HIPAA Breach Log Template
HIPAA BREACH LOG AND INCIDENT TRACKING SYSTEM
INSTRUCTIONS FOR USE
This Breach Log Template is designed for HIPAA covered entities and business associates to document, track, and manage breaches of unsecured protected health information (PHI) as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400-414). The log also supports documentation obligations under 45 C.F.R. § 164.530(j), which requires retention of all records related to HIPAA compliance for a minimum of six (6) years from the date of creation or the date the document was last in effect, whichever is later.
Privacy Officer or Designee: [________________________________]
Organization Name: [________________________________]
Organization Address: [________________________________]
Log Maintained Since: [__/__/____]
Key Definitions
Breach (45 C.F.R. § 164.402): The acquisition, access, use, or disclosure of protected health information in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the protected health information. A breach is presumed unless the covered entity or business associate demonstrates through a documented risk assessment that there is a low probability the PHI has been compromised.
Security Incident (45 C.F.R. § 164.304): The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Not all security incidents constitute breaches; however, all security incidents must be evaluated to determine whether a breach has occurred.
Unsecured PHI (45 C.F.R. § 164.402): Protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by HHS guidance (i.e., encryption meeting NIST standards or destruction per NIST SP 800-88).
Breach vs. Security Incident — Critical Distinction
| Factor | Security Incident | Breach |
|---|---|---|
| Definition | Attempted or successful unauthorized access, use, disclosure, modification, or destruction of information in an information system | Impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy |
| Regulatory Citation | 45 C.F.R. § 164.304 | 45 C.F.R. § 164.402 |
| Scope | All electronic information systems | PHI only |
| Notification Required | Internal documentation only | Individual, HHS, and potentially media notification |
| Response Obligation | Identify, respond, mitigate, document (§ 164.308(a)(6)) | Full breach notification and risk assessment |
| Presumption | No presumption | Presumed breach unless risk assessment demonstrates low probability of compromise |
SECTION 1: BREACH INCIDENT LOG ENTRIES
INCIDENT ENTRY NO. [____]
1.1 Incident Identification
| Field | Entry |
|---|---|
| Incident ID Number | [________________________________] |
| Date of Breach/Incident | [__/__/____] |
| Date Breach Discovered | [__/__/____] |
| Date Reported Internally | [__/__/____] |
| Reported By (Name/Title) | [________________________________] |
| Privacy Officer Notified | ☐ Yes ☐ No — Date: [__/__/____] |
| Security Officer Notified | ☐ Yes ☐ No — Date: [__/__/____] |
| Legal Counsel Notified | ☐ Yes ☐ No — Date: [__/__/____] |
1.2 Incident Classification
Type of Incident (check all that apply):
☐ Hacking/IT incident (ransomware, malware, phishing, network intrusion)
☐ Unauthorized access by workforce member
☐ Unauthorized access by third party
☐ Unauthorized disclosure — verbal
☐ Unauthorized disclosure — written/electronic
☐ Lost or stolen laptop/computer
☐ Lost or stolen portable electronic device (USB, phone, tablet)
☐ Lost or stolen paper records
☐ Mailing error (sent to wrong recipient)
☐ Fax error (sent to wrong number)
☐ Email error (sent to wrong recipient)
☐ Improper disposal of PHI (paper or electronic)
☐ Business associate breach
☐ EHR/system misconfiguration
☐ Patient portal access error
☐ Other: [________________________________]
1.3 Detailed Description of Incident
Narrative Description (what happened, how it was discovered, who was involved):
[________________________________]
[________________________________]
[________________________________]
[________________________________]
[________________________________]
1.4 PHI Types Involved
Check all categories of PHI involved in the incident:
☐ Patient name
☐ Date of birth
☐ Social Security number
☐ Address/geographic data
☐ Phone/fax number
☐ Email address
☐ Medical record number
☐ Health plan beneficiary number
☐ Account number
☐ Diagnosis/clinical information
☐ Treatment information
☐ Medications
☐ Lab results
☐ Mental health records
☐ Substance use disorder records (42 C.F.R. Part 2)
☐ HIV/AIDS status
☐ Genetic information (GINA)
☐ Sexual/reproductive health information
☐ Financial/billing information
☐ Insurance information
☐ Photographs/images
☐ Biometric identifiers
☐ Other: [________________________________]
1.5 Individuals Affected
| Field | Entry |
|---|---|
