Appearance
HIPAA Breach Notification Procedure
Purpose: Step-by-step procedure for identifying, assessing, and notifying affected parties of a HIPAA breach under §164.400–414.
Owner: Rory (designated Security Officer under §164.308(a)(2)) Audience: Rory, Kevin, Greg, Adriana Review frequency: Annual (December) and upon any confirmed breach Last reviewed: May 2026
What Constitutes a Breach
A breach is any unauthorized acquisition, access, use, or disclosure of unsecured ePHI that compromises the security or privacy of that information — unless the 4-factor risk assessment (below) finds a low probability of compromise.
Breaches are not the same as security incidents. A failed phishing attempt that never accessed ePHI is a security incident, not a breach.
Unsecured ePHI means ePHI that has not been rendered unusable, unreadable, or indecipherable through encryption or destruction per NIST guidelines. All Cirius ePHI in Azure and AWS is encrypted at rest — but encryption does not automatically make unauthorized access a non-breach. If an authorized user's credentials were compromised and used to access ePHI, that access is still a potential breach.
Step 1 — Discover and Document
As soon as a potential breach is suspected:
- Open a SecOps incident with
category=hipaa-breach-investigationandseverity=high - Record: date of discovery, date the breach likely occurred (or best estimate), affected systems, types of ePHI involved (name, SSN, DOB, insurance, medical record, etc.), estimated number of individuals
- Preserve evidence: do not modify logs, do not isolate systems until forensic copies are secured. Coordinate with Arctic Wolf if forensic preservation is needed
- Notify Rory immediately if discovered by Kevin or Greg
Step 2 — The 4-Factor Risk Assessment
Before determining whether notification is required, conduct the 4-factor risk assessment. If the assessment concludes there is a low probability of compromise of ePHI, the incident is not a breach and notification is not required. Document the assessment outcome in the SecOps incident.
Factor 1 — Nature and extent of ePHI involved What types of PHI were involved? Greater sensitivity (mental health, substance abuse, HIV, financial) means higher risk. Was the ePHI de-identified in any way?
Factor 2 — Who accessed or could have accessed the ePHI Was it an authorized workforce member who accessed it accidentally? An external attacker? A business associate? The more unauthorized the actor, the higher the risk.
Factor 3 — Whether the ePHI was actually acquired or viewed For unauthorized access to encrypted data where the attacker likely could not decrypt it: low risk. For an attacker who exfiltrated a file and opened it: high risk.
Factor 4 — Extent to which the risk has been mitigated Has the actor provided assurances the data was destroyed? Has the compromised system been isolated and credentials rotated? Effective mitigation can lower the risk score.
If all four factors point to low probability of compromise, document the analysis and close the breach investigation. The incident becomes a security incident, not a breach.
If any factor indicates material risk: proceed to notification.
Step 3 — Internal Escalation
- Rory notifies Kevin and Greg (if workforce members are involved or if operational response is needed)
- Rory notifies Adriana for BAA coordination if the breach involved a business associate or if BA notification is required
- Rory determines whether external legal counsel is needed. For breaches affecting 500+ individuals, legal review before notifications is strongly recommended
Step 4 — Individual Notification
Deadline: No later than 60 days after the date of discovery.
Each affected individual must receive written notice by first-class mail (or email if the individual has agreed to electronic notice).
Required content:
- Brief description of what happened (date, nature of breach)
- Types of ePHI involved (e.g., name, date of birth, account number)
- Steps the individual should take to protect themselves (credit monitoring, contact fraud alert, etc.)
- Brief description of what Cirius is doing to investigate, mitigate harm, and prevent future breaches
- Contact information: a toll-free number, email address, website, or mailing address where individuals can ask questions or get more information
Substitute notice: If contact information is outdated for 10 or more individuals, post a notice on the Cirius Group website for 90 days and provide notice to major print or broadcast media in the affected area.
Urgent notice: If there is immediate risk of irreparable harm, provide notice by telephone in addition to written notice.
Adriana coordinates drafting and sending notifications. Rory reviews and approves content before sending.
Step 5 — HHS Notification
Breaches affecting 500 or more individuals: Notify the HHS Secretary concurrently with individual notification (within 60 days of discovery).
- Portal:
https://ocrportal.hhs.gov/ocr/breach/wizard.jsf - Submit: covered entity name, contact information, type of breach, date discovered, date of breach, number of individuals affected, description of PHI involved, description of safeguards in place
Breaches affecting fewer than 500 individuals: Log the breach in the breach log (maintained in SecOps and in a spreadsheet in SharePoint → Legal/Breach Log). Submit all breaches from the calendar year to HHS no later than 60 days after the end of that calendar year (i.e., by March 1 of the following year for breaches discovered in the prior year).
Step 6 — Media Notification
If the breach affects 500 or more residents of a single state or jurisdiction, notify prominent media outlets in that state or jurisdiction. This is in addition to individual and HHS notification. Provide the same information as the individual notice. Deadline: same 60-day window.
Cirius's primary operating jurisdiction is California. For any breach affecting 500+ California residents, issue a press release and notify major California news outlets.
Step 7 — Business Associate Breaches
If a business associate discovers a breach affecting Cirius ePHI:
- The BA must notify Cirius within 60 days of the BA's discovery
- Cirius remains responsible for notifying affected individuals, HHS, and media — not the BA
- Adriana coordinates with the BA to obtain the breach details
If Cirius discovers that a BA experienced a breach involving Cirius ePHI and the BA did not notify Cirius promptly:
- Treat as a BAA violation
- Notify Rory immediately
- Initiate BAA remediation per
compliance/baa-management.md - Proceed with individual and HHS notification using whatever information Cirius can obtain
Step 8 — Documentation and Retention
Maintain a breach log entry in SecOps with:
| Field | Value |
|---|---|
| Date of discovery | |
| Date of breach (or estimated) | |
| Description | |
| PHI types involved | |
| Number of individuals | |
| Risk assessment outcome | Low probability / Breach |
| Individual notification sent | Date |
| HHS notification sent | Date (or annual log) |
| Media notification sent | Date (if applicable) |
| Mitigation actions taken |
Retain all breach documentation for 6 years from the date of creation or the date it was last in effect, whichever is later. Store in SharePoint → Legal/Breach Log and in the SecOps incident record.
Post-Breach Actions
- Forensics: preserve all logs, memory dumps, and disk images relevant to the breach. Do not destroy evidence until any regulatory investigation period has passed
- Remediation: patch the vulnerability, rotate all credentials involved, review Conditional Access policies, update known-good rules as appropriate
- Lessons learned: within 30 days of breach closure, document what failed and what controls to add. Open SecOps findings for each gap
- HIPAA risk assessment update: material breaches trigger a refresh of
compliance/hipaa-risk-assessment.md - SOC2 disclosure: if Cirius is under a SOC2 audit, notify the auditor — material breaches during the audit period must be disclosed
Key Contacts
| Contact | Role | How to Reach |
|---|---|---|
| Rory | Security Officer, decision-maker | Telegram / phone |
| Adriana | BAA/vendor coordination, SharePoint | |
| Kevin, Greg | T1 Domain Admins, operational escalation | |
| Arctic Wolf | MDR — forensics and containment | Arctic Wolf portal / hotline |
| HHS OCR | Breach reporting | ocrportal.hhs.gov |
Related Documents
compliance/hipaa-administrative-procedures.md— overall security management procedurecompliance/hipaa-risk-assessment.md— risk assessment frameworkcompliance/baa-management.md— BA identification and BAA trackingrunbooks/incident-response.md— general IR procedurecompliance/vendor-phi-inventory.md— PHI vendor inventory