HIPAA Incident Response Plan: What to Do in Hour One
It's 4:52 p.m. on a Friday. Your billing coordinator calls: she clicked a link in what looked like a payer portal notice, entered her credentials, and now her mailbox is sending messages she didn't write. Her inbox holds roughly eighteen months of eligibility discussions, prior auth appeals, and scanned superbills. What happens in the next sixty minutes determines whether you have a manageable security incident or a six-figure notification event.
A HIPAA incident response plan is the written, tested procedure your workforce follows when protected health information may have been accessed, exposed, altered, or made unavailable. It is required by the Security Rule — not optional, not a best practice. This article covers who owns which task, the deadlines that start ticking on discovery, and the documentation you need on file if the Office for Civil Rights ever asks.
The Rule That Actually Requires a HIPAA Incident Response Plan
Look at 45 CFR § 164.308(a)(6). It's short, and it's a required implementation specification — no "addressable" escape hatch. You must identify and respond to suspected or known security incidents, mitigate harmful effects to the extent practicable, and document incidents and their outcomes.
The definition of "security incident" at § 164.304 is broader than most administrators assume: attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations. A failed brute-force attempt against your VPN is a security incident. So is a ransomware event that never exfiltrates a single record, because it destroyed availability.
That breadth matters. If your plan only activates when you're certain PHI walked out the door, it activates too late. The whole point of a HIPAA incident response plan is to start collecting facts before you know whether you have a breach.
What HHS proposed in January 2025 — and where it stands
In January 2025, HHS published a notice of proposed rulemaking to modernize the Security Rule. Among the proposals: mandatory written incident response plans and procedures, documented testing and revision on a set cadence, and tighter notification windows for business associates when contingency plans are activated. As of this writing in December 2025, that rule is not final.
Don't wait for it. Practices that already maintain a tested written plan will absorb the final rule as a documentation exercise. Practices that don't will be rebuilding under a deadline.
What Must a HIPAA Incident Response Plan Include?
A compliant HIPAA incident response plan documents six things:
- Detection and reporting. How any workforce member reports a suspected incident, to whom, and within what window (most practices set one hour for suspected PHI exposure).
- Named roles. An incident lead, a technical responder, a communications owner, and a legal/regulatory contact — by name and by backup, with after-hours phone numbers.
- Severity triage. Written criteria that sort incidents into tiers so a single lost fax cover sheet doesn't trigger the same escalation as an encrypted file server.
- Containment, eradication, and recovery steps. Concrete actions: disable the account, isolate the endpoint, force password resets, restore from the last verified backup.
- Breach risk assessment. The four-factor analysis under § 164.402 and who signs off on the conclusion.
- Notification workflow and evidence retention. Deadlines for individuals, HHS, media, and state regulators, plus a six-year document retention practice under § 164.316(b)(2).
If your plan is a one-page policy that says "the Security Officer will investigate," it will not survive contact with an actual incident.
Incident vs. Breach: The Distinction That Drives Every Clock
Every breach is an incident. Most incidents are not breaches. The Breach Notification Rule creates a presumption: an impermissible acquisition, access, use, or disclosure of unsecured PHI is a breach unless you demonstrate a low probability that the PHI was compromised.
You overcome that presumption only through a documented four-factor risk assessment:
- The nature and extent of the PHI involved, including identifier types and the likelihood of re-identification.
- The unauthorized person who used the PHI or to whom the disclosure was made.
- Whether the PHI was actually acquired or viewed.
- The extent to which the risk to the PHI has been mitigated.
Write the analysis down. Every factor, with the evidence supporting your conclusion. A determination of "low probability of compromise" with no supporting memo is functionally identical, in an OCR investigation, to no determination at all. HHS maintains the governing text and guidance on its breach notification page.
The 60-day clock starts at discovery, not at conclusion
A breach is treated as discovered on the first day it is known — or, exercising reasonable diligence, would have been known — to your practice or any workforce member other than the person who caused it. Individual notice must go out without unreasonable delay and no later than 60 calendar days after that date.
Read that again: the clock runs from discovery, not from the day your forensics vendor finishes. If your investigation takes 45 days, you have 15 days left to write letters, verify addresses, and mail. Build that math into your plan.
Reporting to HHS
For a breach affecting 500 or more individuals, notify HHS contemporaneously with individual notice — no later than 60 days from discovery — and notify prominent media outlets serving the state or jurisdiction. For breaches affecting fewer than 500, maintain a log and submit those to HHS within 60 days after the end of the calendar year. That means small 2025 incidents are due by March 1, 2026.
Submissions go through the OCR breach reporting portal. The same system powers the public breach listing, which is worth reviewing quarterly to see what's actually hitting practices your size.
Roles: Who Does What in Hour One, Day One, and Week One
Hour one
Reporting employee: stops using the affected device or account and calls the incident lead directly. No email — the mailbox may be the problem.
Incident lead (usually your Privacy or Security Officer): opens an incident record with a timestamp, assigns a tracking number, and starts a running log. Every entry gets a time and an initial.
Technical responder (internal IT or your MSP): disables the compromised account, revokes active sessions and app passwords, isolates the endpoint from the network, and preserves logs before anything is reimaged. Preservation before remediation — reimaging a laptop on day one is how practices lose the evidence that would have proven low probability of compromise.