| Estimated Number of Individuals Affected | [____] |
| Final Confirmed Number | [____] |
| States/Jurisdictions Where Affected Individuals Reside | [________________________________] |
| Any State Exceeding 500 Individuals? | ☐ Yes — State(s): [____] ☐ No |
1.6 Systems/Media Affected
☐ Electronic health record (EHR) system — Name: [________________________________]
☐ Email system
☐ Desktop computer(s) — Location: [________________________________]
☐ Laptop(s) — Asset ID: [________________________________]
☐ Server(s) — Name: [________________________________]
☐ Mobile device(s) — Type: [________________________________]
☐ Portable media (USB, external drive)
☐ Paper records
☐ Cloud-based system — Provider: [________________________________]
☐ Fax machine
☐ Copier/scanner
☐ Backup media
☐ Other: [________________________________]
Was the PHI encrypted at the time of the incident? ☐ Yes ☐ No
If yes, specify encryption standard: [________________________________]
Was the encryption key compromised? ☐ Yes ☐ No ☐ Unknown
SECTION 2: FOUR-FACTOR RISK ASSESSMENT
Per 45 C.F.R. § 164.402(2), a breach is presumed unless the covered entity or business associate demonstrates through a risk assessment that there is a low probability the PHI has been compromised. The following four factors must be assessed and documented:
Factor 1: Nature and Extent of the PHI Involved
Evaluate the types of identifiers and the likelihood of re-identification.
| Assessment Element | Analysis |
|---|---|
| Types of identifiers exposed | [________________________________] |
| Sensitivity level of clinical information | ☐ High ☐ Medium ☐ Low |
| Financial information included | ☐ Yes ☐ No |
| SSN or government ID included | ☐ Yes ☐ No |
| Likelihood of re-identification | ☐ High ☐ Medium ☐ Low |
| Combination risk (multiple data elements) | [________________________________] |
Risk Level for Factor 1: ☐ High ☐ Medium ☐ Low
Narrative Analysis: [________________________________]
[________________________________]
Factor 2: The Unauthorized Person Who Used or Received the PHI
Evaluate the identity and characteristics of the unauthorized recipient.
| Assessment Element | Analysis |
|---|---|
| Identity of unauthorized recipient | [________________________________] |
| Is the recipient a covered entity or BA? | ☐ Yes ☐ No ☐ Unknown |
| Is the recipient a workforce member? | ☐ Yes ☐ No |
| Does recipient have independent HIPAA obligations? | ☐ Yes ☐ No ☐ Unknown |
| Was recipient known or unknown? | ☐ Known ☐ Unknown |
| Likelihood recipient will misuse the PHI | [________________________________] |
Risk Level for Factor 2: ☐ High ☐ Medium ☐ Low
Narrative Analysis: [________________________________]
[________________________________]
Factor 3: Whether the PHI Was Actually Acquired or Viewed
Evaluate whether the information was actually accessed or only potentially exposed.
| Assessment Element | Analysis |
|---|---|
| Was PHI actually viewed or accessed? | ☐ Confirmed viewed ☐ Believed viewed ☐ Opportunity to view but no evidence of actual viewing ☐ Unknown |
| Evidence of access (audit logs, forensic analysis) | [________________________________] |
| Was any PHI downloaded, copied, or retained? | ☐ Yes ☐ No ☐ Unknown |
| Duration of unauthorized access | [________________________________] |
Risk Level for Factor 3: ☐ High ☐ Medium ☐ Low
Narrative Analysis: [________________________________]
[________________________________]
Factor 4: Extent to Which Risk Has Been Mitigated
Evaluate steps taken to reduce the risk of harm.
| Assessment Element | Analysis |
|---|---|
| Were records recovered? | ☐ Yes — Date: [__/__/____] ☐ No ☐ N/A |
| Recipient provided assurances of destruction? | ☐ Yes — Date: [__/__/____] ☐ No |
| Recipient signed confidentiality agreement? | ☐ Yes ☐ No ☐ N/A |
| Technical controls applied (password reset, access revocation) | [________________________________] |
| Forensic investigation conducted? | ☐ Yes ☐ No |
| Other mitigation steps | [________________________________] |
Risk Level for Factor 4: ☐ High ☐ Medium ☐ Low
Narrative Analysis: [________________________________]
[________________________________]
Overall Risk Assessment Determination
| Overall Probability PHI Was Compromised | ☐ Low Probability — Not a reportable breach | ☐ Greater than Low Probability — Reportable breach |
|---|---|---|
Determination Made By: [________________________________]
Title: [________________________________]
Date of Determination: [__/__/____]
Note: If the covered entity is unable to demonstrate a low probability of compromise, the incident must be treated as a breach and notification obligations apply. The burden of proof rests with the covered entity or business associate (45 C.F.R. § 164.414(b)).
