HIPAA Breach Log Template

Ready to Edit

HIPAA BREACH LOG AND INCIDENT TRACKING SYSTEM

INSTRUCTIONS FOR USE

This Breach Log Template is designed for HIPAA covered entities and business associates to document, track, and manage breaches of unsecured protected health information (PHI) as required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400-414). The log also supports documentation obligations under 45 C.F.R. § 164.530(j), which requires retention of all records related to HIPAA compliance for a minimum of six (6) years from the date of creation or the date the document was last in effect, whichever is later.

Privacy Officer or Designee: [________________________________]

Organization Name: [________________________________]

Organization Address: [________________________________]

Log Maintained Since: [__/__/____]

Key Definitions

Breach (45 C.F.R. § 164.402): The acquisition, access, use, or disclosure of protected health information in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the protected health information. A breach is presumed unless the covered entity or business associate demonstrates through a documented risk assessment that there is a low probability the PHI has been compromised.

Security Incident (45 C.F.R. § 164.304): The attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. Not all security incidents constitute breaches; however, all security incidents must be evaluated to determine whether a breach has occurred.

Unsecured PHI (45 C.F.R. § 164.402): Protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by HHS guidance (i.e., encryption meeting NIST standards or destruction per NIST SP 800-88).

Breach vs. Security Incident — Critical Distinction

Factor Security Incident Breach
Definition Attempted or successful unauthorized access, use, disclosure, modification, or destruction of information in an information system Impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy
Regulatory Citation 45 C.F.R. § 164.304 45 C.F.R. § 164.402
Scope All electronic information systems PHI only
Notification Required Internal documentation only Individual, HHS, and potentially media notification
Response Obligation Identify, respond, mitigate, document (§ 164.308(a)(6)) Full breach notification and risk assessment
Presumption No presumption Presumed breach unless risk assessment demonstrates low probability of compromise

SECTION 1: BREACH INCIDENT LOG ENTRIES

INCIDENT ENTRY NO. [____]

1.1 Incident Identification

Field Entry
Incident ID Number [________________________________]
Date of Breach/Incident [__/__/____]
Date Breach Discovered [__/__/____]
Date Reported Internally [__/__/____]
Reported By (Name/Title) [________________________________]
Privacy Officer Notified ☐ Yes ☐ No — Date: [__/__/____]
Security Officer Notified ☐ Yes ☐ No — Date: [__/__/____]
Legal Counsel Notified ☐ Yes ☐ No — Date: [__/__/____]

1.2 Incident Classification

Type of Incident (check all that apply):

☐ Hacking/IT incident (ransomware, malware, phishing, network intrusion)
☐ Unauthorized access by workforce member
☐ Unauthorized access by third party
☐ Unauthorized disclosure — verbal
☐ Unauthorized disclosure — written/electronic
☐ Lost or stolen laptop/computer
☐ Lost or stolen portable electronic device (USB, phone, tablet)
☐ Lost or stolen paper records
☐ Mailing error (sent to wrong recipient)
☐ Fax error (sent to wrong number)
☐ Email error (sent to wrong recipient)
☐ Improper disposal of PHI (paper or electronic)
☐ Business associate breach
☐ EHR/system misconfiguration
☐ Patient portal access error
☐ Other: [________________________________]

1.3 Detailed Description of Incident

Narrative Description (what happened, how it was discovered, who was involved):

[________________________________]
[________________________________]
[________________________________]
[________________________________]
[________________________________]

1.4 PHI Types Involved

Check all categories of PHI involved in the incident:

☐ Patient name
☐ Date of birth
☐ Social Security number
☐ Address/geographic data
☐ Phone/fax number
☐ Email address
☐ Medical record number
☐ Health plan beneficiary number
☐ Account number
☐ Diagnosis/clinical information
☐ Treatment information
☐ Medications
☐ Lab results
☐ Mental health records
☐ Substance use disorder records (42 C.F.R. Part 2)
☐ HIV/AIDS status
☐ Genetic information (GINA)
☐ Sexual/reproductive health information
☐ Financial/billing information
☐ Insurance information
☐ Photographs/images
☐ Biometric identifiers
☐ Other: [________________________________]

