Skip to content

HIPAA Breach Notification Procedure

Purpose: Step-by-step procedure for identifying, assessing, and notifying affected parties of a HIPAA breach under §164.400–414.

Owner: Rory (designated Security Officer under §164.308(a)(2)) Audience: Rory, Kevin, Greg, Adriana Review frequency: Annual (December) and upon any confirmed breach Last reviewed: May 2026


What Constitutes a Breach

A breach is any unauthorized acquisition, access, use, or disclosure of unsecured ePHI that compromises the security or privacy of that information — unless the 4-factor risk assessment (below) finds a low probability of compromise.

Breaches are not the same as security incidents. A failed phishing attempt that never accessed ePHI is a security incident, not a breach.

Unsecured ePHI means ePHI that has not been rendered unusable, unreadable, or indecipherable through encryption or destruction per NIST guidelines. All Cirius ePHI in Azure and AWS is encrypted at rest — but encryption does not automatically make unauthorized access a non-breach. If an authorized user's credentials were compromised and used to access ePHI, that access is still a potential breach.


Step 1 — Discover and Document

As soon as a potential breach is suspected:

  1. Open a SecOps incident with category=hipaa-breach-investigation and severity=high
  2. Record: date of discovery, date the breach likely occurred (or best estimate), affected systems, types of ePHI involved (name, SSN, DOB, insurance, medical record, etc.), estimated number of individuals
  3. Preserve evidence: do not modify logs, do not isolate systems until forensic copies are secured. Coordinate with Arctic Wolf if forensic preservation is needed
  4. Notify Rory immediately if discovered by Kevin or Greg

Step 2 — The 4-Factor Risk Assessment

Before determining whether notification is required, conduct the 4-factor risk assessment. If the assessment concludes there is a low probability of compromise of ePHI, the incident is not a breach and notification is not required. Document the assessment outcome in the SecOps incident.

Factor 1 — Nature and extent of ePHI involved What types of PHI were involved? Greater sensitivity (mental health, substance abuse, HIV, financial) means higher risk. Was the ePHI de-identified in any way?

Factor 2 — Who accessed or could have accessed the ePHI Was it an authorized workforce member who accessed it accidentally? An external attacker? A business associate? The more unauthorized the actor, the higher the risk.

Factor 3 — Whether the ePHI was actually acquired or viewed For unauthorized access to encrypted data where the attacker likely could not decrypt it: low risk. For an attacker who exfiltrated a file and opened it: high risk.

Factor 4 — Extent to which the risk has been mitigated Has the actor provided assurances the data was destroyed? Has the compromised system been isolated and credentials rotated? Effective mitigation can lower the risk score.

If all four factors point to low probability of compromise, document the analysis and close the breach investigation. The incident becomes a security incident, not a breach.

If any factor indicates material risk: proceed to notification.


Step 3 — Internal Escalation

  1. Rory notifies Kevin and Greg (if workforce members are involved or if operational response is needed)
  2. Rory notifies Adriana for BAA coordination if the breach involved a business associate or if BA notification is required
  3. Rory determines whether external legal counsel is needed. For breaches affecting 500+ individuals, legal review before notifications is strongly recommended

Step 4 — Individual Notification

Deadline: No later than 60 days after the date of discovery.

Each affected individual must receive written notice by first-class mail (or email if the individual has agreed to electronic notice).

Required content:

  • Brief description of what happened (date, nature of breach)
  • Types of ePHI involved (e.g., name, date of birth, account number)
  • Steps the individual should take to protect themselves (credit monitoring, contact fraud alert, etc.)
  • Brief description of what Cirius is doing to investigate, mitigate harm, and prevent future breaches
  • Contact information: a toll-free number, email address, website, or mailing address where individuals can ask questions or get more information

Substitute notice: If contact information is outdated for 10 or more individuals, post a notice on the Cirius Group website for 90 days and provide notice to major print or broadcast media in the affected area.

Urgent notice: If there is immediate risk of irreparable harm, provide notice by telephone in addition to written notice.

Adriana coordinates drafting and sending notifications. Rory reviews and approves content before sending.


Step 5 — HHS Notification

Breaches affecting 500 or more individuals: Notify the HHS Secretary concurrently with individual notification (within 60 days of discovery).

  • Portal: https://ocrportal.hhs.gov/ocr/breach/wizard.jsf
  • Submit: covered entity name, contact information, type of breach, date discovered, date of breach, number of individuals affected, description of PHI involved, description of safeguards in place

Breaches affecting fewer than 500 individuals: Log the breach in the breach log (maintained in SecOps and in a spreadsheet in SharePoint → Legal/Breach Log). Submit all breaches from the calendar year to HHS no later than 60 days after the end of that calendar year (i.e., by March 1 of the following year for breaches discovered in the prior year).


Step 6 — Media Notification

If the breach affects 500 or more residents of a single state or jurisdiction, notify prominent media outlets in that state or jurisdiction. This is in addition to individual and HHS notification. Provide the same information as the individual notice. Deadline: same 60-day window.

Cirius's primary operating jurisdiction is California. For any breach affecting 500+ California residents, issue a press release and notify major California news outlets.


Step 7 — Business Associate Breaches

If a business associate discovers a breach affecting Cirius ePHI:

  • The BA must notify Cirius within 60 days of the BA's discovery
  • Cirius remains responsible for notifying affected individuals, HHS, and media — not the BA
  • Adriana coordinates with the BA to obtain the breach details

If Cirius discovers that a BA experienced a breach involving Cirius ePHI and the BA did not notify Cirius promptly:

  • Treat as a BAA violation
  • Notify Rory immediately
  • Initiate BAA remediation per compliance/baa-management.md
  • Proceed with individual and HHS notification using whatever information Cirius can obtain

Step 8 — Documentation and Retention

Maintain a breach log entry in SecOps with:

FieldValue
Date of discovery
Date of breach (or estimated)
Description
PHI types involved
Number of individuals
Risk assessment outcomeLow probability / Breach
Individual notification sentDate
HHS notification sentDate (or annual log)
Media notification sentDate (if applicable)
Mitigation actions taken

Retain all breach documentation for 6 years from the date of creation or the date it was last in effect, whichever is later. Store in SharePoint → Legal/Breach Log and in the SecOps incident record.


Post-Breach Actions

  1. Forensics: preserve all logs, memory dumps, and disk images relevant to the breach. Do not destroy evidence until any regulatory investigation period has passed
  2. Remediation: patch the vulnerability, rotate all credentials involved, review Conditional Access policies, update known-good rules as appropriate
  3. Lessons learned: within 30 days of breach closure, document what failed and what controls to add. Open SecOps findings for each gap
  4. HIPAA risk assessment update: material breaches trigger a refresh of compliance/hipaa-risk-assessment.md
  5. SOC2 disclosure: if Cirius is under a SOC2 audit, notify the auditor — material breaches during the audit period must be disclosed

Key Contacts

ContactRoleHow to Reach
RorySecurity Officer, decision-makerTelegram / phone
AdrianaBAA/vendor coordination, SharePointEmail
Kevin, GregT1 Domain Admins, operational escalationEmail
Arctic WolfMDR — forensics and containmentArctic Wolf portal / hotline
HHS OCRBreach reportingocrportal.hhs.gov

  • compliance/hipaa-administrative-procedures.md — overall security management procedure
  • compliance/hipaa-risk-assessment.md — risk assessment framework
  • compliance/baa-management.md — BA identification and BAA tracking
  • runbooks/incident-response.md — general IR procedure
  • compliance/vendor-phi-inventory.md — PHI vendor inventory

Internal use only — Cirius Group