A laptop with imaging software on it is gone from the front seat of a car. A staff member emailed a treatment plan to the wrong address. A ransomware note is on the server. In each case the practice has the same problem: you do not yet know whether this is a reportable breach, and a 60-day clock may already be running.
Breach response is not one decision. It is a containment phase, an investigation phase, a documented legal analysis, and then a notification phase, and the first 72 hours cover the first three. This article assumes you have the basics in place from Chapter 6: Compliance: a privacy official, a security risk analysis, and signed business associate agreements. Here we deal with the incident itself.
Key takeaways
- Under the Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you document a low probability of compromise using four specific factors.
- The 60-day individual notification clock starts at discovery, which is the first day the incident is known, or would have been known with reasonable diligence, by anyone in the workforce other than the person who caused it.
- Breaches affecting 500 or more individuals require notice to HHS and to prominent media within 60 days. Smaller breaches go into a log and are submitted through the HHS portal within 60 days after the end of the calendar year.
- PHI encrypted to HHS specifications is not "unsecured," and its loss generally does not trigger notification. That is the single best argument for encrypting every laptop, phone, and backup drive.
- Every state has its own breach notification law, and many have shorter deadlines and different definitions than HIPAA. State law applies on top of HIPAA, not instead of it.
- The burden of proof is on you. If you conclude there was no breach, the written risk assessment that got you there is the only thing standing between you and an enforcement finding.
Hour 0 to 2: contain, and stop the second breach
Containment comes before analysis. The goal is to keep the exposure from growing while preserving what you will need to investigate.
- Isolate, do not wipe. If a computer is involved, disconnect it from the network and from Wi-Fi. Do not reimage it, do not run cleanup tools, and do not restore over it. You will need the evidence to answer whether data was actually acquired or viewed.
- Disable credentials. Reset the password and disable the account of any user involved, including the practice management software login, email, remote access, and any cloud imaging portal.
- Recall what can be recalled. For a misdirected email or fax, contact the recipient immediately, in writing, and ask for confirmation of deletion or destruction. That confirmation feeds directly into the fourth risk factor.
- Freeze the deletion. Tell staff not to delete emails, logs, or voicemails related to the incident, and confirm your practice software's audit log retention period before it rolls over.
- Write down the time. Who discovered it, when, and how. This timestamp is the anchor for every deadline that follows, and it is the first thing OCR asks about.
Do not announce anything yet. The urge to email patients on day one is understandable and almost always wrong. You do not yet know the scope, the list of affected individuals, or whether this is even a reportable breach. An inaccurate first notice has to be corrected, and the correction is what patients remember.
Hour 2 to 8: assemble the response and start the log
Call, in this order:
- Your privacy or security official. This is a named person in your policies. If that name is a former office manager, fix that this week.
- Counsel. Use a healthcare attorney, not a general business attorney. Engaging counsel early can also help protect parts of the investigation, and state law analysis is genuinely specialized work.
- Your cyber insurance carrier's hotline, if you carry a policy. Most policies require prompt notice and many require you to use panel vendors for forensics and breach counsel. Calling your own IT company first and the carrier second can jeopardize coverage of those costs.
- Your IT provider or an incident response firm, for anything involving systems. For a physical loss such as a stolen laptop, file a police report and keep the report number.
- Your business associate, if their system is involved. Under the rule they must notify you of a breach without unreasonable delay and no later than 60 days after their discovery, and your BAA may set a shorter window.
Open a single incident file, dated, that will hold everything: the timeline, the systems and record counts, emails, the forensic report, the risk assessment, and copies of every notice. HIPAA requires you to retain this documentation for six years, and it is the file an investigator will ask for.
Hour 8 to 48: establish the facts
The analysis only works if you know three things: what data, whose data, and what happened to it.
| Question | Where the answer comes from |
|---|---|
| What information was involved? | The application itself: which modules were on the device, what a report or export contained, what fields an emailed document included |
| How many individuals? | Practice management audit log, database query, mail merge list, the actual export file |
| Was it accessed or exfiltrated? | Server and firewall logs, application audit trails, cloud provider sign-in logs, forensic imaging of the device |
| Was it encrypted at the time? | Device management console, BitLocker or FileVault status, backup software configuration |
| Who received it? | Email headers, fax confirmation, recipient response, chain of custody for physical records |
| What has been done to mitigate? | Written confirmation of deletion, remote wipe records, credential resets, recovered device |
"We think it was about 40 patients" is not an answer. Build the actual list of affected individuals with names and current mailing addresses, because the notification requirements run on that list.