SECTION 3: CONTAINMENT AND REMEDIATION ACTIONS
3.1 Immediate Containment Actions
| Action | Completed | Date | Responsible Party |
|---|---|---|---|
| System access revoked/password changed | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Affected device secured/isolated | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Physical records recovered/secured | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Network/system vulnerability patched | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Remote wipe of device initiated | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Law enforcement contacted | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Forensic investigation initiated | ☐ Yes ☐ No ☐ N/A | [__/__/____] | [________________] |
| Other: [________________] | ☐ Yes ☐ No | [__/__/____] | [________________] |
3.2 Root Cause Analysis
| Element | Finding |
|---|---|
| Root cause category | ☐ Human error ☐ System failure ☐ Criminal/malicious act ☐ Process failure ☐ Third-party failure ☐ Natural disaster ☐ Unknown |
| Detailed root cause description | [________________________________] |
| Contributing factors | [________________________________] |
| Existing controls that failed | [________________________________] |
| Was this a repeat occurrence? | ☐ Yes — Reference prior incident ID: [____] ☐ No |
3.3 Corrective Actions / Remediation Plan
| Corrective Action | Responsible Party | Target Date | Completion Date | Status |
|---|---|---|---|---|
| [________________________________] | [________________] | [__/__/____] | [__/__/____] | ☐ Open ☐ In Progress ☐ Complete |
| [________________________________] | [________________] | [__/__/____] | [__/__/____] | ☐ Open ☐ In Progress ☐ Complete |
| [________________________________] | [________________] | [__/__/____] | [__/__/____] | ☐ Open ☐ In Progress ☐ Complete |
| [________________________________] | [________________] | [__/__/____] | [__/__/____] | ☐ Open ☐ In Progress ☐ Complete |
| [________________________________] | [________________] | [__/__/____] | [__/__/____] | ☐ Open ☐ In Progress ☐ Complete |
SECTION 4: NOTIFICATION STATUS TRACKING
4.1 Individual Notification (45 C.F.R. § 164.404)
Notification to affected individuals must be made without unreasonable delay and no later than 60 calendar days from the date of discovery of the breach.
| Field | Entry |
|---|---|
| 60-Day Deadline | [__/__/____] |
| Method of notification | ☐ First-class mail ☐ Email (if individual previously agreed) ☐ Substitute notice (insufficient contact info for 10+ individuals) ☐ Urgent notification by phone (imminent misuse) |
| Date individual notification letters sent | [__/__/____] |
| Number of individuals notified | [____] |
| Notification letter approved by | [________________________________] |
| Return mail/undeliverable notices | [____] |
| Substitute notice posted on website | ☐ Yes — URL: [________________________________] ☐ No ☐ N/A |
| Toll-free number activated (if substitute notice) | ☐ Yes — Number: [________________] ☐ No ☐ N/A |
Required Content of Individual Notification (45 C.F.R. § 164.404(c)):
☐ Brief description of what happened, including date of breach and date of discovery
☐ Description of types of unsecured PHI involved
☐ Steps individuals should take to protect themselves
☐ Brief description of what covered entity is doing to investigate, mitigate harm, and prevent future breaches
☐ Contact procedures (toll-free number, email, website, postal address)
4.2 HHS/OCR Notification (45 C.F.R. § 164.408)
| Field | Entry |
|---|---|
| Total individuals affected | [____] |
| Breach involves 500+ individuals? | ☐ Yes ☐ No |
| If 500+ individuals: Notification to HHS due no later than 60 days from discovery | [__/__/____] |
| Date HHS notified via breach portal | [__/__/____] |
| If fewer than 500 individuals: Annual log submitted to HHS | Due within 60 days of end of calendar year |
| Date added to annual breach log for HHS | [__/__/____] |
| HHS case number (if assigned) | [________________________________] |
4.3 Media Notification (45 C.F.R. § 164.406)
Required only when breach affects 500 or more individuals in a single state or jurisdiction.
