HIPAA Breach Response Plan¶
Last Updated: April 2026 Target Audience: Management, IT Manager (HIPAA Security Officer), Operations Manager, All Supervisors Review Frequency: Annually and after every breach incident
This document provides step-by-step procedures for responding to a suspected or confirmed breach of Protected Health Information (PHI). Federal law requires Scott Recycling to notify affected Covered Entities (healthcare customers) within 5 business days of discovering a breach.
What Is a Breach?¶
A breach is an impermissible use or disclosure of PHI that compromises the security or privacy of the information. Under HIPAA, a breach is presumed unless Scott Recycling can demonstrate through a risk assessment that there is a low probability the PHI was compromised.
Examples of Breaches¶
| Scenario | Breach? |
|---|---|
| A hard drive from a hospital customer is lost before destruction and cannot be located | Yes — unsecured ePHI is unaccounted for |
| Paper patient records found in a dumpster instead of the secure shredding bin | Yes — PHI disclosed to unauthorized persons |
| An employee reads patient records found in equipment out of curiosity | Yes — impermissible use of PHI |
| Healthcare customer materials fall off a truck during transport | Likely yes — PHI potentially exposed |
| An employee emails a healthcare customer's serial number list to the wrong person | Possibly — depends on whether PHI was included |
| A locked box of hard drives from a hospital is stolen from the warehouse | Yes — unless drives were encrypted (unsecured PHI) |
Exceptions (NOT a Breach)¶
These situations are not breaches under HIPAA:
- Unintentional access by an authorized employee acting in good faith within the scope of their job, with no further disclosure
- Inadvertent disclosure between authorized persons at Scott Recycling, where the information is not further used or disclosed
- Good faith belief that the person who received the PHI would not be able to retain the information (e.g., a glimpse of a name on a label during normal sorting)
When In Doubt, Report It
If you are unsure whether something is a breach, report it anyway. It is far better to investigate and find no breach than to ignore a real one. There is no penalty for over-reporting.
Breach Response Team¶
| Role | Person | Responsibility |
|---|---|---|
| HIPAA Security Officer | IT Manager | Leads investigation, conducts risk assessment, coordinates notification |
| Management | Owner / GM | Approves notifications, authorizes resources, communicates with legal counsel |
| Operations Manager | Operations Manager | Secures physical evidence, interviews staff, implements corrective actions |
Step-by-Step Breach Response¶
Phase 1: Discovery and Reporting (Immediate — Day 0)¶
Any employee who suspects a breach must act immediately:
- Stop the breach if you can do so safely:
- If PHI is in an unsecured area, move it to a secure location
- If a device is missing, secure the area and do not move other items
- If unauthorized access is ongoing, restrict it immediately
- Report to your supervisor verbally and immediately — do not wait until end of shift
- Supervisor reports to the HIPAA Security Officer (IT Manager) within 1 hour
- Document what you observed:
- Date and time you became aware of the incident
- What happened (what you saw, heard, or discovered)
- What PHI may be involved (patient names, records, devices)
- Who was involved or affected
- What actions you took
The Clock Starts Now
The 5 business day notification deadline to the Covered Entity starts when ANY employee at Scott Recycling becomes aware of the breach — not when management is informed. Prompt internal reporting is critical.
Phase 2: Investigation and Risk Assessment (Days 0-2)¶
The HIPAA Security Officer leads the investigation:
-
Gather facts:
- Interview the reporting employee and any witnesses
- Review chain of custody records, access logs, camera footage
- Determine what PHI was involved and how much
- Identify which healthcare customer(s) are affected
- Determine how the breach occurred
-
Conduct a 4-factor risk assessment (required by 45 C.F.R. §164.402):
Factor Questions to Answer 1. Nature and extent of PHI What types of PHI were involved? (names, SSNs, diagnoses, etc.) How many records? 2. Who accessed or received the PHI Was it an unauthorized employee, an outside party, unknown? Can they be identified? 3. Was PHI actually acquired or viewed Was the PHI just exposed (e.g., a lost encrypted drive) or actually seen/taken? 4. Extent of risk mitigation What steps were taken to reduce harm? Was the PHI recovered? Was the recipient contacted? -
Determine if it's a reportable breach:
- If the risk assessment shows low probability of compromise across all 4 factors → document the analysis and retain it for 6 years, but no notification required
- If there is any reasonable probability of compromise → it is a reportable breach, proceed to Phase 3
-
Document the investigation — retain all evidence, interview notes, risk assessment findings, and the final determination
Phase 3: Notification (Days 2-4)¶
If the incident is a reportable breach:
-
Prepare the notification to the Covered Entity including:
