HIPAA requires you to have a written incident response plan. Cyber insurers require it. Auditors ask for it. And yet, most small practices either don't have one or have one that's too long and complex to be useful when something actually goes wrong.
A breach response plan doesn't need to be a binder. It needs to be something your team can follow when they're panicking, the EHR is locked, and it's 9pm on a Friday.
What a response plan needs to do
Your response plan serves three purposes: it tells your team what to do immediately, it keeps you on the right side of HIPAA notification requirements, and it provides documentation that you acted in good faith. It doesn't need to anticipate every scenario. It needs to cover the most common ones well.
The four sections every plan needs
Section 1: Who's in charge
Name one person (and a backup) who is responsible for leading the response. This person makes decisions, coordinates communication, and keeps the log. In a small practice, this is usually the owner or practice manager. Without a named decision-maker, responses stall on coordination while the situation gets worse.
Include phone numbers. Not just work phone numbers. Personal cell numbers. At 9pm on a Friday, you need to be able to reach people.
Section 2: The first four hours
Write a checklist for the immediate response. Here's a starting template:
- Isolate the affected device or account (disconnect from the network, don't turn off)
- Document what you know: what happened, when you found out, what systems are affected
- Call your cyber insurance carrier and open a claim (do this early, not after you've figured everything out)
- Contact your IT provider or your forensic vendor if you have one
- Do not pay any ransom without consulting your insurer and legal counsel
- Preserve logs, screenshots, and any emails related to the incident
Report early, update later. Your cyber insurer wants to hear from you as soon as you know something happened, not after you've determined the full scope. Waiting until you have the complete picture often means waiting past the reporting window. Open the claim first, add details as they develop.
Section 3: The notification timeline
HIPAA has specific notification requirements you must follow. Write these down explicitly so no one has to look them up during a crisis:
- Within 60 days of discovery: Notify affected individuals in writing. Include what happened, what PHI was involved, what you're doing about it, and how they can protect themselves.
- Within 60 days of discovery: Report to HHS OCR. File the breach report at hhs.gov/ocr/breach-reporting. For breaches under 500 individuals, you can file annually. For 500 or more, you must file immediately.
- Without unreasonable delay: If the breach affects 500 or more individuals in a single state, notify prominent media outlets in that state.
- Your cyber insurer: Check your policy's reporting window. Most require notification within 24 to 72 hours of discovering an incident.
Section 4: The log
Document everything as you go: what happened, when you learned about it, what decisions you made, who you contacted, and when. This log is evidence of good faith if OCR investigates. It's also how you'll reconstruct the timeline six months later when you're writing the required documentation.
A simple shared document or even a dated email chain works. The format matters less than the habit of creating it.
What not to do: Don't post about the incident on social media. Don't email patients from a potentially compromised account. Don't delete files or logs in an attempt to clean up. And don't assume a small incident isn't worth reporting because it seems minor. The reporting threshold for HHS is lower than most practices realize.
Keep it short and findable
The best breach response plan fits on one or two pages. It lives somewhere everyone knows about and can access, including from a phone, in case the office computers are part of the problem. Print a copy and keep it somewhere physical. Post it in the office. Make sure your backup decision-maker has it too.
Write it once, review it annually, and update it when your team, your technology, or your insurance changes.
A response plan you can follow under pressure is worth more than a perfect plan that's buried in a binder. Get the basics documented today. You can refine it over time.
Want to know if your practice is breach-ready?
The free Cyber Health Score takes 5 minutes and includes questions on incident response readiness.
Get your free Cyber Health Score