Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[ticketing system]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] identifies, responds to, documents, and mitigates suspected or known security incidents affecting its information systems and the electronic protected health information (ePHI) they create, receive, maintain, or transmit. It defines reporting channels and timelines, a consistent incident lifecycle, and the point at which a security incident must be handed off to the breach-assessment process. It satisfies the security incident requirements of the HIPAA Security Rule at 45 CFR § 164.308(a)(6) and the mitigation requirement of the Privacy Rule at 45 CFR § 164.530(f).
This Policy applies to all workforce members (employees, contractors, interns, and volunteers), business associates, and any other party that uses [Organization] systems, and to all system components (applications, endpoints, cloud services, and infrastructure) that handle ePHI. It covers every category of security event, including unauthorized access, use, or disclosure of ePHI; malware and account compromise; lost or stolen devices; data-handling errors; and material control deficiencies. Reporting and mitigation duties apply regardless of a workforce member's role.
[Organization] maintains documented security incident procedures to address (identify, respond to, document, and mitigate) suspected and known security incidents. A standing, cross-functional Incident Response Team (IRT), led by the , is responsible for the response process from declaration through closure. Incident handling is coordinated with contingency planning, and lessons learned are fed back into these procedures, training, and testing. The reviews the program at least annually and after any significant change to the ePHI environment, and the IRT validates readiness through at least an annual tabletop exercise. ()
See where your organization stands on the controls this template cites.
Join Us[Security Official][Security Official]A security incident is the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations. To aid recognition, [Organization] classifies security-related observations as: events (observable occurrences, e.g., a hardware fault causing an outage), precursors (signs an incident may occur, e.g., repeated failed logins), indications (signs an incident may be occurring, e.g., an endpoint protection alert), and incidents (a security policy violation or data compromise, e.g., unauthorized disclosure of ePHI). Reportable incidents include, at minimum: suspected or actual breaches of PHI/PII or other confidential information; data-handling incidents; security incidents; and control deficiencies. (164.308(a)(6)(i))
Every workforce member who identifies a potentially malicious, suspicious, or disruptive event must report it immediately, and no later than [1 hour] after discovery, to the IRT. Reports may be made through the [internal messaging tool] incident channel, by email to [contact email], or to the workforce member's manager, who escalates to the [Security Official] without delay. Reporting in good faith is mandatory and non-punitive; failure to report a known incident is itself a policy violation. The [Security Official] records every report in the [compliance tracking system] on receipt, regardless of whether it is ultimately confirmed as an incident. (164.308(a)(6)(i), 164.308(a)(6)(ii))
[Organization] responds to confirmed incidents through a defined lifecycle, and to the extent practicable mitigates known harmful effects and documents the outcome:
[Organization]'s configuration standards, validate functionality, and confirm monitoring is in place before resuming normal use.Severity is assessed on a [Low / Medium / High] scale; a suspected breach of confidential information such as PHI is treated as High and triggers the escalation in §7. (164.308(a)(6)(ii))
Every reported incident is logged and tracked from initial report through final resolution. The IRT maintains an incident record (ticket) in the [ticketing system] capturing the timeline, severity, affected systems and data, responders, actions taken, evidence collected, mitigation steps, root cause, and final disposition. Communications and evidence are preserved wherever possible. Incident records and all documentation related to any associated breach assessment are retained for at least six (6) years. (164.308(a)(6)(ii))
[Organization] mitigates, to the extent practicable, any harmful effect that is known to it of a use or disclosure of PHI in violation of its policies or the HIPAA Rules, whether caused by [Organization] or one of its business associates. Mitigation is part of every incident response: for example, revoking compromised access, recalling or securing misdirected information, requesting deletion or return of data from an unintended recipient, correcting a faulty process, and taking reasonable steps to reduce the risk of harm to affected individuals. Mitigation steps and their outcomes are recorded in the incident record. Workforce sanctions for violations are governed by the Workforce Security, Training & Sanctions Policy. (164.530(f))
When an incident may involve the unauthorized acquisition, access, use, or disclosure of unsecured PHI, the [Security Official] notifies the [Privacy Officer] and escalates to the breach-assessment process without unreasonable delay and no later than [24 hours] after the incident is confirmed. The determination of whether the incident is a reportable breach (including the four-factor risk assessment) and any resulting notification to individuals, the media, and HHS are governed by the Breach Notification Policy; this Policy does not duplicate those steps. Incident handling, containment, and mitigation under this Policy continue in parallel with the breach assessment. (164.308(a)(6)(ii), 164.530(f))
The IRT determines which internal and external parties must be informed and shares incident information on a need-to-know basis with affected business units; Human Resources (for workforce or personnel matters); Legal or external counsel (for criminal or regulatory matters); and the leadership team. The IRT engages relevant [cloud infrastructure provider] support or specialized third-party responders for additional visibility or expertise when warranted, and coordinates with law enforcement through Legal as necessary. (164.308(a)(6)(ii))
[Security Official]: owns this Policy; leads the IRT; ensures incidents are investigated, documented, mitigated, and closed; tracks all activity from report to lessons learned; reports to leadership on the program.[Privacy Officer]: receives escalations involving PHI and owns the breach-assessment hand-off to the Breach Notification Policy.Security Incident Response Procedures · Breach Notification Policy · Workforce Security, Training & Sanctions Policy · Access Control Policy · Audit Controls & Activity Review Policy · Contingency Plan.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.308(a)(6)(i) | Security Incident Procedures | §1, §2, §3 |
| 164.308(a)(6)(ii) | Response and Reporting | §3, §4, §5, §7, §8 |
| 164.530(f) | Mitigation | §6, §7 |
Reviewed at least annually by the [Security Official] and after any significant change to the ePHI environment or any major incident. v1.0.