An assistant emails a treatment plan to the wrong patient. A laptop goes missing from a car. The billing coordinator looks up her neighbour's chart out of curiosity. A ransomware note appears on the server at 6:40 in the morning and the schedule does not open.
Four very different Tuesdays, and the response to all four begins the same way: somebody decides what just happened, whether it triggers obligations, who needs to be told, and what gets written down. Practices that have thought about this in advance do it calmly in an afternoon. Practices that have not spend a week arguing about whether it counts while the clock, whichever clock applies, runs.
This final lesson covers the incident half of the program and the habits that keep everything else alive: training, documentation, and the compliance file. It is where the whole course comes back together, because a breach analysis draws on your flow map from Lesson 1, your audit logs from Lesson 2, your vendor list from Lesson 3, and your disclosure discipline from Lesson 4.
Breach notification carries specific obligations about who must be notified, in what circumstances, by what method and within what timeframes, and there are separate provisions depending on the scale of the incident. Every state also has its own data breach notification law, many reach health information, many are stricter than the federal framework, and they change. This lesson deliberately describes only the shape of these obligations and states no deadline, threshold or penalty amount. When an incident happens, your first two calls are your healthcare attorney and your cyber insurance carrier, and you follow their direction on timing and content, not a summary you read online. Check your state through our state resource pages. Nothing here is legal advice.
What you will learn
- What makes an impermissible use or disclosure a breach, and the four factor risk assessment concept.
- The shape of the notification obligations and why you do not improvise them.
- How to document an incident so it holds up later.
- Why ransomware is a privacy event and not only an IT event.
- A training cadence that survives contact with a busy schedule, and the compliance file that ties the program together.
What Actually Counts as a Breach
Not every mistake is a breach. The analysis runs in stages.
Stage one: was there an impermissible use or disclosure of PHI, meaning one the Privacy Rule does not permit? If the disclosure was permitted, you are done. If not, continue.
Stage two: does it fall within one of the defined exceptions? The rules set out specific ones, including certain unintentional acquisitions by workforce members acting in good faith, certain inadvertent disclosures between authorised people at the same practice, and situations where the recipient could not reasonably have retained the information. These are narrower than people hope and are defined in the regulation, not by judgment.
Stage three: the presumption. An impermissible use or disclosure is presumed to be a breach unless the practice demonstrates a low probability that the PHI has been compromised. That word "presumed" is the operative one. The default is that it is a breach, and the burden is on you to show otherwise, with documentation.
The demonstration is done through a risk assessment that considers at least four factors:
- The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification. A name and an appointment time is not the same as a name, a date of birth and a clinical history.
- The unauthorised person who used the PHI or received it. Another covered entity bound by the same rules is a different situation from an unknown recipient.
- Whether the PHI was actually acquired or viewed, as opposed to merely exposed. This is where audit logs earn their keep, and where shared logins make the question unanswerable.
- The extent to which the risk has been mitigated, for example confirmed destruction or return with credible assurances.
The assessment is not a vibe check and it is not optional paperwork. It is how you document a conclusion of low probability of compromise, and if you cannot document it, the presumption stands. Notice too the encryption point from Lesson 2 arriving on cue: information rendered unusable, unreadable or indecipherable to unauthorised persons under the recognised standard is treated differently, which is why encrypting the laptop was the bargain.
One page: what happened, when, when and how it was discovered and by whom, what information was involved, how many individuals, who received it, what was done to contain it, what the audit logs show, and the four factor assessment with a conclusion and the name of whoever reached it. Having the form ready is the difference between a documented decision and a memory of a stressful week.
The Notification Obligations, in Shape Only
The framework has several layers. Affected individuals are notified. There is a notification obligation to the Secretary of Health and Human Services. Incidents above a certain scale trigger additional obligations including media notice, with timing and mechanics that differ by scale. Business associates must notify the covered entity. And state breach notification law sits alongside all of it with its own triggers, timelines, content requirements and sometimes its own regulator.
Every one of those elements has a specific rule attached, several have numbers attached, and the numbers are exactly the kind of thing that gets repeated wrongly in continuing education slides and vendor webinars. A practice that notifies on the wrong schedule, or decides an incident falls below a threshold it does not actually fall below, has converted a manageable problem into a serious one.
So the operating rule is simple. Contain it, preserve the evidence including logs, start documenting immediately, and call your healthcare attorney and your cyber insurance carrier before you send anything to anyone. The carrier matters for a practical reason many owners miss: policies often require prompt notice and may direct you to use their panel counsel and forensics, and doing your own thing first can affect coverage. Read that part of your policy before you have a claim. The operational mechanics of the response, who does what in what order, are worked through in HIPAA breach response. Read it as process, and take your timing instructions from counsel.
Ransomware Is a Privacy Event
The reflex in a dental office is to treat ransomware as an IT outage. The schedule is down, the server is encrypted, get it back up. Understandable, and incomplete.
When ransomware encrypts electronic PHI, that information has been affected by an unauthorised party, and guidance has generally treated such an event as involving an impermissible disclosure requiring breach analysis unless a low probability of compromise can be demonstrated through the four factor assessment. It is not outside the framework simply because the attacker encrypted rather than obviously copied the data, and the conclusion has to be documented.
Two consequences follow. First, your response cannot be purely technical. Somebody must preserve evidence and logs while somebody else restores, and those goals conflict if nobody planned for it. Wiping a machine to get back to work destroys what you need to answer factor three. Second, availability is a Security Rule question in its own right: a practice that cannot reach its own records has a contingency planning problem.