Required Element Details Description of the incident What happened, when it was discovered, how it occurred Types of PHI involved Names, SSNs, medical record numbers, diagnoses, etc. Identification of affected individuals Names or number of patients whose PHI was involved (if known) Mitigation actions taken What Scott Recycling has done to contain and remediate the breach Mitigation actions planned What steps will be taken to prevent recurrence Contact information Name, phone number, and email for Scott Recycling's point of contact -
Management reviews and approves the notification
-
Send the notification to the Covered Entity:
- Method: Written notice (email followed by certified mail) to the contact specified in the BAA
- Deadline: No later than 5 business days from the date any Scott Recycling employee first became aware of the breach
- Follow up by phone to confirm receipt
-
Supplement the notification if additional information becomes available — send updates as facts are confirmed
Phase 4: Remediation (Days 5-30)¶
After notification:
- Implement corrective actions to address the root cause:
- Fix the process failure that caused the breach
- Update procedures, add controls, increase monitoring
- Retrain affected employees
- Document all corrective actions with dates, owners, and completion status
- Cooperate with the Covered Entity — they may have questions, request additional information, or conduct their own investigation
- Cooperate with HHS if the Covered Entity reports the breach to the Department of Health and Human Services
- Update the risk assessment to reflect lessons learned
Phase 5: Post-Incident Review (Day 30+)¶
Within 30 days after the breach:
- Conduct a post-incident review with the breach response team:
- What happened and why
- Were our procedures followed? If not, why not?
- Was our response timely and effective?
- What changes are needed to prevent recurrence?
- Update policies and procedures based on findings
- Conduct additional training if needed
- File the complete breach record — retain for 6 years minimum
Breach Response Timeline Summary¶
| Timeframe | Action | Owner |
|---|---|---|
| Immediate | Employee reports suspected breach to supervisor | Any employee |
| Within 1 hour | Supervisor escalates to HIPAA Security Officer | Supervisor |
| Day 0 | Secure the scene, begin evidence collection | HIPAA Security Officer + Operations Manager |
| Days 0-2 | Investigation and 4-factor risk assessment | HIPAA Security Officer |
| Day 2 | Breach determination made | HIPAA Security Officer + Management |
| Days 2-4 | Prepare and send notification to Covered Entity | HIPAA Security Officer + Management |
| Day 5 (max) | Covered Entity notified (5 business day deadline) | HIPAA Security Officer |
| Days 5-30 | Implement corrective actions, cooperate with customer | All |
| Day 30+ | Post-incident review and documentation | Breach Response Team |
Security Incidents (Non-Breach)¶
Not every security incident is a breach, but all security incidents must be documented:
- Unsuccessful login attempts to systems containing healthcare customer data
- Port scans or firewall probes against our network
- Attempted phishing emails targeting employees with access to healthcare customer data
- Physical security incidents (tailgating, propped doors) in areas where PHI is stored
These should be logged and reported to the IT Manager. Routine, unsuccessful attempts (port scans, failed logins) may be reported in aggregate on a monthly basis.
Breach Log¶
Maintain a log of all suspected and confirmed breaches:
| Date Discovered | Description | Healthcare Customer Affected | Breach Confirmed (Y/N) | Date Customer Notified | Corrective Action | Status |
|---|---|---|---|---|---|---|
| (template row) |
This log is maintained by the HIPAA Security Officer and reviewed by management quarterly. Retain for a minimum of 6 years.
Contact Information for Breach Reporting¶
| Contact | Role | How to Reach |
|---|---|---|
| IT Manager | HIPAA Security Officer | In person, phone, or email — immediately |
| Management | Approves notifications | In person or phone — same day |
| Operations Manager | Physical evidence and staff | In person or phone — immediately |
Healthcare Customer Notification Contacts¶
| Covered Entity | Contact Name | Contact Method | BAA Reference |
|---|---|---|---|
| Java Medical Group, LLC | Tim Snider (IT Director) | Per BAA | Effective 4/7/2026 |
Update this table whenever a new BAA is signed.
Annual Testing¶
The breach response plan should be tested annually:
- Tabletop exercise — walk through a hypothetical breach scenario with the response team
- Verify contact information — confirm all notification contacts are current
- Review timelines — ensure the team understands the 5 business day deadline
- Update the plan based on any changes to staff, procedures, or BAAs
Related Documents¶
- HIPAA Compliance Policy — Overall HIPAA policy, safeguards, and responsibilities
- Data Destruction Procedures — Chain of custody, destruction methods, certificates
- HIPAA Training — Employee training on PHI handling and breach reporting
Questions? Contact the IT Manager (HIPAA Security Officer) or Management immediately for any breach-related concerns.