The call comes at 4:40 on a Friday. The IT vendor for a four-physician internal medicine practice says the file server is encrypted, the EHR will not open, and there is a text file on the desktop with instructions for paying in cryptocurrency. The practice manager's first instinct is to have the vendor restore from backup and get Monday's schedule working. Nobody writes down the time of the call. Nobody knows where the cyber insurance policy is. By Monday the vendor has wiped and rebuilt two workstations, the logs that would have shown how the attackers got in are gone, and the 60-day HIPAA notification clock has been running for 64 hours without anyone noticing it started.

A breach response plan for a small medical practice is not a 40-page binder. It is a one-page call list, a log template, three decisions made in advance, and a habit of writing things down. The practices that come through an incident in reasonable shape are the ones that knew, on Friday at 4:41, who to call first and what not to touch.

Glossary first. Under HIPAA, a security incident is any attempted or successful unauthorized access to systems holding protected health information (PHI). A breach is an impermissible use or disclosure of unsecured PHI; it is a legal conclusion reached after a risk assessment, not the same thing as an incident. A business associate is a vendor that handles PHI on the practice's behalf.

Key takeaways

  • Contain first and preserve everything: isolate affected machines from the network and do not wipe or rebuild anything until forensics has copied it.
  • Call the cyber insurance carrier within hours; most policies require prompt notice and the carrier supplies breach counsel and forensics.
  • Start the incident log at the first phone call, because the discovery date starts HIPAA's 60-day clock.
  • Under HIPAA, an incident involving unsecured PHI is presumed to be a breach unless a documented four-factor risk assessment shows a low probability of compromise.
  • OCR's July 2026 settlement with OSF HealthCare confirmed that the 60 days run from discovery, not from the end of the investigation.

Hour zero: contain, then stop touching things

The first hour has two goals that pull against each other: stop the damage from spreading, and preserve the evidence of how it happened. Disconnecting affected machines from the network does both. Pull the network cable or disable the Wi-Fi; do not power them off, because memory holds evidence that disappears on shutdown, and do not let anyone "clean" them. Change the passwords for email, the EHR, the clearinghouse, the bank and the practice management system from a device that was not on the office network, and turn on multifactor authentication anywhere it was off. Then stop. Restoring from backup and rebuilding machines wait until forensics has taken images, because a rebuilt machine cannot tell anyone what data left the building, and the practice has to answer that question to know who to notify.

Do not contact the attackers, do not open the ransom note's links, and do not decide about paying. The Treasury Department's Office of Foreign Assets Control has warned since 2020 that paying certain groups can itself violate sanctions law.

The call list, in order

The order matters because the first calls create the structure for the rest. The cyber insurance carrier goes first, within hours, and always before the practice hires anyone. Most policies require prompt notice and give the carrier the right to appoint counsel and a forensics firm from its panel; hiring your own first can mean the carrier declines to pay for them. The carrier's hotline typically connects the practice to a breach coach, a lawyer who runs the response, on the same call. With no cyber policy, the first call is to a healthcare attorney who does breach work, and the second to a forensics firm the attorney recommends.

OrderWhoWhenWhy
1Cyber insurance carrier hotlineWithin hoursPolicy notice requirement; carrier supplies counsel and forensics
2Breach counselSame day, via the carrierRuns the response under privilege; owns the notification decisions
3Forensics firmDay oneImages systems; determines how the attackers got in and what data left
4IT vendor and EHR or PM vendorDay one, after counselContainment help; they are business associates with their own obligations
5BankDay one if any account was reachableFreeze or monitor accounts; reverse fraudulent transfers
6FBI (field office or ic3.gov)Day one or two, with counselLaw enforcement report; may have decryption keys or intelligence
7Patients, HHS, state attorney general, mediaLater, within the legal deadlinesNotification once the facts are known

Notice what is not in the first 72 hours: patient notification and a press statement. Telling patients before you know what happened means telling them again, differently, in three weeks.

The incident log: what to write down

The log is the single most valuable document the practice will produce, and it starts at the first call, on a legal pad if necessary. Every later question, from the carrier, from OCR, from the state attorney general and from the practice's own lawyer, comes back to when the practice knew what, and who did what about it. OCR's settlement with OSF HealthCare, announced July 29, 2026, concerned a 2021 ransomware incident where notification waited for the forensic investigation to finish; OCR's position was that the clock had started at discovery. The practice needs to be able to show the date and time of discovery and everything after it.

  1. Date and time of discovery, by whom, and how (the vendor's call, a user's report, an alert).
  2. Systems and data involved as currently understood, each update dated.
  3. Every containment action, with time and person: cables pulled, passwords changed, accounts disabled.
  4. Every call made and received, with time, person and what was decided.
  5. Evidence preserved: which machines were imaged, by whom, where the images are.
  6. Communications sent to staff, patients and vendors, with copies.
  7. The risk assessment and the notification decision, with the reasoning and who made it.

