Get Demo
↑

HIPAA Incident Response Plan Template

Incident response plan outline for §164.308(a)(6), aligned to Breach Notification Rule timelines under 45 CFR 164.400–414.

Published: September 2026 Compliance · HIPAA 8–12 min read

§164.308(a)(6) requires security incident procedures. When an incident is a breach of unsecured PHI, the Breach Notification Rule clocks apply. Use this template outline to structure your plan — customise with counsel and your clinical/ops stakeholders.

Related: HIPAA hub · Breach notification guide · Penalties.

Breach Notification Rule clocks — 45 CFR 164.400–414 (HITECH-based): Individuals: without unreasonable delay and in no case later than 60 calendar days after discovery (164.404). HHS for breaches affecting 500+ individuals: without unreasonable delay and no later than 60 calendar days after discovery (164.408). HHS for fewer than 500: not later than 60 days after the end of the calendar year in which the breach was discovered. Media: if 500+ residents of a State or jurisdiction, notify prominent media without unreasonable delay and no later than 60 days (164.406). Business associates must notify the covered entity without unreasonable delay and no later than 60 days after discovery (164.410).

Plan Outline

  1. Purpose & scope: systems with ePHI; CE/BA role
  2. Roles: Security Officer, Privacy Officer, IR lead, communications, legal
  3. Detection & triage: severity, PHI involvement, ransomware vs misdirected disclosure
  4. Containment & eradication: isolate, preserve logs, rotate credentials
  5. Risk assessment: four-factor breach assessment for unsecured PHI
  6. Notification decision tree: map to 164.404 / 406 / 408 / 410 clocks
  7. Recovery & lessons learned: update risk analysis and controls
  8. Record retention: keep IR/breach files with Security Rule documentation practices

Notification Clock Checklist

No Word/Excel download is attached. Request facilitation via contact.

How CyberSilo Helps

Rehearse the 60-Day Clocks Before You Need Them

Tabletop detection → breach assessment → notification packages with real log sources.

Frequently Asked Questions

What is the individual notification deadline?

Without unreasonable delay and in no case later than 60 calendar days after discovery (45 CFR 164.404).

When must HHS be notified for 500+ breaches?

Without unreasonable delay and no later than 60 calendar days after discovery (164.408).

What must business associates do?

Notify the covered entity without unreasonable delay and no later than 60 days after discovery (164.410).

HIPAA hub · Breach rule · Audit logs · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!