1.5 Individuals Affected

Field Entry
Estimated Number of Individuals Affected [____]
Final Confirmed Number [____]
States/Jurisdictions Where Affected Individuals Reside [________________________________]
Any State Exceeding 500 Individuals? ☐ Yes — State(s): [____] ☐ No

1.6 Systems/Media Affected

☐ Electronic health record (EHR) system — Name: [________________________________]
☐ Email system
☐ Desktop computer(s) — Location: [________________________________]
☐ Laptop(s) — Asset ID: [________________________________]
☐ Server(s) — Name: [________________________________]
☐ Mobile device(s) — Type: [________________________________]
☐ Portable media (USB, external drive)
☐ Paper records
☐ Cloud-based system — Provider: [________________________________]
☐ Fax machine
☐ Copier/scanner
☐ Backup media
☐ Other: [________________________________]

Was the PHI encrypted at the time of the incident? ☐ Yes ☐ No
If yes, specify encryption standard: [________________________________]
Was the encryption key compromised? ☐ Yes ☐ No ☐ Unknown


SECTION 2: FOUR-FACTOR RISK ASSESSMENT

Per 45 C.F.R. § 164.402(2), a breach is presumed unless the covered entity or business associate demonstrates through a risk assessment that there is a low probability the PHI has been compromised. The following four factors must be assessed and documented:

Factor 1: Nature and Extent of the PHI Involved

Evaluate the types of identifiers and the likelihood of re-identification.

Assessment Element Analysis
Types of identifiers exposed [________________________________]
Sensitivity level of clinical information ☐ High ☐ Medium ☐ Low
Financial information included ☐ Yes ☐ No
SSN or government ID included ☐ Yes ☐ No
Likelihood of re-identification ☐ High ☐ Medium ☐ Low
Combination risk (multiple data elements) [________________________________]

Risk Level for Factor 1: ☐ High ☐ Medium ☐ Low

Narrative Analysis: [________________________________]
[________________________________]

Factor 2: The Unauthorized Person Who Used or Received the PHI

Evaluate the identity and characteristics of the unauthorized recipient.

Assessment Element Analysis
Identity of unauthorized recipient [________________________________]
Is the recipient a covered entity or BA? ☐ Yes ☐ No ☐ Unknown
Is the recipient a workforce member? ☐ Yes ☐ No
Does recipient have independent HIPAA obligations? ☐ Yes ☐ No ☐ Unknown
Was recipient known or unknown? ☐ Known ☐ Unknown
Likelihood recipient will misuse the PHI [________________________________]

Risk Level for Factor 2: ☐ High ☐ Medium ☐ Low

Narrative Analysis: [________________________________]
[________________________________]

Factor 3: Whether the PHI Was Actually Acquired or Viewed

Evaluate whether the information was actually accessed or only potentially exposed.

Assessment Element Analysis
Was PHI actually viewed or accessed? ☐ Confirmed viewed ☐ Believed viewed ☐ Opportunity to view but no evidence of actual viewing ☐ Unknown
Evidence of access (audit logs, forensic analysis) [________________________________]
Was any PHI downloaded, copied, or retained? ☐ Yes ☐ No ☐ Unknown
Duration of unauthorized access [________________________________]

Risk Level for Factor 3: ☐ High ☐ Medium ☐ Low

Narrative Analysis: [________________________________]
[________________________________]

Factor 4: Extent to Which Risk Has Been Mitigated

Evaluate steps taken to reduce the risk of harm.

