Skip to content

HIPAA Breach Response Plan

Last Updated: April 2026 Target Audience: Management, IT Manager (HIPAA Security Officer), Operations Manager, All Supervisors Review Frequency: Annually and after every breach incident

This document provides step-by-step procedures for responding to a suspected or confirmed breach of Protected Health Information (PHI). Federal law requires Scott Recycling to notify affected Covered Entities (healthcare customers) within 5 business days of discovering a breach.


What Is a Breach?

A breach is an impermissible use or disclosure of PHI that compromises the security or privacy of the information. Under HIPAA, a breach is presumed unless Scott Recycling can demonstrate through a risk assessment that there is a low probability the PHI was compromised.

Examples of Breaches

Scenario Breach?
A hard drive from a hospital customer is lost before destruction and cannot be located Yes — unsecured ePHI is unaccounted for
Paper patient records found in a dumpster instead of the secure shredding bin Yes — PHI disclosed to unauthorized persons
An employee reads patient records found in equipment out of curiosity Yes — impermissible use of PHI
Healthcare customer materials fall off a truck during transport Likely yes — PHI potentially exposed
An employee emails a healthcare customer's serial number list to the wrong person Possibly — depends on whether PHI was included
A locked box of hard drives from a hospital is stolen from the warehouse Yes — unless drives were encrypted (unsecured PHI)

Exceptions (NOT a Breach)

These situations are not breaches under HIPAA:

  • Unintentional access by an authorized employee acting in good faith within the scope of their job, with no further disclosure
  • Inadvertent disclosure between authorized persons at Scott Recycling, where the information is not further used or disclosed
  • Good faith belief that the person who received the PHI would not be able to retain the information (e.g., a glimpse of a name on a label during normal sorting)

When In Doubt, Report It

If you are unsure whether something is a breach, report it anyway. It is far better to investigate and find no breach than to ignore a real one. There is no penalty for over-reporting.


Breach Response Team

Role Person Responsibility
HIPAA Security Officer IT Manager Leads investigation, conducts risk assessment, coordinates notification
Management Owner / GM Approves notifications, authorizes resources, communicates with legal counsel
Operations Manager Operations Manager Secures physical evidence, interviews staff, implements corrective actions

Step-by-Step Breach Response

Phase 1: Discovery and Reporting (Immediate — Day 0)

Any employee who suspects a breach must act immediately:

  1. Stop the breach if you can do so safely:
    • If PHI is in an unsecured area, move it to a secure location
    • If a device is missing, secure the area and do not move other items
    • If unauthorized access is ongoing, restrict it immediately
  2. Report to your supervisor verbally and immediately — do not wait until end of shift
  3. Supervisor reports to the HIPAA Security Officer (IT Manager) within 1 hour
  4. Document what you observed:
    • Date and time you became aware of the incident
    • What happened (what you saw, heard, or discovered)
    • What PHI may be involved (patient names, records, devices)
    • Who was involved or affected
    • What actions you took

The Clock Starts Now

The 5 business day notification deadline to the Covered Entity starts when ANY employee at Scott Recycling becomes aware of the breach — not when management is informed. Prompt internal reporting is critical.

Phase 2: Investigation and Risk Assessment (Days 0-2)

The HIPAA Security Officer leads the investigation:

  1. Gather facts:

    • Interview the reporting employee and any witnesses
    • Review chain of custody records, access logs, camera footage
    • Determine what PHI was involved and how much
    • Identify which healthcare customer(s) are affected
    • Determine how the breach occurred
  2. Conduct a 4-factor risk assessment (required by 45 C.F.R. §164.402):

    Factor Questions to Answer
    1. Nature and extent of PHI What types of PHI were involved? (names, SSNs, diagnoses, etc.) How many records?
    2. Who accessed or received the PHI Was it an unauthorized employee, an outside party, unknown? Can they be identified?
    3. Was PHI actually acquired or viewed Was the PHI just exposed (e.g., a lost encrypted drive) or actually seen/taken?
    4. Extent of risk mitigation What steps were taken to reduce harm? Was the PHI recovered? Was the recipient contacted?
  3. Determine if it's a reportable breach:

    • If the risk assessment shows low probability of compromise across all 4 factors → document the analysis and retain it for 6 years, but no notification required
    • If there is any reasonable probability of compromise → it is a reportable breach, proceed to Phase 3
  4. Document the investigation — retain all evidence, interview notes, risk assessment findings, and the final determination