Discovery is a legal term. A breach is treated as discovered on the first day it is known to the covered entity, or would have been known by exercising reasonable diligence, and knowledge of any workforce member other than the person who committed the breach is imputed to the practice. In other words: the assistant who noticed the missing laptop on Friday started the clock on Friday, even if the owner did not hear about it until Monday. Train the team to report same day, in writing, to one named person.
Hour 48 to 72: run the four-factor risk assessment
An impermissible use or disclosure of unsecured PHI is presumed to be a breach. To rebut that presumption you must document a risk assessment showing a low probability that the PHI has been compromised, based on at least four factors from the Breach Notification Rule:
- The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification. A list of names and appointment times is not the same as names with Social Security numbers, insurance IDs, and clinical notes.
- The unauthorized person who used the PHI or to whom it was disclosed. A fax to another HIPAA-covered dental office that is itself obligated to protect the information is different from a record left in a public parking lot.
- Whether the PHI was actually acquired or viewed. Forensics matter here. A laptop recovered with no sign of the drive being mounted is very different from a database that was exported and uploaded.
- The extent to which the risk has been mitigated, for example a signed attestation of destruction from the recipient, a successful remote wipe, or a recovered device with encryption confirmed active.
The assessment must be thorough, done in good faith, and reach conclusions that are reasonable given the circumstances. Address every factor in writing, even the ones that cut against you, and state the conclusion and the reasoning. A one-line memo saying "low risk, no notification required" is worse than useless.
The three exceptions
Three situations are excluded from the definition of breach entirely, and worth checking before running the full assessment:
- Unintentional acquisition, access, or use by a workforce member acting in good faith within the scope of authority, with no further impermissible use or disclosure (an assistant opens the wrong chart, realizes it, and closes it).
- Inadvertent disclosure between two people who are both authorized to access PHI at the same covered entity, again with no further impermissible disclosure.
- A good faith belief that the unauthorized recipient would not reasonably have been able to retain the information.
The encryption safe harbor
The rule applies to unsecured PHI. Information rendered unusable, unreadable, or indecipherable through encryption meeting HHS specifications is not unsecured, and its loss generally does not trigger notification. A stolen encrypted laptop, with the key not on the device and documented proof the encryption was active at the time, is often a police report and an internal memo rather than a mailing to 3,000 patients. That single fact should drive your whole device policy, and it is covered further in our dental cybersecurity threat list.
The clocks, once you conclude it is a breach
| Notice | Who | Deadline | How |
|---|---|---|---|
| Individual notice | Every affected individual | Without unreasonable delay, no later than 60 calendar days after discovery | First-class mail to the last known address; email only with prior agreement |
| Substitute notice | Individuals with insufficient or out-of-date contact information | Same 60-day window | For fewer than 10, an alternative written notice, phone, or other means. For 10 or more, a conspicuous website posting for 90 days with a toll-free number, or notice in major print or broadcast media |
| Media notice | Prominent media outlets serving the state or jurisdiction | Within 60 days of discovery | Required when the breach affects more than 500 residents of that state or jurisdiction |
| HHS notice, 500 or more individuals | Secretary of HHS | Within 60 days of discovery | HHS breach portal; posted publicly on the OCR site |
| HHS notice, fewer than 500 individuals | Secretary of HHS | Within 60 days after the end of the calendar year in which the breach was discovered | Same portal, one separate submission per incident |
| Business associate to covered entity | You, the practice | No later than 60 days after the BA's discovery, or sooner if your BAA says so | Per the BAA |
Sixty days is an outer limit, not a target. The standard is "without unreasonable delay," and OCR has taken the position that sitting on a fully investigated breach for 59 days is itself a violation.
What the individual notice has to say
Write it in plain language and include: a brief description of what happened and the dates of the breach and of discovery; the types of information involved (for example, name, address, date of birth, insurance information, clinical information); steps individuals should take to protect themselves; a brief description of what you are doing to investigate, mitigate harm, and prevent recurrence; and contact procedures including a toll-free number, an email address, a website, or a postal address.