Assessment Element Analysis
Were records recovered? ☐ Yes — Date: [__/__/____] ☐ No ☐ N/A
Recipient provided assurances of destruction? ☐ Yes — Date: [__/__/____] ☐ No
Recipient signed confidentiality agreement? ☐ Yes ☐ No ☐ N/A
Technical controls applied (password reset, access revocation) [________________________________]
Forensic investigation conducted? ☐ Yes ☐ No
Other mitigation steps [________________________________]

Risk Level for Factor 4: ☐ High ☐ Medium ☐ Low

Narrative Analysis: [________________________________]
[________________________________]

Overall Risk Assessment Determination

Overall Probability PHI Was Compromised ☐ Low Probability — Not a reportable breach ☐ Greater than Low Probability — Reportable breach

Determination Made By: [________________________________]
Title: [________________________________]
Date of Determination: [__/__/____]

Note: If the covered entity is unable to demonstrate a low probability of compromise, the incident must be treated as a breach and notification obligations apply. The burden of proof rests with the covered entity or business associate (45 C.F.R. § 164.414(b)).


SECTION 3: CONTAINMENT AND REMEDIATION ACTIONS

3.1 Immediate Containment Actions

Action Completed Date Responsible Party
System access revoked/password changed ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Affected device secured/isolated ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Physical records recovered/secured ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Network/system vulnerability patched ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Remote wipe of device initiated ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Law enforcement contacted ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Forensic investigation initiated ☐ Yes ☐ No ☐ N/A [__/__/____] [________________]
Other: [________________] ☐ Yes ☐ No [__/__/____] [________________]

3.2 Root Cause Analysis

Element Finding
Root cause category ☐ Human error ☐ System failure ☐ Criminal/malicious act ☐ Process failure ☐ Third-party failure ☐ Natural disaster ☐ Unknown
Detailed root cause description [________________________________]
Contributing factors [________________________________]
Existing controls that failed [________________________________]
Was this a repeat occurrence? ☐ Yes — Reference prior incident ID: [____] ☐ No

3.3 Corrective Actions / Remediation Plan

Corrective Action Responsible Party Target Date Completion Date Status
[________________________________] [________________] [__/__/____] [__/__/____] ☐ Open ☐ In Progress ☐ Complete
[________________________________] [________________] [__/__/____] [__/__/____] ☐ Open ☐ In Progress ☐ Complete
[________________________________] [________________] [__/__/____] [__/__/____] ☐ Open ☐ In Progress ☐ Complete
[________________________________] [________________] [__/__/____] [__/__/____] ☐ Open ☐ In Progress ☐ Complete
[________________________________] [________________] [__/__/____] [__/__/____] ☐ Open ☐ In Progress ☐ Complete

SECTION 4: NOTIFICATION STATUS TRACKING

4.1 Individual Notification (45 C.F.R. § 164.404)

Notification to affected individuals must be made without unreasonable delay and no later than 60 calendar days from the date of discovery of the breach.

Field Entry
60-Day Deadline [__/__/____]
Method of notification ☐ First-class mail ☐ Email (if individual previously agreed) ☐ Substitute notice (insufficient contact info for 10+ individuals) ☐ Urgent notification by phone (imminent misuse)
Date individual notification letters sent [__/__/____]
Number of individuals notified [____]
Notification letter approved by [________________________________]
Return mail/undeliverable notices [____]
Substitute notice posted on website ☐ Yes — URL: [________________________________] ☐ No ☐ N/A
Toll-free number activated (if substitute notice) ☐ Yes — Number: [________________] ☐ No ☐ N/A

Required Content of Individual Notification (45 C.F.R. § 164.404(c)):
☐ Brief description of what happened, including date of breach and date of discovery
☐ Description of types of unsecured PHI involved
☐ Steps individuals should take to protect themselves
☐ Brief description of what covered entity is doing to investigate, mitigate harm, and prevent future breaches
☐ Contact procedures (toll-free number, email, website, postal address)

4.2 HHS/OCR Notification (45 C.F.R. § 164.408)

Field Entry
Total individuals affected [____]
Breach involves 500+ individuals? ☐ Yes ☐ No
If 500+ individuals: Notification to HHS due no later than 60 days from discovery [__/__/____]
Date HHS notified via breach portal [__/__/____]
If fewer than 500 individuals: Annual log submitted to HHS Due within 60 days of end of calendar year
Date added to annual breach log for HHS [__/__/____]
HHS case number (if assigned) [________________________________]

4.3 Media Notification (45 C.F.R. § 164.406)

Required only when breach affects 500 or more individuals in a single state or jurisdiction.