| Field | Entry |
|---|---|
| Media notification required? | ☐ Yes ☐ No |
| State(s) requiring media notification | [________________________________] |
| Date media notice issued | [__/__/____] |
| Media outlets contacted | [________________________________] |
| Method of media notification | ☐ Press release ☐ Direct media contact ☐ Other: [________________] |
4.4 State Attorney General / Regulatory Notification
Many states require separate breach notification to the state attorney general or other regulatory bodies, often with shorter timelines.
| State | AG Notification Required | Deadline | Date Notified | Confirmation/Reference |
|---|---|---|---|---|
| [____] | ☐ Yes ☐ No | [__/__/____] | [__/__/____] | [________________] |
| [____] | ☐ Yes ☐ No | [__/__/____] | [__/__/____] | [________________] |
| [____] | ☐ Yes ☐ No | [__/__/____] | [__/__/____] | [________________] |
State-Specific Notification Deadlines (Selected):
- California (Cal. Civ. Code § 1798.82): Notification to AG if 500+ CA residents affected; "expedient" notification to individuals
- Texas (Tex. Bus. & Com. Code § 521.053): Notification within 60 days; AG notification if 250+ TX residents
- Florida (Fla. Stat. § 501.171): Notification within 30 days; AG notification if 500+ FL residents
- New York (N.Y. Gen. Bus. Law § 899-aa; SHIELD Act): Notification "in the most expedient time possible"; AG, DFS, and Division of State Police notification required
4.5 Business Associate Breach Reporting (45 C.F.R. § 164.410)
| Field | Entry |
|---|---|
| Did breach originate with a business associate? | ☐ Yes ☐ No |
| Business associate name | [________________________________] |
| Date BA discovered breach | [__/__/____] |
| Date BA notified covered entity | [__/__/____] |
| Was notification within 60 days (or shorter if specified in BAA)? | ☐ Yes ☐ No |
| BAA notification deadline per agreement | [____] days |
| Information provided by BA | ☐ Identity of individuals affected ☐ Description of breach ☐ Types of PHI ☐ Other: [________________] |
4.6 Law Enforcement Delay (45 C.F.R. § 164.412)
| Field | Entry |
|---|---|
| Law enforcement requested delay of notification? | ☐ Yes ☐ No |
| Law enforcement agency | [________________________________] |
| Written statement received? | ☐ Yes — Date: [__/__/____] ☐ Oral request — Date: [__/__/____] |
| Duration of delay requested | [____] days (max 30 days for oral; as specified for written) |
| Date delay expired | [__/__/____] |
| Notification resumed | ☐ Yes — Date: [__/__/____] |
SECTION 5: ANNUAL BREACH SUMMARY REPORT
This section supports the annual compilation and review of all breach incidents. Complete at the end of each calendar year.
Reporting Period: [__/__/____] to [__/__/____]
Prepared By: [________________________________]
Date Prepared: [__/__/____]
5.1 Annual Summary Statistics
| Metric | Count |
|---|---|
| Total security incidents reported | [____] |
| Total incidents determined to be breaches | [____] |
| Total incidents determined NOT to be breaches (low probability per risk assessment) | [____] |
| Total individuals affected (all breaches combined) | [____] |
| Breaches reported to HHS (500+ individuals) | [____] |
| Breaches included in annual HHS log (<500 individuals) | [____] |
| Media notifications issued | [____] |
| State AG notifications issued | [____] |
5.2 Breach Categories Summary
| Category | Number of Incidents | Percentage |
|---|---|---|
| Hacking/IT incident | [____] | [____]% |
| Unauthorized access/disclosure | [____] | [____]% |
| Lost/stolen device | [____] | [____]% |
| Mailing/fax/email error | [____] | [____]% |
| Improper disposal | [____] | [____]% |
| Business associate breach | [____] | [____]% |
| Other | [____] | [____]% |
5.3 Trends and Patterns
Identified Trends: [________________________________]
[________________________________]
Repeat Incident Types: [________________________________]
Departments/Locations with Highest Incident Rates: [________________________________]
5.4 Corrective Action Effectiveness Review
| Corrective Action Implemented | Effective? | Evidence |
|---|---|---|
| [________________________________] | ☐ Yes ☐ Partially ☐ No | [________________________________] |
| [________________________________] | ☐ Yes ☐ Partially ☐ No | [________________________________] |
| [________________________________] | ☐ Yes ☐ Partially ☐ No | [________________________________] |
5.5 Recommendations for Upcoming Year
[________________________________]
[________________________________]
[________________________________]
SECTION 6: SAMPLE LOG ENTRIES — REFERENCE EXAMPLES
The following examples illustrate how to document different breach types. These are for reference only and should not be submitted as actual incidents.
