EMStool LLC — Cadence MIH Scheduling Platform

Breach Notification Procedure

Policy #: HIPAA-SEC-006 Effective Date: June 1, 2026 Version: 1.0 Next Review: June 1, 2027
⚠ If you believe a breach has occurred — contact the Security Officer immediately:
Jacob Russell  |  [email protected]  |  Do not attempt to handle independently.

1. Purpose

This procedure defines the steps EMStool LLC must follow when a breach of unsecured Protected Health Information (PHI) is discovered or suspected. It establishes responsibilities, timelines, and notification requirements under the HIPAA Breach Notification Rule.

The HIPAA Breach Notification Rule (45 CFR §§164.400–414) requires covered entities and business associates to notify affected individuals, the Secretary of HHS, and in some cases the media, following the discovery of a breach of unsecured PHI. Notification to HHS is required within 60 calendar days of discovery.

2. What Constitutes a Breach

A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. Common examples include:

2.1 Presumption of Breach

An impermissible use or disclosure of PHI is presumed to be a breach unless the Organization can demonstrate a low probability that the PHI was compromised based on a four-factor risk assessment:

  1. The nature and extent of the PHI involved (type, amount)
  2. Who used or received the PHI and whether PHI was actually acquired or viewed
  3. Whether the PHI was actually acquired or viewed
  4. The extent to which the risk has been mitigated

2.2 Exceptions — Not a Breach

3. Breach Response Timeline

1
Immediately upon discovery
Contain and assess
  • Stop the breach if ongoing (revoke access, disconnect system, change credentials)
  • Preserve evidence — do not delete logs, emails, or files
  • Report to Security Officer: Jacob Russell at [email protected]
  • Document: date/time of discovery, who discovered it, what was observed
2
Within 24–72 hours of discovery
Risk assessment
  • Security Officer performs four-factor risk assessment (see §2.1)
  • Determine: is this a reportable breach or a non-breach incident?
  • Identify: which patients/records were affected, how many individuals, what PHI types
  • Review audit logs in Cadence (Admin → Audit Log) for scope of unauthorized access
  • Document findings in writing
3
Within 10 business days of discovery
Internal documentation
  • Complete the Breach Incident Report (see §6)
  • Determine notification obligations (individuals, HHS, media)
  • Notify affected customer organization's leadership if breach involves their patient data
  • Engage legal counsel if breach involves 500+ individuals or potential criminal activity
4
Without unreasonable delay, no later than 60 days after discovery
Notify affected individuals
  • Written notice sent by first-class mail to last known address of each affected individual
  • Email permitted only if individual previously agreed to electronic notice
  • If contact information is insufficient for 10+ individuals: substitute notice via web posting or major media outlet
  • Notice must include the elements listed in §4.1 below
5
Within 60 calendar days of discovery
Notify HHS
  • 500+ individuals: Notify HHS simultaneously with individual notification via HHS Breach Reporting Portal
  • Fewer than 500 individuals: Log the breach and submit to HHS annually no later than 60 days after the end of the calendar year in which the breach occurred
6
If 500+ residents of a single state or jurisdiction
Media notification
  • Notify prominent media outlets serving the affected state or jurisdiction
  • Timing: same as individual notification (within 60 days)

4. Notification Content Requirements

4.1 Individual Notification Must Include:

Organization Contact for Breach Inquiries:
EMStool LLC — Security Officer
Jacob Russell
Email: [email protected]
Website: emstool.com

5. Business Associate Obligations

EMStool LLC operates as a Business Associate for its Cadence customers (covered entities). Upon discovery of a breach affecting a customer's patient data:

6. Breach Incident Report Template

FieldDetails
Incident ID 
Date/Time Discovered 
Discovered By 
Date/Time Breach Occurred (estimated) 
Description of Incident 
Systems / Data Affected 
PHI Types Involved 
Number of Individuals Affected 
Affected Customer Organization(s) 
Breach Contained? (Y/N, how) 
Risk Assessment Result (Breach / Non-Breach) 
Four-Factor Assessment Summary 
Individual Notification Date 
HHS Notification Date 
Customer Notification Date 
Corrective Actions Taken 
Security Officer Signature 

7. Record Retention

All breach-related documentation — incident reports, risk assessments, notifications sent, HHS submissions, and corrective action plans — must be retained for a minimum of 6 years from date of creation per 45 CFR §164.316(b)(2).

Security Officer Signature
Jacob Russell, Security Officer
Date
June 1, 2026