Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[ticketing system]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] determines whether an impermissible use or disclosure of unsecured protected health information (PHI) is a reportable breach, and how it notifies affected individuals, the media, the Secretary of the U.S. Department of Health and Human Services (HHS), and, where [Organization] acts as a business associate, the covered entity. It also establishes the documentation [Organization] keeps to meet its burden of proof. It satisfies the Breach Notification requirements of the HITECH Act as codified in the HIPAA Breach Notification Rule at 45 CFR §§ 164.402, 164.404, 164.406, 164.408, 164.410, 164.412, and 164.414.
This Policy applies to all workforce members (employees, contractors, interns, and volunteers), business associates, and any other party that creates, receives, maintains, or transmits PHI on behalf of [Organization], and to every impermissible acquisition, access, use, or disclosure of unsecured PHI regardless of the medium (electronic, paper, or oral) or the number of individuals affected. It governs the determination of whether a breach has occurred and all resulting notifications; the upstream detection, containment, and investigation of the underlying security incident are governed by the Security Incident Response Policy.
A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. A use or disclosure that is incident to an otherwise permissible use or disclosure, occurs despite reasonable safeguards, and respects the minimum-necessary standard is not a violation and is not a breach. The definition also excludes:
[Organization] (or within an organized health-care arrangement in which it participates), where the PHI is not further used or disclosed impermissibly; and[Organization] has a good-faith belief that the unauthorized recipient would not reasonably have been able to retain the PHI.This Policy applies only to unsecured PHI: PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through encryption or destruction meeting HHS guidance. PHI secured to that standard is outside the notification obligation.
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless [Organization] demonstrates, through a documented risk assessment, that there is a low probability the PHI has been compromised. The risk assessment is fact-specific and evaluates at least the following four factors:
If the assessment does not establish a low probability of compromise, or [Organization] elects not to perform one, the incident is treated as a reportable breach and notification proceeds. The burden of demonstrating a low probability rests with [Organization] (§9).
A breach is treated as discovered on the first day it is known to [Organization], or by exercising reasonable diligence would have been known. [Organization] is deemed to have knowledge if the breach is known, or would be known through reasonable diligence, to any workforce member or agent, other than the person who committed the breach. All notification timelines run from the date of discovery.
[Organization] notifies each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed in a breach. Notice is provided without unreasonable delay and in no case later than 60 calendar days after discovery. Notice is written in plain language and includes, to the extent known:
[Organization] is doing to investigate, mitigate harm, and protect against further breaches; andIndividual notice is delivered by first-class mail to the last known address (or by email if the individual has agreed to electronic notice). If [Organization] knows the individual is deceased, notice goes to the next of kin or personal representative where that address is known. Where contact information is insufficient or out of date for fewer than 10 individuals, a substitute notice (e.g., telephone or another reasonable means) is used; for 10 or more, substitute notice is given either by a conspicuous posting for 90 days on the home page of [Organization]'s website or in major print or broadcast media serving the affected area, together with a toll-free number active for at least 90 days. If there is a possibility of imminent misuse, [Organization] may also provide urgent notice by telephone or other means.
For a breach of unsecured PHI involving more than 500 residents of a single state or jurisdiction, [Organization] notifies prominent media outlets serving that state or jurisdiction, without unreasonable delay and in no case later than 60 calendar days after discovery. The media notice contains the same content elements as the individual notice (§4). Media notification supplements, and does not replace, individual notice.
[Organization] notifies the HHS Secretary of breaches of unsecured PHI using the form on the HHS website:
Where [Organization] acts as a business associate, it notifies the affected covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. The notice identifies each individual whose PHI has been or is reasonably believed to have been breached, and provides the other information the covered entity needs to make its own notifications, to the extent known at the time and as it becomes available. Where [Organization] is a covered entity, it requires its business associates by written agreement to report breaches to it on the same timeline so that [Organization] can meet its obligations under §§4–6. Time-of-discovery by a business associate that is an agent of the covered entity is imputed to the covered entity.
[Organization] maintains a log or other documentation of all breaches of unsecured PHI, capturing at least the description of the event, the dates of breach and discovery, the number of individuals affected, the types of PHI involved, the notifications made, and the mitigation and resolution steps. The log is the basis for the annual submission to the Secretary under §6 and is retained per §10.
If a law-enforcement official states that a notification, notice, or posting would impede a criminal investigation or cause damage to national security, [Organization]:
[Organization] maintains the administrative safeguards required by 45 CFR § 164.530(b), (d), (e), (g), (h), (i), and (j) with respect to breach notification, including workforce training on identifying and reporting breaches, a process for individuals to file complaints, sanctions for noncompliance, and a prohibition on retaliation or requiring individuals to waive their rights. In any incident involving an impermissible use or disclosure, [Organization] carries the burden of proof to demonstrate either that all required notifications were made or that the use or disclosure did not constitute a reportable breach (i.e., that the risk assessment established a low probability of compromise). All breach determinations, risk assessments, notifications, and supporting documentation are retained for 6 years.
[Privacy Officer]: owns this Policy; makes the final breach determination; approves the content and timing of notifications to individuals, media, and HHS.[Security Official]: coordinates the underlying incident investigation, names a breach investigator, and supplies the technical facts feeding the risk assessment.Breach Notification Procedures · Security Incident Response Policy · Audit Controls & Activity Review Policy · Workforce Security, Training & Sanctions Policy · Business Associate Management Policy.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.402 | Breach definition & four-factor risk assessment | §1, §2, §3 |
| 164.404 | Notification to individuals | §4 |
| 164.406 | Notification to the media | §5 |
| 164.408 | Notification to the HHS Secretary (incl. annual log) | §6, §8 |
| 164.410 | Notification by a business associate | §7 |
| 164.412 | Law-enforcement delay | §9 |
| 164.414 | Administrative requirements & burden of proof | §2, §10 |
Reviewed at least annually by the [Privacy Officer] and after any breach or significant change to the PHI environment or applicable law. v1.0.
See where your organization stands on the controls this template cites.
Join Us