Example A: Hacking/Ransomware Incident
| Field | Example Entry |
|---|---|
| Incident ID | 2026-001 |
| Date of Breach | 01/15/2026 |
| Date Discovered | 01/16/2026 |
| Classification | Hacking/IT incident — ransomware |
| Description | Ransomware encrypted EHR database server. Forensic analysis confirmed unauthorized access to patient records database containing demographic, clinical, and insurance information for approximately 12,500 patients. Attacker gained access through phishing email to administrative staff member. |
| PHI Types | Names, DOB, SSN, diagnosis, treatment, insurance |
| Individuals Affected | 12,500 |
| Risk Assessment Result | High probability of compromise — reportable breach |
| Notifications | Individual (mail), HHS (portal), media (press release to 3 state outlets), state AG (CA, TX) |
Example B: Unauthorized Access by Workforce Member
| Field | Example Entry |
|---|---|
| Incident ID | 2026-002 |
| Date of Breach | 02/03/2026 |
| Date Discovered | 02/10/2026 |
| Classification | Unauthorized access — workforce member |
| Description | Registration clerk accessed medical records of a co-worker and disclosed diagnosis information to other staff members. Discovered through routine audit log review. |
| PHI Types | Name, diagnosis, treatment information |
| Individuals Affected | 1 |
| Risk Assessment Result | Greater than low probability — reportable breach |
| Notifications | Individual (letter), HHS annual log |
Example C: Mailing Error
| Field | Example Entry |
|---|---|
| Incident ID | 2026-003 |
| Date of Breach | 03/01/2026 |
| Date Discovered | 03/05/2026 |
| Classification | Mailing error |
| Description | Explanation of Benefits statements for 45 patients mailed to incorrect addresses due to mail merge error in billing system. Unintended recipients were other patients of the practice. |
| PHI Types | Names, dates of service, procedure codes, billing amounts |
| Individuals Affected | 45 |
| Risk Assessment Result | Low probability of compromise — recipients are HIPAA-covered patients with confidentiality obligations; letters recovered |
| Notifications | None required (documented risk assessment on file) |
Example D: Lost/Stolen Device
| Field | Example Entry |
|---|---|
| Incident ID | 2026-004 |
| Date of Breach | 04/12/2026 |
| Date Discovered | 04/12/2026 |
| Classification | Lost/stolen portable device |
| Description | Physician's unencrypted laptop stolen from locked vehicle. Laptop contained patient scheduling information and clinical notes for approximately 300 patients. |
| PHI Types | Names, DOB, appointment dates, clinical notes |
| Individuals Affected | 300 |
| Risk Assessment Result | Greater than low probability — device unencrypted, PHI unsecured |
| Notifications | Individual (letter), HHS annual log, police report filed |
Example E: Verbal Disclosure
| Field | Example Entry |
|---|---|
| Incident ID | 2026-005 |
| Date of Breach | 05/20/2026 |
| Date Discovered | 05/20/2026 |
| Classification | Unauthorized disclosure — verbal |
| Description | Nurse discussed patient's HIV status in hospital elevator within earshot of visitors. Reported by charge nurse who overheard the conversation. |
| PHI Types | Name, HIV status |
| Individuals Affected | 1 |
| Risk Assessment Result | Greater than low probability — sensitive diagnosis, visitors present |
| Notifications | Individual (letter), HHS annual log |
SECTION 7: OCR AUDIT PREPAREDNESS DOCUMENTATION
7.1 Documentation Retention Checklist
Per 45 C.F.R. § 164.530(j), the following documentation must be retained for a minimum of six (6) years:
☐ This breach log and all incident entries
☐ Risk assessment documentation for each incident
☐ Notification letters (copies)
☐ HHS breach portal submission confirmations
☐ Media notifications (copies)
☐ State AG notifications (copies)
☐ Business associate breach notifications received
☐ Law enforcement delay requests and correspondence
☐ Corrective action plans and completion documentation
☐ Root cause analysis documentation
☐ Sanctions applied to workforce members (if any)
☐ Training records related to breach incidents
☐ Policies and procedures related to breach notification
☐ Annual breach summary reports
7.2 Audit Response Preparation
| Element | Location/Status |
|---|---|
| Breach notification policies and procedures | [________________________________] |
| Current risk analysis | [________________________________] |
| Encryption documentation/inventory | [________________________________] |
| Business associate agreements (relevant) | [________________________________] |
| Workforce training records | [________________________________] |
| Sanctions policy and records | [________________________________] |
| Designated privacy officer documentation | [________________________________] |
| Designated security officer documentation | [________________________________] |
SECTION 8: LOG MAINTENANCE INSTRUCTIONS
-
Assign Incident IDs sequentially using the format YYYY-NNN (e.g., 2026-001, 2026-002).