Have counsel draft the letter. The content requirements are specific, and the same letter usually has to satisfy your state's breach law too. Attach whatever credit monitoring or identity protection offer you and your carrier decide on, but do not promise services you have not actually contracted for.
State breach laws apply on top of HIPAA
Every state has a data breach notification law. They are not HIPAA, they are not uniform, and HIPAA does not preempt state laws that are more stringent. Recurring differences that catch practices out:
- Shorter deadlines. Several states require notice within 30 or 45 days of determination, which can land well inside the federal 60-day window.
- Different triggers. Many state laws key off "personal information" such as name plus Social Security number, driver's license number, or financial account number, and some now include medical or health insurance information. A breach can be reportable under state law and not under HIPAA, or the reverse.
- Attorney general and agency notice. Many states require notice to the state attorney general, sometimes at a threshold as low as 250 or 500 residents, and some require notice to consumer reporting agencies.
- Required content and delivery methods that differ from HIPAA's.
- Multi-state exposure. Patients who moved out of state still count as residents of where they live now. A practice near a state line can trigger three state laws with one incident.
- Your state dental board. Some boards have their own reporting or recordkeeping expectations when patient records are lost or destroyed. Check your state resources page and confirm directly with the board.
This is exactly the area where a healthcare attorney earns the fee. Do not try to map 50 state statutes yourself in a weekend.
Ransomware is its own case
HHS guidance treats a ransomware attack that encrypts ePHI as an impermissible disclosure, because the data has been acquired by an unauthorized party. That means a breach is presumed, and you must notify unless your four-factor risk assessment documents a low probability of compromise. Restoring cleanly from backup does not by itself eliminate the obligation. Note also that if ransomware accessed files that were decrypted for normal use, the fact that the drive has full-disk encryption at rest does not save you.
The forensic question that decides these cases is whether data was exfiltrated before encryption, which is why preserving logs in hour one matters so much. Prevention, backups, and the recovery sequence are covered in detail in ransomware in dental practices.
What happens after you notify
Submitting a report for 500 or more individuals puts your practice name on a public HHS list and usually triggers an OCR investigation. Expect a data request covering your security risk analysis and risk management plan, policies and procedures, workforce training records, business associate agreements, audit log configuration, and evidence of the corrective actions you described in the notice. OCR's enforcement announcements repeatedly cite the absence of an accurate and thorough risk analysis, so the quality of that document, dated before the incident, matters enormously.
Plan for the practical fallout too: a phone line that can absorb patient calls for two weeks, a short script for the front desk, one designated spokesperson, and a decision in advance about what you will and will not say publicly. Responding to a patient's online review of the incident with any detail about their treatment is its own HIPAA violation.
First 72 hours checklist
- Record the discovery date, time, and who found it
- Isolate affected devices without wiping or reimaging
- Disable or reset involved credentials across all systems
- Request written confirmation of deletion from any unintended recipient
- Suspend log and email deletion; confirm audit log retention window
- Notify counsel and the cyber insurance hotline before hiring vendors
- Confirm whether the data was encrypted at the time and document the proof
- Build the actual list of affected individuals with current addresses
- Document all four risk assessment factors and the conclusion in writing
- Check state breach law deadlines, which may be shorter than 60 days
- Calendar the 60-day individual, media, and HHS deadlines
- Open a six-year retention file holding the entire record
Build the plan before you need it
Every hour in this article is easier if three things already exist: full-disk encryption on every device that touches PHI, a named privacy official whose phone number is on the wall, and a one-page incident response sheet that tells whoever is on duty at 6 p.m. on a Friday exactly who to call and what not to touch. Add a tabletop exercise to the annual calendar and walk the team through a stolen-laptop scenario once a year.
Next steps: work through the HIPAA security checklist, tighten the technical controls in the realistic dental cybersecurity threat list, and make sure your backups are actually restorable using the backup and recovery guide. If you use Open Dental, the backup and audit trail settings are covered in Module 8.
This article is educational and is not legal advice. Federal requirements are summarized from HHS sources as of September 2026. State breach notification laws vary widely and change often. Confirm your obligations with a healthcare attorney licensed in your state before making a notification decision.
Educational content only. It is not legal, financial, tax, or clinical advice. Prices and ranges are approximate and vary by region, condition, and year. Verify current rules with your state dental board and qualified professionals. ChairsideSource is not affiliated with any manufacturer, the ADA, or the DAT.