HIPAA breach notification process flowchart

HIPAA breach notification workflow for containment, evidence preservation, qualified privacy assessment, approved notices, documented handoffs and remediation.

Use this template

What the hipaa breach notification process is

A suspected privacy or security incident begins with containment that preserves evidence. Security may revoke access, recover a device or stop a disclosure while retaining logs, messages and recipient details. The workforce reporter opens an incident record with the discovery date and known facts; Security and IT identify the information, systems, people and recipients involved. The Privacy officer decides whether unsecured protected health information is implicated and performs the documented risk assessment. If a low probability of compromise is not demonstrated, the organization identifies who owns individual notice, prepares any additional notices, executes approved communications, remediates the weakness and retains the full decision record.

This is a breach-notification workflow, not the whole HIPAA privacy or security program. It does not define minimum necessary access, conduct enterprise risk analysis, set retention schedules, investigate every cyber incident or replace a business-associate agreement. It also does not assume that a security incident is a reportable breach: the facts, exclusions, status of the information and documented risk assessment matter. Decisions such as "Unsecured PHI involved?" and "Low probability of compromise demonstrated?" belong to a qualified Privacy officer with counsel as needed, not to an automated score. The template is a customizable operational starting point, not legal or medical advice, and adopting it does not guarantee HIPAA, state-law, contractual, regulator or accreditation compliance.

The chart makes the handoff between covered entities and business associates visible. One party may discover and contain the incident while another is responsible for notifying individuals, HHS or the media. The decision "Is this organization responsible for individual notice?" sends a non-notifying organization to a documented handoff instead of duplicating or omitting communications. Five lanes also separate technical facts, privacy determinations, approved messaging and business remediation, so the same person is not silently asked to investigate, interpret the law, approve the message and attest that the fix worked.

What this flowchart covers

In this template

  • Five swimlanes across containment, evidence preservation, qualified assessment, notification planning, execution, remediation and closure
  • Containment that preserves logs and recipient evidence, followed by an incident record that captures the discovery date before the final breach determination is known
  • The decisions "Unsecured PHI involved?" and "Low probability of compromise demonstrated?" owned by the Privacy officer and supported by documented facts
  • A covered-entity and business-associate responsibility check, so the file records who will send individual notices and whether a contractual handoff was confirmed
  • Separate preparation of individual, media, jurisdictional and HHS notices, followed by one approved communication and response route
  • Technical or process remediation, business-owner verification and a retained no-breach or breach rationale before Privacy officer sign-off

When to use this template

  • A healthcare organization or service provider is mapping its response after suspected unauthorized access, use or disclosure of protected health information
  • Security incident tickets are being closed after containment without a documented privacy assessment or notification owner
  • Covered-entity and business-associate teams need an explicit handoff for facts, contract notices and responsibility for individual communication
  • Privacy, legal, communications and operations are maintaining separate task lists and need one view of dependencies and approvals
  • You are configuring a case-management workflow and want decision records, recipient reconciliation and remediation checks defined before automation

How it works

  1. Map the covered-entity and business-associate roles

    For each service and vendor relationship, name who receives the first report, who investigates technical facts, who performs the breach assessment and who is contractually responsible for each notice. Link the current agreement rather than relying on a generic label.

  2. Define evidence-preserving containment

    List approved actions for common scenarios such as a misdirected message, lost device, exposed portal or compromised account. State which logs and records must be preserved before systems are rebuilt or accounts are removed.

  3. Attach the qualified assessment worksheet

    Have the Privacy officer and counsel maintain the current legal factors, exclusions and evidentiary standard in a controlled worksheet. Do not turn the four-factor review into an automatic numeric answer that replaces professional judgment.

  4. Build a jurisdiction and deadline matrix

    Map federal, state, contractual and other applicable notice routes, including responsible approvers and channels. Verify current requirements with qualified counsel and keep dates calculated from the legally relevant discovery event, not an arbitrary ticket status.

  5. Prepare and approve communication materials

    Identify who confirms the affected population, drafts notices, approves public statements, handles returned mail and answers calls. Reconcile all delivery results back to the incident file without exposing more health information than necessary.

  6. Exercise both outcomes

    Run one scenario that ends with a documented no-breach rationale and one that requires individual and regulator notices. Confirm evidence, approvals, handoffs, delivery reconciliation and remediation verification survive review in both paths.

Frequently asked questions

What are the steps in a HIPAA breach notification process?

Contain the suspected incident while preserving evidence, open a record with the discovery date, and identify the PHI, people, systems and recipients involved. A qualified Privacy officer determines whether unsecured PHI is involved and performs the documented breach risk assessment. If a low probability of compromise is not demonstrated, identify the responsible covered entity or business associate, confirm affected individuals and jurisdictions, prepare and approve the applicable individual, HHS, media or other notices, execute communication and reconcile delivery. Remediate the weakness, verify the fix and retain the assessment and approvals before closure.

What does the HIPAA breach risk assessment consider?

The HIPAA Breach Notification Rule at 45 CFR 164.402 describes a risk assessment that considers at least the nature and extent of PHI involved, the unauthorized person who used it or received it, whether it was actually acquired or viewed, and the extent to which risk was mitigated. Exclusions and whether the information was unsecured also matter. Applying those factors requires reliable facts and qualified interpretation; this diagram does not make the determination or replace legal advice.

What are the HIPAA breach notification deadlines?

Under the federal rule, notice to affected individuals is generally required without unreasonable delay and no later than 60 calendar days after discovery of a breach. HHS and media timing depends in part on the number and location of affected individuals, and business associates have separate notice duties to covered entities. State law and contracts can require different or faster action. Verify the current text of 45 CFR 164.404 through 164.410 and all applicable state rules with qualified counsel; a generic chart cannot calculate the correct deadline for a case.

Does every healthcare security incident become a HIPAA breach?

No. An incident may involve no PHI, secured information, an applicable exclusion, or facts that support a documented low probability of compromise. Conversely, a small or accidental disclosure can still require assessment. Security supplies the technical facts, while the Privacy officer applies the legal criteria and records the conclusion. Closing a security ticket is not itself a no-breach determination.

Does this template guarantee HIPAA compliance?

No. It is a customizable operational flowchart, not legal or medical advice, a HIPAA risk analysis, a policy set or proof of compliance. HIPAA applicability, state privacy law, business-associate terms, regulator expectations and accreditation requirements depend on the organization and incident. Qualified privacy and legal professionals should review the adapted process and each material determination, and the organization should test that records and notifications are actually produced as required.

Use this template

More in Healthcare and clinical operations process templates

More in Process flowchart templates

Browse all Healthcare and clinical operations process templates