Back to resources

HIPAA requires you to have a written incident response plan. Cyber insurers require it. Auditors ask for it. And yet, most small practices either don't have one or have one that's too long and complex to be useful when something actually goes wrong.

A breach response plan doesn't need to be a binder. It needs to be something your team can follow when they're panicking, the EHR is locked, and it's 9pm on a Friday.

What a response plan needs to do

Your response plan serves three purposes: it tells your team what to do immediately, it keeps you on the right side of HIPAA notification requirements, and it provides documentation that you acted in good faith. It doesn't need to anticipate every scenario. It needs to cover the most common ones well.

The four sections every plan needs

Section 1: Who's in charge

Name one person (and a backup) who is responsible for leading the response. This person makes decisions, coordinates communication, and keeps the log. In a small practice, this is usually the owner or practice manager. Without a named decision-maker, responses stall on coordination while the situation gets worse.

Include phone numbers. Not just work phone numbers. Personal cell numbers. At 9pm on a Friday, you need to be able to reach people.

Section 2: The first four hours

Write a checklist for the immediate response. Here's a starting template:

Report early, update later. Your cyber insurer wants to hear from you as soon as you know something happened, not after you've determined the full scope. Waiting until you have the complete picture often means waiting past the reporting window. Open the claim first, add details as they develop.

Section 3: The notification timeline

HIPAA has specific notification requirements you must follow. Write these down explicitly so no one has to look them up during a crisis:

Section 4: The log

Document everything as you go: what happened, when you learned about it, what decisions you made, who you contacted, and when. This log is evidence of good faith if OCR investigates. It's also how you'll reconstruct the timeline six months later when you're writing the required documentation.

A simple shared document or even a dated email chain works. The format matters less than the habit of creating it.

What not to do: Don't post about the incident on social media. Don't email patients from a potentially compromised account. Don't delete files or logs in an attempt to clean up. And don't assume a small incident isn't worth reporting because it seems minor. The reporting threshold for HHS is lower than most practices realize.

Keep it short and findable

The best breach response plan fits on one or two pages. It lives somewhere everyone knows about and can access, including from a phone, in case the office computers are part of the problem. Print a copy and keep it somewhere physical. Post it in the office. Make sure your backup decision-maker has it too.

Write it once, review it annually, and update it when your team, your technology, or your insurance changes.


A response plan you can follow under pressure is worth more than a perfect plan that's buried in a binder. Get the basics documented today. You can refine it over time.

Want to know if your practice is breach-ready?

The free Cyber Health Score takes 5 minutes and includes questions on incident response readiness.

Get your free Cyber Health Score