Day one
Determine scope: which mailboxes, which shares, which date ranges, how many distinct patients. Pull sign-in logs and mail forwarding rules. Check whether any inbox rules were created to hide replies — that's a routine attacker move and a strong indicator of actual access.
Notify your cyber insurance carrier. Most policies require prompt notice and many require you to use panel counsel or panel forensics; calling your own vendor first can jeopardize coverage.
If a vendor caused the incident, open the notification clause in their BAA and read it that day.
Week one
Complete the four-factor assessment. Draft notification letters if required. Identify the root cause and the corrective action — not "employee error," but "no phishing-resistant MFA on cloud mailboxes" or "no conditional access policy blocking foreign logins." OCR resolution agreements consistently focus on whether the root cause was addressed, not whether the incident happened.
Your Vendors Are Half Your Incident Surface
A business associate must notify you of a breach without unreasonable delay and no later than 60 days after discovery under § 164.410. That default is useless to you. If your transcription vendor uses all 60 days, you have zero days left to notify patients.
Negotiate shorter. Standard practice for practices that take this seriously: notice of any suspected security incident within 24 to 72 hours, a full written report within 10 business days, and a contractual obligation to cooperate with your investigation and provide logs on request. Specify who pays for notification and credit monitoring if the vendor's failure caused it.
Then check that you actually have signed agreements with everyone on your vendor list — the answering service, the shredding company, the IT contractor with domain admin, the cloud fax provider, the marketing agency with access to your patient portal analytics. If you're missing agreements or working from a template that says nothing useful about breach timelines, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — useful when you need three agreements this week and not a platform.
A Worked Example: The Friday Phishing Call
Back to the billing coordinator. Here's what a functioning plan produces.
4:55 p.m. Incident lead opens record INC-2025-014. Technical responder disables the account and revokes sessions.
5:20 p.m. Sign-in logs show two successful authentications from an IP geolocated outside the country, 41 minutes apart. A mail forwarding rule was created routing messages containing "invoice" or "remit" to an external address, then deleted.
5:45 p.m. Lead notifies the practice owner and the cyber carrier's 24-hour hotline. Carrier assigns counsel.
Monday. Mailbox export scoped to the access window. 1,340 messages accessible, 212 containing patient identifiers across 178 unique patients.
Day 9. Four-factor assessment completed. Factor three is decisive: the forwarding rule targeted financial keywords, but the attacker had unrestricted mailbox access during two sessions and cannot be shown not to have viewed PHI. Conclusion: breach presumption not overcome.
Day 22. Letters mailed to 178 individuals. Substitute notice not required — fewer than 10 addresses were insufficient.
Day 24. Logged for annual HHS submission (under 500).
Day 30. Corrective action documented: phishing-resistant MFA enforced on all mailboxes, conditional access geo-restrictions applied, forwarding-rule alerting enabled, targeted retraining for the billing team.
Total elapsed time from discovery to notification: 22 days. That's what a rehearsed plan buys you.
Test It Twice a Year, and Write Down That You Did
A plan nobody has run is a document, not a capability. Schedule two tabletop exercises a year, 90 minutes each, with the actual people named in the plan. Use scenarios that match your real risk profile: ransomware on the practice management server, a lost unencrypted laptop, a mis-sent records fax, a vendor notifying you of their own breach.
Capture the output: date, scenario, participants, gaps identified, and remediation owners with due dates. NIST's incident handling guidance is the standard reference for structuring the lifecycle, and it maps cleanly onto Security Rule obligations.
Feed every exercise finding back into your risk analysis. Your incident response plan and your risk analysis and policy set should reference each other; auditors notice when they don't.
The Evidence File OCR Will Ask For
When a complaint or breach report triggers an OCR data request, they don't ask whether you had a plan. They ask for it, dated, along with:
- The current written HIPAA incident response plan with version history and approval date
- Your incident log for the past six years, including incidents determined not to be breaches
- The four-factor risk assessment for each incident, signed
- Copies of notification letters, mailing records, and HHS submission confirmations
- Tabletop exercise records and resulting corrective actions
- Workforce training records covering incident reporting
- Executed business associate agreements for every vendor involved
Keep it all for six years from creation or last effective date. Store it somewhere that survives the ransomware event you're planning for — an offline or separately-credentialed copy, not a folder on the file server.
Three Failures That Cost Practices the Most
No after-hours path. Incidents happen at 7 p.m. and on holiday weekends. If your plan routes through an office phone nobody answers, your discovery date and your response date are days apart, and you'll be explaining that gap.
Reimaging before preserving. IT's instinct is to restore service. Your instinct must be to capture logs first. Once the evidence is gone, the presumption of breach is very hard to rebut.
Never documenting the non-breaches. Practices log the big events and skip the fax sent to a wrong number that was confirmed shredded. That confirmed-shredded fax, documented, is exactly the record that shows a functioning program.
Start This Week
Pick a date in the next fourteen days. Name your incident lead and backup, write their cell numbers into the plan, set your internal reporting window, and run one tabletop. If that exercise surfaces vendors without adequate breach-notification language — and it usually does — build the replacement agreements and get them signed before the next quarter closes. A HIPAA incident response plan is only worth what it's worth at 4:52 on a Friday.