When attackers claim a 33GB archive of your files, your first 72 hours determine whether you face regulatory penalties, class-action exposure, or both. This guide breaks down the technical and compliance actions your team must take after a healthcare data breach.
Scope
This guide covers post-breach response for U.S. healthcare organizations subject to HIPAA and state notification laws. It addresses technical containment, evidence preservation, regulatory notification timelines, and patient communication requirements. Use this when you've confirmed unauthorized access to systems containing protected health information.
Key Concepts
Protected Health Information (PHI): Any individually identifiable health data created, received, or maintained by a covered entity. This includes patient ID numbers, treatment records, and provider contact information tied to specific patients.
Breach under HIPAA: Unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy. The breach presumption applies unless you can demonstrate a low probability of compromise through a four-factor risk assessment.
Covered Entity: Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically.
Business Associate: Any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
Requirements Breakdown
Federal: HIPAA Breach Notification Rule (45 CFR §§ 164.400-414)
Individual notification: Required within 60 calendar days of breach discovery for all affected individuals. Must include:
- Description of the breach
- Types of information involved
- Steps individuals should take
- What you're doing to investigate and mitigate
- Contact procedures for questions
Media notification: Required if the breach affects 500+ residents of a state or jurisdiction. Notify prominent media outlets within 60 days.
HHS notification:
- Breaches affecting 500+ individuals: notify HHS Secretary within 60 days
- Breaches affecting fewer than 500: maintain an internal log, submit annually within 60 days of calendar year-end
State Laws: California Example
California Civil Code § 1798.82 requires notification "in the most expedient time possible and without unreasonable delay" following discovery. Unlike HIPAA's 60-day window, California expects notification as soon as you've completed a preliminary investigation.
Implementation Guidance
Hour 0-4: Immediate Containment
Isolate compromised systems without destroying forensic evidence. If attackers accessed "some information systems" (as in the Novocure incident), your priority is determining scope before you lock down everything and lose visibility.
Actions:
- Snapshot running memory on affected systems
- Preserve authentication logs (minimum 90 days retention recommended)
- Document all administrative actions with timestamps
- Establish an incident command structure with defined roles
Hour 4-24: Scope Determination
Your risk assessment drives notification obligations. HIPAA requires you to evaluate:
- Nature and extent of PHI involved
- Unauthorized person who accessed PHI
- Whether PHI was actually acquired or viewed
- Extent to which risk has been mitigated
In the Novocure breach, attackers accessed patient ID numbers for over 1,400 individuals but no names or identifying data for most. For fewer than 50 patients, they obtained identifying information and provider contacts. This distinction matters: patient ID numbers alone may not trigger notification if you can demonstrate low compromise risk.
Technical evidence to collect:
- Database query logs showing exact fields accessed
- File access logs with read/write/copy operations
- Network egress logs showing data volume transmitted
- Authentication logs showing session duration and privilege escalation
Day 1-3: Legal and Regulatory Assessment
Engage privacy counsel before you notify anyone. Your outside counsel can claim attorney-client privilege over your investigation findings; your internal compliance team cannot.
Regulatory notification decision tree:
- Was PHI accessed? (Yes = continue)
- Can you demonstrate low probability of compromise? (No = breach notification required)
- Does the breach affect 500+ individuals? (Yes = immediate HHS and media notification)
- Are affected individuals in multiple states? (Yes = review each state's law)
Day 3-60: Patient Notification
Draft notification letters with specificity. Vague language like "your information may have been accessed" invites regulatory scrutiny. State exactly what happened.
Required elements:
- Date range of unauthorized access
- Specific data elements compromised (e.g., "patient ID numbers and treatment dates" vs. "medical records")
- Whether data included names, Social Security numbers, financial information
- Services you're offering (credit monitoring if financial data exposed)
Ongoing: System Hardening
ShinyHunters, the group claiming the Novocure breach, has targeted Snowflake customers, Salesforce integrations, and Oracle PeopleSoft deployments. Their pattern: exploit third-party platforms and integration points, not primary healthcare applications.
Priority controls:
- Audit all third-party data processor access
- Implement network segmentation between clinical and administrative systems
- Require multi-factor authentication for any system storing PHI
- Monitor for anomalous database queries (large result sets, off-hours access)
Common Pitfalls
Waiting for investigation completion before notification. HIPAA's 60-day clock starts at discovery, not when you've finished your forensic review. Notify based on what you know, then provide updates.
Treating patient ID numbers as non-identifying. If an attacker can correlate your patient IDs with external data sources, they become identifiable. Your risk assessment must consider reasonably foreseeable re-identification.
Overlooking Business Associate obligations. If a vendor caused the breach, they must notify you within 60 days. You then have 60 days from their notification. Don't assume the vendor is handling patient notification.
Inconsistent notification timing. If you notify patients on day 45 but wait until day 59 for HHS, regulators will question the delay. Coordinate all notifications within a tight window.
Failing to preserve evidence of risk assessment. If you determine notification isn't required, document your four-factor analysis in detail. HHS may audit your decision years later.
Quick Reference Table
| Requirement | Timeline | Trigger | Recipient |
|---|---|---|---|
| Individual notification | 60 days from discovery | Breach of unsecured PHI | Each affected individual |
| HHS notification (500+) | 60 days from discovery | Breach affecting 500+ individuals | HHS Secretary |
| HHS notification (<500) | Annually, within 60 days of year-end | Breach affecting <500 individuals | HHS Secretary |
| Media notification | 60 days from discovery | Breach affecting 500+ state residents | Prominent media outlets |
| Business Associate to Covered Entity | 60 days from discovery | BA discovers breach | Covered Entity |
| State notification (varies) | "Without unreasonable delay" | State-specific thresholds | State Attorney General or residents |
Key regulation: 45 CFR Part 164, Subpart D (HIPAA Breach Notification Rule)
Enforcement: Office for Civil Rights (OCR), U.S. Department of Health and Human Services
Penalties: Up to $1.5 million per violation category per year (tiered based on culpability)
Bookmark this guide. When you discover unauthorized access, work through each section systematically. Your regulatory exposure depends on documented decision-making, not perfect prevention.