Field Entry
Media notification required? ☐ Yes ☐ No
State(s) requiring media notification [________________________________]
Date media notice issued [__/__/____]
Media outlets contacted [________________________________]
Method of media notification ☐ Press release ☐ Direct media contact ☐ Other: [________________]

4.4 State Attorney General / Regulatory Notification

Many states require separate breach notification to the state attorney general or other regulatory bodies, often with shorter timelines.

State AG Notification Required Deadline Date Notified Confirmation/Reference
[____] ☐ Yes ☐ No [__/__/____] [__/__/____] [________________]
[____] ☐ Yes ☐ No [__/__/____] [__/__/____] [________________]
[____] ☐ Yes ☐ No [__/__/____] [__/__/____] [________________]

State-Specific Notification Deadlines (Selected):

  • California (Cal. Civ. Code § 1798.82): Notification to AG if 500+ CA residents affected; "expedient" notification to individuals
  • Texas (Tex. Bus. & Com. Code § 521.053): Notification within 60 days; AG notification if 250+ TX residents
  • Florida (Fla. Stat. § 501.171): Notification within 30 days; AG notification if 500+ FL residents
  • New York (N.Y. Gen. Bus. Law § 899-aa; SHIELD Act): Notification "in the most expedient time possible"; AG, DFS, and Division of State Police notification required

4.5 Business Associate Breach Reporting (45 C.F.R. § 164.410)

Field Entry
Did breach originate with a business associate? ☐ Yes ☐ No
Business associate name [________________________________]
Date BA discovered breach [__/__/____]
Date BA notified covered entity [__/__/____]
Was notification within 60 days (or shorter if specified in BAA)? ☐ Yes ☐ No
BAA notification deadline per agreement [____] days
Information provided by BA ☐ Identity of individuals affected ☐ Description of breach ☐ Types of PHI ☐ Other: [________________]

4.6 Law Enforcement Delay (45 C.F.R. § 164.412)

Field Entry
Law enforcement requested delay of notification? ☐ Yes ☐ No
Law enforcement agency [________________________________]
Written statement received? ☐ Yes — Date: [__/__/____] ☐ Oral request — Date: [__/__/____]
Duration of delay requested [____] days (max 30 days for oral; as specified for written)
Date delay expired [__/__/____]
Notification resumed ☐ Yes — Date: [__/__/____]

SECTION 5: ANNUAL BREACH SUMMARY REPORT

This section supports the annual compilation and review of all breach incidents. Complete at the end of each calendar year.

Reporting Period: [__/__/____] to [__/__/____]

Prepared By: [________________________________]

Date Prepared: [__/__/____]

5.1 Annual Summary Statistics

Metric Count
Total security incidents reported [____]
Total incidents determined to be breaches [____]
Total incidents determined NOT to be breaches (low probability per risk assessment) [____]
Total individuals affected (all breaches combined) [____]
Breaches reported to HHS (500+ individuals) [____]
Breaches included in annual HHS log (<500 individuals) [____]
Media notifications issued [____]
State AG notifications issued [____]

5.2 Breach Categories Summary

Category Number of Incidents Percentage
Hacking/IT incident [____] [____]%
Unauthorized access/disclosure [____] [____]%
Lost/stolen device [____] [____]%
Mailing/fax/email error [____] [____]%
Improper disposal [____] [____]%
Business associate breach [____] [____]%
Other [____] [____]%

5.3 Trends and Patterns

Identified Trends: [________________________________]
[________________________________]

Repeat Incident Types: [________________________________]

Departments/Locations with Highest Incident Rates: [________________________________]

5.4 Corrective Action Effectiveness Review

Corrective Action Implemented Effective? Evidence
[________________________________] ☐ Yes ☐ Partially ☐ No [________________________________]
[________________________________] ☐ Yes ☐ Partially ☐ No [________________________________]
[________________________________] ☐ Yes ☐ Partially ☐ No [________________________________]

5.5 Recommendations for Upcoming Year

[________________________________]
[________________________________]
[________________________________]


SECTION 6: SAMPLE LOG ENTRIES — REFERENCE EXAMPLES

The following examples illustrate how to document different breach types. These are for reference only and should not be submitted as actual incidents.