So check this month: when was your backup last restored, as a test? Not "is it running." Restored. Practices discover backup failures at exactly the worst moment with depressing regularity. Read ransomware in a dental practice for the mechanics, and make the restore test a standing calendar item with a name on it.
The instinct in an incident is to fix the machine immediately. Before anyone reimages, wipes or restores over anything, isolate the affected systems and get your attorney and insurer on the phone, because their forensic direction usually starts with preservation. Once the evidence is gone you cannot demonstrate what was and was not accessed, and that inability is exactly what the presumption punishes. Write the sequence down and give it to whoever is first through the door in the morning.
Training That Actually Holds
Training is required, it must be documented, and in most dental offices it decays fastest, because it is the one item with no equipment attached and no vendor sending reminders.
The regulation requires training on your policies and procedures as appropriate for each person's functions, including new members within a reasonable period, and retraining when material changes occur. The security side adds an ongoing awareness program, which is a different thing from an annual session.
The cadence that survives real practice life: every new hire trained during onboarding, before they have access, not in week three. Everyone refreshed on a set annual rhythm tied to whatever compliance calendar already runs your year. Targeted training whenever something material changes. And short, frequent awareness touches, five minutes at a huddle, on what actually causes incidents: phishing, verifying callers, not sharing credentials, and what to do when you realise you sent something to the wrong person.
That last one is worth designing deliberately. The most valuable cultural property a practice can have on privacy is that people report their own mistakes immediately and without fear. An assistant who realises at 2pm that she emailed the wrong patient and says so at 2:01 gives you every option. The same assistant who hopes it goes unnoticed gives you a discovery six weeks later from the recipient. Say out loud that reporting fast is expected and that an honest error reported promptly will not be punished. Then behave that way the first time it happens, because the whole team is watching.
Document all of it: date, topic, materials, who delivered it, who attended, and signatures. Undocumented training and no training look identical from the outside. Fold it into onboarding so it happens automatically rather than by memory, and put the annual items on whatever calendar already carries your compliance dates.
The Compliance File
Here is the test that clarifies everything: if someone asked tomorrow to see your privacy and security program, what would you hand them, and how long would it take to assemble? A practice with a working program hands over a folder. A practice without one spends three weeks reconstructing, which is both expensive and, in its own way, an answer to the question. Build it once and keep it current, with one named person owning it.
- The security risk analysis, current, with the dates of prior versions and evidence that it has been revisited as the practice changed.
- The risk management plan: what you found, what you decided to do about each item, who owns it, and what has been completed.
- Written policies and procedures for privacy and security, specific to your practice rather than a generic set with your name typed into the header.
- The named privacy official and security official, in writing, plus your PHI flow map and device inventory from Lessons 1 and 2.
- The vendor list and every business associate agreement, with dates and renewal dates, from Lesson 3.
- The Notice of Privacy Practices, current version, with the acknowledgement process and your authorisation forms.
- Records request procedure and log, plus the disclosure log for accountable disclosures.
- Training records: dates, topics, attendees, materials, signatures, onboarding and annual.
- Incident log and completed incident forms, including those you concluded were not breaches, with the four factor assessment attached. Near misses are evidence of a functioning program.
- Access management records: the user list, role based access levels, periodic reviews, termination records, and dated audit log review notes.
- Contingency and backup documentation, including restore test results with dates, and media disposal certificates for retired equipment.
- Sanction policy for workforce members who violate policies, and any applications of it.
One warning that carries over from every compliance discipline: do not create records you then ignore. A risk analysis that flagged three high risk items two years ago with nothing done about them is a document that testifies against you. Every finding gets an owner, a date and an outcome, even where the outcome is a documented decision to accept the risk for a stated reason.
For the broader picture of how this file sits alongside OSHA, infection control and records retention, the compliance chapter is the wider view. Retention in particular is governed heavily by state law.
Try this in your own office
- Write the incident one pager with the four factor section on it, and the first hour card: contain, preserve, do not reimage, call the attorney, call the carrier, start writing.
- Test a restore. Actually recover something from backup this month and record the date, the result and how long it took.
- Read your cyber policy for notice requirements and panel counsel provisions before you need to claim, and put training into onboarding so it happens before access is granted.
- Assemble the compliance file against the list above and mark each item present, stale or missing. Every gap gets an owner and a date.
- Say the reporting rule out loud: tell us immediately, an honest mistake reported promptly will not be punished. Then honour it.
Where to Go Next
That completes the course. Every deadline, threshold and retention period belongs to the regulation text and to your state's law, which is often stricter and does change. This is education, not legal advice. Three next steps: work through the HIPAA security checklist, pair this with being inspection ready, and book the conversation with a healthcare attorney now, with your flow map and vendor list in hand.
THE CHAIRSIDE TAKE
Do three things this month: write the first hour incident card, test a restore from backup, and build the compliance file so it exists before anybody asks for it. Those three cost almost nothing and they convert a program that lives in your head into one that survives a bad Tuesday and a staff change. When something does happen, call your attorney and your cyber carrier before you send a single notification letter, because the timing rules are specific, your state adds its own, and this course has deliberately told you none of them. Verify everything with a professional who knows your practice and your state.
Lesson 5 of 5 in HIPAA and Patient Privacy for Dental Practices
This guide is educational content and does not constitute legal, financial, tax, or clinical advice. Laws and regulations vary by state and change over time. Consult your own dental-specific attorney, CPA, and state dental board before acting.