⚠ If you believe a breach has occurred — contact the Security Officer immediately:
Jacob Russell |
[email protected] | Do not attempt to handle independently.
1. Purpose
This procedure defines the steps EMStool LLC must follow when a breach of unsecured Protected Health Information (PHI) is discovered or suspected. It establishes responsibilities, timelines, and notification requirements under the HIPAA Breach Notification Rule.
The HIPAA Breach Notification Rule (45 CFR §§164.400–414) requires covered entities and business associates to notify affected individuals, the Secretary of HHS, and in some cases the media, following the discovery of a breach of unsecured PHI. Notification to HHS is required within 60 calendar days of discovery.
2. What Constitutes a Breach
A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. Common examples include:
- Unauthorized access to the Cadence application or database
- PHI sent to the wrong recipient (email, fax, print)
- Lost or stolen device containing ePHI
- Ransomware or malware infection affecting systems containing ePHI
- Workforce member accessing patient records without authorization
- Inadvertent disclosure of PHI to an unauthorized third party
2.1 Presumption of Breach
An impermissible use or disclosure of PHI is presumed to be a breach unless the Organization can demonstrate a low probability that the PHI was compromised based on a four-factor risk assessment:
- The nature and extent of the PHI involved (type, amount)
- Who used or received the PHI and whether PHI was actually acquired or viewed
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
2.2 Exceptions — Not a Breach
- Unintentional access by a workforce member acting in good faith within the scope of authority, with no further use or disclosure
- Inadvertent disclosure between authorized workforce members at the same organization
- Disclosure where the Organization has a good faith belief the unauthorized recipient could not have retained the PHI
3. Breach Response Timeline
1
Immediately upon discovery
Contain and assess
- Stop the breach if ongoing (revoke access, disconnect system, change credentials)
- Preserve evidence — do not delete logs, emails, or files
- Report to Security Officer: Jacob Russell at [email protected]
- Document: date/time of discovery, who discovered it, what was observed
2
Within 24–72 hours of discovery
Risk assessment
- Security Officer performs four-factor risk assessment (see §2.1)
- Determine: is this a reportable breach or a non-breach incident?
- Identify: which patients/records were affected, how many individuals, what PHI types
- Review audit logs in Cadence (Admin → Audit Log) for scope of unauthorized access
- Document findings in writing
3
Within 10 business days of discovery
Internal documentation
- Complete the Breach Incident Report (see §6)
- Determine notification obligations (individuals, HHS, media)
- Notify affected customer organization's leadership if breach involves their patient data
- Engage legal counsel if breach involves 500+ individuals or potential criminal activity
4
Without unreasonable delay, no later than 60 days after discovery
Notify affected individuals
- Written notice sent by first-class mail to last known address of each affected individual
- Email permitted only if individual previously agreed to electronic notice
- If contact information is insufficient for 10+ individuals: substitute notice via web posting or major media outlet
- Notice must include the elements listed in §4.1 below
5
Within 60 calendar days of discovery
Notify HHS
- 500+ individuals: Notify HHS simultaneously with individual notification via HHS Breach Reporting Portal
- Fewer than 500 individuals: Log the breach and submit to HHS annually no later than 60 days after the end of the calendar year in which the breach occurred
6
If 500+ residents of a single state or jurisdiction
Media notification
- Notify prominent media outlets serving the affected state or jurisdiction
- Timing: same as individual notification (within 60 days)
4. Notification Content Requirements
4.1 Individual Notification Must Include:
- Brief description of what happened, including date of breach and date of discovery
- Description of the types of PHI involved (e.g., name, DOB, diagnosis, SSN)
- Steps individuals should take to protect themselves (credit monitoring, etc.)
- Brief description of what the Organization is doing to investigate, mitigate, and prevent future breaches
- Contact information: toll-free number, email, website, or mailing address for individuals to ask questions
5. Business Associate Obligations
EMStool LLC operates as a Business Associate for its Cadence customers (covered entities). Upon discovery of a breach affecting a customer's patient data:
- Notify the affected covered entity without unreasonable delay and no later than 60 days after discovery
- Provide the covered entity with all information necessary for them to fulfill their own breach notification obligations
- The covered entity (not EMStool LLC) is responsible for notifying their patients and HHS
- Document the notification to the covered entity and retain for 6 years
6. Breach Incident Report Template
| Field | Details |
| Incident ID | |
| Date/Time Discovered | |
| Discovered By | |
| Date/Time Breach Occurred (estimated) | |
| Description of Incident | |
| Systems / Data Affected | |
| PHI Types Involved | |
| Number of Individuals Affected | |
| Affected Customer Organization(s) | |
| Breach Contained? (Y/N, how) | |
| Risk Assessment Result (Breach / Non-Breach) | |
| Four-Factor Assessment Summary | |
| Individual Notification Date | |
| HHS Notification Date | |
| Customer Notification Date | |
| Corrective Actions Taken | |
| Security Officer Signature | |
7. Record Retention
All breach-related documentation — incident reports, risk assessments, notifications sent, HHS submissions, and corrective action plans — must be retained for a minimum of 6 years from date of creation per 45 CFR §164.316(b)(2).
Security Officer Signature
Jacob Russell, Security Officer