Example A: Hacking/Ransomware Incident

Field Example Entry
Incident ID 2026-001
Date of Breach 01/15/2026
Date Discovered 01/16/2026
Classification Hacking/IT incident — ransomware
Description Ransomware encrypted EHR database server. Forensic analysis confirmed unauthorized access to patient records database containing demographic, clinical, and insurance information for approximately 12,500 patients. Attacker gained access through phishing email to administrative staff member.
PHI Types Names, DOB, SSN, diagnosis, treatment, insurance
Individuals Affected 12,500
Risk Assessment Result High probability of compromise — reportable breach
Notifications Individual (mail), HHS (portal), media (press release to 3 state outlets), state AG (CA, TX)

Example B: Unauthorized Access by Workforce Member

Field Example Entry
Incident ID 2026-002
Date of Breach 02/03/2026
Date Discovered 02/10/2026
Classification Unauthorized access — workforce member
Description Registration clerk accessed medical records of a co-worker and disclosed diagnosis information to other staff members. Discovered through routine audit log review.
PHI Types Name, diagnosis, treatment information
Individuals Affected 1
Risk Assessment Result Greater than low probability — reportable breach
Notifications Individual (letter), HHS annual log

Example C: Mailing Error

Field Example Entry
Incident ID 2026-003
Date of Breach 03/01/2026
Date Discovered 03/05/2026
Classification Mailing error
Description Explanation of Benefits statements for 45 patients mailed to incorrect addresses due to mail merge error in billing system. Unintended recipients were other patients of the practice.
PHI Types Names, dates of service, procedure codes, billing amounts
Individuals Affected 45
Risk Assessment Result Low probability of compromise — recipients are HIPAA-covered patients with confidentiality obligations; letters recovered
Notifications None required (documented risk assessment on file)

Example D: Lost/Stolen Device

Field Example Entry
Incident ID 2026-004
Date of Breach 04/12/2026
Date Discovered 04/12/2026
Classification Lost/stolen portable device
Description Physician's unencrypted laptop stolen from locked vehicle. Laptop contained patient scheduling information and clinical notes for approximately 300 patients.
PHI Types Names, DOB, appointment dates, clinical notes
Individuals Affected 300
Risk Assessment Result Greater than low probability — device unencrypted, PHI unsecured
Notifications Individual (letter), HHS annual log, police report filed

Example E: Verbal Disclosure

Field Example Entry
Incident ID 2026-005
Date of Breach 05/20/2026
Date Discovered 05/20/2026
Classification Unauthorized disclosure — verbal
Description Nurse discussed patient's HIV status in hospital elevator within earshot of visitors. Reported by charge nurse who overheard the conversation.
PHI Types Name, HIV status
Individuals Affected 1
Risk Assessment Result Greater than low probability — sensitive diagnosis, visitors present
Notifications Individual (letter), HHS annual log

SECTION 7: OCR AUDIT PREPAREDNESS DOCUMENTATION

7.1 Documentation Retention Checklist

Per 45 C.F.R. § 164.530(j), the following documentation must be retained for a minimum of six (6) years:

☐ This breach log and all incident entries
☐ Risk assessment documentation for each incident
☐ Notification letters (copies)
☐ HHS breach portal submission confirmations
☐ Media notifications (copies)
☐ State AG notifications (copies)
☐ Business associate breach notifications received
☐ Law enforcement delay requests and correspondence
☐ Corrective action plans and completion documentation
☐ Root cause analysis documentation
☐ Sanctions applied to workforce members (if any)
☐ Training records related to breach incidents
☐ Policies and procedures related to breach notification
☐ Annual breach summary reports

7.2 Audit Response Preparation

Element Location/Status
Breach notification policies and procedures [________________________________]
Current risk analysis [________________________________]
Encryption documentation/inventory [________________________________]
Business associate agreements (relevant) [________________________________]
Workforce training records [________________________________]
Sanctions policy and records [________________________________]
Designated privacy officer documentation [________________________________]
Designated security officer documentation [________________________________]

SECTION 8: LOG MAINTENANCE INSTRUCTIONS

  1. Assign Incident IDs sequentially using the format YYYY-NNN (e.g., 2026-001, 2026-002).

  2. Record Entries Promptly. Begin a log entry as soon as an incident is reported. Update the entry as the investigation progresses. Under 45 C.F.R. § 164.404(a)(2), the date of discovery is the first day the breach is known or would have been known by exercising reasonable diligence.

