Free HIPAA procedures template · v1.0 · Applies to covered entities & business associates · Companion: Policy →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Template. These procedures operationalize the Breach Notification Policy. Replace
[bracketed]items with your specifics and adjust steps to match your tools and team size. The letter templates are starting points. Have counsel review notification content before it is sent.
To provide repeatable, auditable steps for determining whether an impermissible use or disclosure of unsecured protected health information (PHI) is a reportable breach, for notifying affected individuals, the media, the HHS Secretary, and (where [Organization] is a business associate) the covered entity, and for documenting the breach to meet [Organization]'s burden of proof, implementing the Breach Notification Policy.
[ticketing system].[Security Official] records the discovery date: the first day the event was known, or by reasonable diligence would have been known, to any workforce member or agent other than the person who caused it. All notification deadlines run from this date. Compute and record the 60-day deadline on intake.[Security Official], with the [Privacy Officer], names a breach investigator to own the risk assessment and the notification package.Complete the worksheet below for every impermissible use or disclosure of unsecured PHI. First confirm the threshold question; if any exclusion in Policy §1 applies, document it and stop. Otherwise the incident is presumed a breach and notification proceeds unless all four factors together establish a low probability that the PHI was compromised.
Breach Risk Assessment Worksheet
- Incident ID / discovery date:
[id]/[date]- Threshold: is this PHI, and was the use/disclosure impermissible under the Privacy Rule?[Y/N + basis]- Was the PHI _unsecured_ (not encrypted/destroyed to HHS standard)?[Y/N](if secured → no notification; document and close) - Does an exclusion apply (good-faith internal access / inadvertent authorized-to-authorized / unable-to-retain)?[Y/N + basis]- Factor 1 (Nature & extent of PHI): identifiers involved, sensitivity, re-identification likelihood →[low/med/high + notes]- Factor 2 (Unauthorized recipient): who received/used it; are they HIPAA-obligated? →[low/med/high + notes]- Factor 3: Was the PHI actually acquired or viewed (vs. merely exposed)? →[low/med/high + notes]- Factor 4 (Mitigation): recovery, attestations of destruction, other risk reduction →[low/med/high + notes]- Number of individuals affected / states or jurisdictions:[n]/[list]- Determination: ☐ Low probability of compromise: not a reportable breach ☐ Reportable breach - Assessor / date /[Privacy Officer]approval:[name/date]
[Privacy Officer] reviews and records the final determination. A "not a reportable breach" outcome must rest on the documented low-probability finding (this is the burden-of-proof record).[ticketing system] and the [compliance tracking system].Using the affected count and residency from §2, select the obligations (all measured from the discovery date):
| Trigger | Notify | Deadline |
|---|---|---|
| Any reportable breach | Affected individuals (§4) | Without unreasonable delay; ≤ 60 days |
| Reportable breach, any size | HHS Secretary (§6) | < 500: annual log, ≤ 60 days after year-end · ≥ 500: ≤ 60 days |
| > 500 residents of one state/jurisdiction | Prominent media in that area (§5) | Without unreasonable delay; ≤ 60 days |
[Organization] is the business associate | Affected covered entity (§7) | Without unreasonable delay; ≤ 60 days |
Before sending, check §8 (law-enforcement delay) and any state breach-notification laws, which may impose shorter deadlines or additional recipients (e.g., state attorney general); counsel confirms.
[Privacy Officer] and counsel approve.[Organization] website home page or in major print/broadcast media serving the area, with a toll-free number live ≥ 90 days.Template: Individual Notification Letter
[Date][Individual Name]·[Address]Dear
[Individual Name],We are writing to inform you of a recent incident that may have involved some of your protected health information. We discovered this incident on
[discovery date]; it is believed to have occurred on or about[breach date].What happened.
[Brief, plain-language description.]Information involved. The information that may have been involved included
[types of PHI, e.g., name, date of birth, Social Security number, account number, diagnosis].What you can do.
[Steps the individual should take, e.g., monitor statements, place a fraud alert, review the enclosed guidance.]What we are doing.
[Investigation, mitigation, and steps to prevent recurrence.]For more information. Call
[toll-free number], email[contact email], or write to[postal address].[Website.]Sincerely,
[Name],[Privacy Officer],[Organization]
[Privacy Officer] and counsel, within the 60-day deadline.[HHS breach portal URL]) and open the electronic breach-report form.Record every reportable breach (regardless of size) in the breach log at determination, then update it through closure. The log drives the annual HHS submission for sub-500 breaches and is part of the burden-of-proof record.
Breach Log: columns
Incident ID · discovery date · breach date(s) · description · type(s) of PHI · # individuals affected · state(s)/jurisdiction(s) · risk-assessment outcome · individual-notice date & method · media-notice date (if applicable) · HHS-notice date & confirmation ID · BA/CE-notice date (if applicable) · mitigation & resolution · annual-submission year · record location.
Breach risk-assessment worksheets · breach determinations & [Privacy Officer] approvals · individual notification letters and proofs of delivery · media releases & distribution proof · HHS portal submission confirmations · business-associate/covered-entity breach notices · law-enforcement delay documentation · the breach log. These are the artifacts an auditor will request to confirm the controls operate.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.402 | Breach definition & four-factor risk assessment | §1, §2 |
| 164.404 | Notification to individuals | §3, §4 |
| 164.406 | Notification to the media | §3, §5 |
| 164.408 | Notification to the HHS Secretary (incl. annual log) | §3, §6, §7 |
| 164.410 | Notification by a business associate | §3 |
| 164.412 | Law-enforcement delay | §8 |
| 164.414 | Administrative requirements & burden of proof | §2, §7, §9 |
Reviewed at least annually by the [Privacy Officer] and after any breach. v1.0.
See where your organization stands on the controls this template cites.
Join Us