-
Record Entries Promptly. Begin a log entry as soon as an incident is reported. Update the entry as the investigation progresses. Under 45 C.F.R. § 164.404(a)(2), the date of discovery is the first day the breach is known or would have been known by exercising reasonable diligence.
-
Complete the Four-Factor Risk Assessment for every incident involving an impermissible use or disclosure of PHI. Document the assessment even if the determination is that the incident does not constitute a breach.
-
Track All Deadlines. The 60-day notification clock begins on the date of discovery, not the date of the breach itself. Calendar all notification deadlines immediately upon discovery.
-
Coordinate with Legal Counsel. Engage legal counsel early in the breach assessment process. Consider conducting the risk assessment under attorney-client privilege when appropriate.
-
Retain for Six Years Minimum. Per 45 C.F.R. § 164.530(j), all documentation must be retained for at least six years. Many states require longer retention. Establish a retention schedule that meets the most stringent applicable requirement.
-
Review Annually. Conduct an annual review of the breach log to identify trends, evaluate corrective action effectiveness, and update policies and procedures as necessary.
-
Secure the Log. This log contains sensitive information about security vulnerabilities and breaches. Store it securely with access limited to the Privacy Officer, Security Officer, legal counsel, and authorized compliance personnel.
-
Coordinate State Requirements. Many states have breach notification laws with shorter timelines or additional requirements. Consult the state-specific notification deadlines in Section 4.4 and review applicable state law for each incident.
-
Annual HHS Reporting. For breaches affecting fewer than 500 individuals, compile and submit the annual breach log to HHS within 60 days after the end of the calendar year in which the breaches were discovered (45 C.F.R. § 164.408(c)).
Sources and References
- U.S. Department of Health and Human Services, "Breach Notification Rule": https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- 45 C.F.R. Part 164, Subpart D — Notification in the Case of Breach of Unsecured PHI: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
- HHS OCR, "How OCR Enforces the HIPAA Privacy & Security Rules": https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/examples/how-ocr-enforces-the-hipaa-privacy-and-security-rules/index.html
- 45 C.F.R. § 164.402 — Definitions (Breach, Unsecured PHI): https://www.law.cornell.edu/cfr/text/45/164.402
- 45 C.F.R. § 164.530 — Administrative Requirements (Documentation and Retention): https://www.law.cornell.edu/cfr/text/45/164.530
- HIPAA Journal, "HIPAA Breach Notification Requirements — Updated 2026": https://www.hipaajournal.com/hipaa-breach-notification-requirements/
- HHS OCR, "Fact Sheet: Ransomware and HIPAA": https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html
- NIST SP 800-88, "Guidelines for Media Sanitization" (encryption/destruction guidance for rendering PHI unusable)
About This Template
These templates cover the everyday paperwork that happens between patients, providers, and health plans: consent forms, medical record authorizations, directives for end-of-life care, and requests to approve or deny treatment. Getting them right matters because they document medical decisions, release sensitive health information, and often have to meet both federal privacy rules and state-specific requirements. A form that is missing a required disclosure can be rejected by a provider or challenged later in court.
Important Notice
This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Last updated: March 2026
Get your HIPAA Breach Log Template, done and ready to use
Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.