Keep the log and everything it references for six years, HIPAA's documentation retention period. Counsel will want the log kept under their direction so that parts of it are privileged; follow their instructions on where it lives and who writes in it.

The 60-day clock and the four-factor risk assessment

HIPAA's Breach Notification Rule presumes that an impermissible use or disclosure of unsecured PHI is a breach. The practice can overcome the presumption only with a documented risk assessment of four factors: the nature and extent of the PHI involved, the unauthorized person who received it, whether the PHI was actually acquired or viewed, and the extent of mitigation. For ransomware, OCR's guidance since 2016 has been that encryption of PHI is itself a disclosure and is presumed a breach unless the assessment shows a low probability of compromise. "We have no evidence the data was taken" is not a low probability; the absence of evidence is often the absence of logs.

If the assessment concludes there was a breach, or the practice chooses to treat it as one, notification runs on these clocks. Individuals get written notice without unreasonable delay and no later than 60 calendar days after discovery, where discovery means the first day the breach was known or should reasonably have been known to anyone in the practice other than the person who committed it. The notice has to say what happened, what kinds of information were involved, what individuals should do, what the practice is doing, and how to reach the practice, including a toll-free number. If the practice lacks current contact information for ten or more people, it posts a substitute notice on its website for 90 days or in major media. HHS is notified through the OCR breach portal: at the same time as individuals if 500 or more are affected, or in an annual filing within 60 days after the end of the calendar year if fewer than 500. A breach affecting more than 500 residents of one state also requires notice to prominent media outlets there.

State law adds a second set of deadlines that can be shorter. Every state has a breach notification statute, most require notice to the state attorney general above some threshold, and several, Colorado and Florida among them, require individual notice within 30 days. Counsel handles this, but 60 days is the outer federal limit and not the plan.

When the breach is your vendor's

Most small-practice breaches now arrive through a business associate. A business associate must notify the practice without unreasonable delay and within 60 days of its own discovery, and the practice's clock generally starts when it receives that notice (unless the vendor is acting as the practice's agent, in which case the vendor's discovery counts). In the first 72 hours after a vendor notice, the practice needs three things in writing: the date the vendor discovered the incident, the data elements involved, and the list of the practice's patients affected. Then the two decide who sends the patient notices; the legal duty is the practice's, but many agreements assign the work and the cost to the vendor. Read yours before you need it; the answers belong in the vendor file next to the RCM audit findings on clearinghouse contingency.

Days 3 to 30: running the practice while the investigation runs

Meanwhile the practice has to see patients. The downtime plan is paper: printed schedules (a nightly export of tomorrow's schedule to a secure location is a good habit), paper superbills, eligibility through payer portals from a clean device, and a log of every encounter so nothing is lost when the systems return. Cash flow suffers for four to eight weeks because claims stop, so the second week is when the practice talks with its bank and plans to enter the paper backlog in date order once the system is back. Forensics decides when a restore is safe.

Where the regulations stand this month: the HIPAA Security Rule update that OCR proposed in January 2025, which would require written incident response plans and restoration of critical systems within 72 hours, has still not been finalized, and the federal regulatory agenda now points to 2027. The current rule already requires a security incident response process and a risk analysis, and OCR's recent enforcement has focused on practices that could not produce either one.

Questions we hear

The vendor restored everything from backup by Monday and nothing seems to be missing. Do we still have to notify anyone?

Restoration answers the availability question, not the disclosure question. If PHI was encrypted or accessible to an outside party, the presumption of breach applies until a documented four-factor risk assessment says otherwise.

Should we pay the ransom?

That is a decision for the owners with counsel, the carrier and forensics at the table, usually on the second or third day once the scope is known. Payment does not remove the notification duty, does not guarantee working decryption, and can raise sanctions issues. Practices with tested backups rarely face the question.

What if we discover a small incident, like a misdirected fax with two patients' records?

Same process, smaller scale. Log it, do the four-factor assessment, notify the two patients if it is a breach, and record it for the annual HHS filing due within 60 days after year end.

What to do this week

  1. Find the cyber insurance policy, write the carrier's hotline and policy numbers on the call list, and read the notice requirement.
  2. Print a one-page call list in the order above with after-hours numbers, and keep copies at the front desk, in the manager's office and at home.
  3. Create the incident log template from the seven fields above and store a blank copy off the office network.
  4. Ask each business associate for its notification commitment and its incident response contact, and file the answers.
  5. Test a restore from backup, confirm the backups are offline or immutable, and set a nightly export of the next day's schedule.
  6. Run a 30-minute tabletop exercise with the physicians using the Friday 4:40 scenario, and fix what you could not answer.