Definition
HIPAA incident response is the coordinated process for identifying, responding to, mitigating, and documenting security incidents and potential impermissible uses or disclosures.
In practice
- A misdirected email is routed to privacy and security together because the event may involve both disclosure and access questions.
- A ransomware playbook includes downtime operations, restoration validation, and notification analysis.
Who this applies to
- Covered entities and business associates
- Security, privacy, legal, communications, and executive stakeholders
- Vendors reporting incidents under business associate agreements
What the rule asks for
- Identify and respond to suspected security incidents.
- Mitigate harmful effects and document the incident and response.
- Coordinate a breach risk assessment where an impermissible use or disclosure may have occurred.
How teams put it into practice
- Define intake, severity, decision ownership, evidence preservation, and escalation.
- Use tabletop exercises for ransomware, lost devices, misdirected email, and vendor incidents.
- Link incident tickets to notification decisions and remediation evidence.
Common mistakes
- Waiting for certainty before opening an investigation.
- Letting a vendor control the covered entity's breach decision.
- Overwriting logs or reimaging systems before preserving evidence.
Questions that come up
Is a security incident always a breach?
No. A security incident may or may not involve an impermissible use or disclosure of PHI that meets the breach definition. Analyze and document the specific facts.
References
- Security incident procedures HHS Office for Civil Rights
- Breach Notification Rule HHS Office for Civil Rights