Phase 3: Notification (Days 2-4)

If the incident is a reportable breach:

  1. Prepare the notification to the Covered Entity including:

    Required Element Details
    Description of the incident What happened, when it was discovered, how it occurred
    Types of PHI involved Names, SSNs, medical record numbers, diagnoses, etc.
    Identification of affected individuals Names or number of patients whose PHI was involved (if known)
    Mitigation actions taken What Scott Recycling has done to contain and remediate the breach
    Mitigation actions planned What steps will be taken to prevent recurrence
    Contact information Name, phone number, and email for Scott Recycling's point of contact
  2. Management reviews and approves the notification

  3. Send the notification to the Covered Entity:

    • Method: Written notice (email followed by certified mail) to the contact specified in the BAA
    • Deadline: No later than 5 business days from the date any Scott Recycling employee first became aware of the breach
    • Follow up by phone to confirm receipt
  4. Supplement the notification if additional information becomes available — send updates as facts are confirmed

Phase 4: Remediation (Days 5-30)

After notification:

  1. Implement corrective actions to address the root cause:
    • Fix the process failure that caused the breach
    • Update procedures, add controls, increase monitoring
    • Retrain affected employees
  2. Document all corrective actions with dates, owners, and completion status
  3. Cooperate with the Covered Entity — they may have questions, request additional information, or conduct their own investigation
  4. Cooperate with HHS if the Covered Entity reports the breach to the Department of Health and Human Services
  5. Update the risk assessment to reflect lessons learned

Phase 5: Post-Incident Review (Day 30+)

Within 30 days after the breach:

  1. Conduct a post-incident review with the breach response team:
    • What happened and why
    • Were our procedures followed? If not, why not?
    • Was our response timely and effective?
    • What changes are needed to prevent recurrence?
  2. Update policies and procedures based on findings
  3. Conduct additional training if needed
  4. File the complete breach record — retain for 6 years minimum

Breach Response Timeline Summary

Timeframe Action Owner
Immediate Employee reports suspected breach to supervisor Any employee
Within 1 hour Supervisor escalates to HIPAA Security Officer Supervisor
Day 0 Secure the scene, begin evidence collection HIPAA Security Officer + Operations Manager
Days 0-2 Investigation and 4-factor risk assessment HIPAA Security Officer
Day 2 Breach determination made HIPAA Security Officer + Management
Days 2-4 Prepare and send notification to Covered Entity HIPAA Security Officer + Management
Day 5 (max) Covered Entity notified (5 business day deadline) HIPAA Security Officer
Days 5-30 Implement corrective actions, cooperate with customer All
Day 30+ Post-incident review and documentation Breach Response Team

Security Incidents (Non-Breach)

Not every security incident is a breach, but all security incidents must be documented:

  • Unsuccessful login attempts to systems containing healthcare customer data
  • Port scans or firewall probes against our network
  • Attempted phishing emails targeting employees with access to healthcare customer data
  • Physical security incidents (tailgating, propped doors) in areas where PHI is stored

These should be logged and reported to the IT Manager. Routine, unsuccessful attempts (port scans, failed logins) may be reported in aggregate on a monthly basis.


Breach Log

Maintain a log of all suspected and confirmed breaches:

Date Discovered Description Healthcare Customer Affected Breach Confirmed (Y/N) Date Customer Notified Corrective Action Status
(template row)

This log is maintained by the HIPAA Security Officer and reviewed by management quarterly. Retain for a minimum of 6 years.


Contact Information for Breach Reporting

Contact Role How to Reach
IT Manager HIPAA Security Officer In person, phone, or email — immediately
Management Approves notifications In person or phone — same day
Operations Manager Physical evidence and staff In person or phone — immediately

Healthcare Customer Notification Contacts

Covered Entity Contact Name Contact Method BAA Reference
Java Medical Group, LLC Tim Snider (IT Director) Per BAA Effective 4/7/2026

Update this table whenever a new BAA is signed.


Annual Testing

The breach response plan should be tested annually:

  1. Tabletop exercise — walk through a hypothetical breach scenario with the response team
  2. Verify contact information — confirm all notification contacts are current
  3. Review timelines — ensure the team understands the 5 business day deadline
  4. Update the plan based on any changes to staff, procedures, or BAAs


Questions? Contact the IT Manager (HIPAA Security Officer) or Management immediately for any breach-related concerns.