purpose of This Checklist
Use this template when an employee has been tricked into disclosing PHI, granting system access, or transferring sensitive files through deception, whether by phone (vishing), email (phishing), or in-person pretexting.
The checklist covers the first 72 hours after discovery and aligns with HIPAA Breach Notification Rule requirements. It complements your incident response plan, bridging the gap between "something's wrong" and "we've activated our full CSIRT."
Prerequisites
Before using this checklist:
- Designated response lead: Identify who activates the checklist (typically your privacy officer, CISO, or compliance director).
- Contact sheet ready: Keep current phone numbers for legal counsel, forensics firm, cyber insurance carrier, and HHS breach notification contact.
- Access to logs: Ensure you can retrieve email gateway logs, authentication logs, and file access logs within 30 minutes.
- Notification templates: Pre-draft your breach notification letter and have it legally reviewed now.
You'll also need authority to isolate accounts quickly, social engineering incidents require swift decisions.
The Checklist
Hour 0-2: Containment
Immediate actions (first 15 minutes):
- Document discovery time and method (who reported it, what triggered the alert).
- Isolate the compromised account: disable credentials, revoke active sessions.
- If file transfer occurred: identify receiving email address or phone number.
- Preserve the employee's workstation state, do not let them "fix" anything.
- Contact your cyber insurance carrier (many policies require notice within 24 hours).
Initial scoping (next 90 minutes):
- Interview the employee while details are fresh, use your IR interview script.
- Pull authentication logs for the past 7 days for the compromised account.
- Review outbound email/file transfer logs for unusual recipients or attachment sizes.
- Check if MFA was bypassed or if the attacker used the employee's valid session.
- Identify what data classifications the employee had access to (PHI, PII, financial).
Stakeholder notification:
- Brief your privacy officer on data types potentially exposed.
- Notify legal counsel, they'll guide breach determination under HIPAA.
- Alert executive sponsor (your breach may require board notification depending on scale).
- If the incident involves a business associate, notify them per your BAA terms.
Hour 2-24: Investigation
Forensic evidence collection:
- Engage third-party forensics if the incident involves email account compromise.
- Image the employee's workstation before anyone touches it again.
- Export all emails to/from the compromised account for the relevant timeframe.
- Request phone records if vishing is suspected (with employee consent and legal guidance).
- Document the social engineering technique used, this informs your training response.
Data exposure assessment:
- List every file accessed or sent during the compromise window.
- For each file, catalog: record count, data elements (name, DOB, SSN, diagnosis codes, insurance IDs).
- Cross-reference against your data inventory, do you know what was in those files?
- Determine if encryption was applied (encrypted PHI may not trigger breach notification).
- Calculate affected individual count (you need this for HHS reporting threshold).
Breach determination (consult legal counsel):
- Apply HIPAA's low probability standard: consider nature of PHI, who received it, whether it was actually acquired/viewed, and extent of mitigation.
- Document your risk assessment in writing, HHS will ask for it.
- If you determine it's a breach affecting 500+ individuals, you have 60 days to notify HHS and must report to media.
- If under 500 individuals, you still notify affected persons within 60 days and report to HHS annually.
Hour 24-72: Notification Planning
Affected individual notification (if breach determination is yes):
- Finalize notification letter using your template, include: date of breach, description of incident, types of PHI involved, steps you're taking, what individuals should do, contact information.
- Decide on notification method: first-class mail is HIPAA's default; email requires prior consent.
- If 10+ individuals have insufficient contact information, post substitute notice on your website and in major media for 90 days.
- Arrange credit monitoring services if SSNs or financial information were exposed.
- Prepare call center scripts for individuals who phone with questions.
Regulatory reporting:
- If 500+ individuals affected: submit breach report to HHS within 60 days via the breach portal.
- If breach affects residents of multiple states, check state-specific notification laws (some have shorter windows than HIPAA's 60 days).
- Notify business associates if the breach originated from or impacts their systems.
- Document everything in your incident log, your next audit will review this.
Remediation:
- Schedule targeted training for the affected employee and their department within one week.
- Review authentication controls: can you enforce MFA for file transfers or high-risk actions?
- Update your email security rules to flag external senders impersonating internal domains.
- Add vishing scenarios to your next security awareness training cycle.
- Test your incident response plan, did this checklist expose gaps?
How to Customize It
For smaller practices (under 50 employees):
You likely don't have a dedicated CSIRT. Assign the privacy officer as the default checklist owner and pre-contract with a forensics firm. Simplify the stakeholder notification section to just privacy officer and legal counsel.
For multi-facility health systems:
Add a facility-level coordinator to each section. Your breach may span multiple locations if the compromised account had enterprise access. Include your compliance committee chair in the Hour 0-2 notification list.
For business associates:
Insert a step in Hour 0-2 to notify your covered entity clients per your BAA. Their breach notification clock starts when you inform them, not when you discovered the incident.
For organizations subject to state-specific laws:
Some states (e.g., New York, California) have breach notification timelines shorter than HIPAA's 60 days. Add a jurisdiction check to your Hour 24-72 section and maintain a matrix of state requirements.
Validation Steps
Test this checklist quarterly using tabletop exercises:
- Scenario realism: Use vishing and email compromise patterns from real incidents.
- Time pressure: Force decisions in compressed windows, can your team execute Hour 0-2 steps in real-time?
- Log accessibility: Verify you can pull the required logs within your stated timeframes.
- Contact sheet accuracy: Call your forensics firm and legal counsel contacts, are the numbers current?
- Notification mechanics: Do you have current mailing addresses for patients? Can you generate the affected individual list from your EHR?
After each test, update the checklist. The version you validate today is the version that works when an employee forwards PHI to an attacker tomorrow.
Your incident response plan is comprehensive. This checklist is what you hand to the person who answers the phone when your employee says, "I think I just made a mistake."