  3. Complete the Four-Factor Risk Assessment for every incident involving an impermissible use or disclosure of PHI. Document the assessment even if the determination is that the incident does not constitute a breach.

  4. Track All Deadlines. The 60-day notification clock begins on the date of discovery, not the date of the breach itself. Calendar all notification deadlines immediately upon discovery.

  5. Coordinate with Legal Counsel. Engage legal counsel early in the breach assessment process. Consider conducting the risk assessment under attorney-client privilege when appropriate.

  6. Retain for Six Years Minimum. Per 45 C.F.R. § 164.530(j), all documentation must be retained for at least six years. Many states require longer retention. Establish a retention schedule that meets the most stringent applicable requirement.

  7. Review Annually. Conduct an annual review of the breach log to identify trends, evaluate corrective action effectiveness, and update policies and procedures as necessary.

  8. Secure the Log. This log contains sensitive information about security vulnerabilities and breaches. Store it securely with access limited to the Privacy Officer, Security Officer, legal counsel, and authorized compliance personnel.

  9. Coordinate State Requirements. Many states have breach notification laws with shorter timelines or additional requirements. Consult the state-specific notification deadlines in Section 4.4 and review applicable state law for each incident.

  10. Annual HHS Reporting. For breaches affecting fewer than 500 individuals, compile and submit the annual breach log to HHS within 60 days after the end of the calendar year in which the breaches were discovered (45 C.F.R. § 164.408(c)).


Sources and References

  • U.S. Department of Health and Human Services, "Breach Notification Rule": https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  • 45 C.F.R. Part 164, Subpart D — Notification in the Case of Breach of Unsecured PHI: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D
  • HHS OCR, "How OCR Enforces the HIPAA Privacy & Security Rules": https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/examples/how-ocr-enforces-the-hipaa-privacy-and-security-rules/index.html
  • 45 C.F.R. § 164.402 — Definitions (Breach, Unsecured PHI): https://www.law.cornell.edu/cfr/text/45/164.402
  • 45 C.F.R. § 164.530 — Administrative Requirements (Documentation and Retention): https://www.law.cornell.edu/cfr/text/45/164.530
  • HIPAA Journal, "HIPAA Breach Notification Requirements — Updated 2026": https://www.hipaajournal.com/hipaa-breach-notification-requirements/
  • HHS OCR, "Fact Sheet: Ransomware and HIPAA": https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html
  • NIST SP 800-88, "Guidelines for Media Sanitization" (encryption/destruction guidance for rendering PHI unusable)
Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?
AI Legal Assistant
Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?

Insert Image

Insert Table

Watch Ezel in action (sample case)

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
hipaa_breach_log_template_universal.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Get your finished document

Filled in for your situation. Drafting from scratch takes hours; finish yours in about 5 minutes for $99 one time.

  • Deep Legal Knowledge
    Understands case law, statutes, and legal doctrine.
  • Court-Ready Formatting
    Proper captions and local-rule compliance.
  • AI-Powered Editing
    Tailor every section to your case.
  • Export as PDF & Word
    Ready to file or send.
Secure checkout via Stripe
Need to customize this document?

About This Template

These templates cover the everyday paperwork that happens between patients, providers, and health plans: consent forms, medical record authorizations, directives for end-of-life care, and requests to approve or deny treatment. Getting them right matters because they document medical decisions, release sensitive health information, and often have to meet both federal privacy rules and state-specific requirements. A form that is missing a required disclosure can be rejected by a provider or challenged later in court.

Important Notice

This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Last updated: March 2026

Get your HIPAA Breach Log Template, done and ready to use

Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.