...

Ekim IT Solutions

Blog / Dental Data Breach Notification Steps for Tampa Bay Practices
All Dental

Dental Data Breach Notification Steps for Tampa Bay Practices

Illustration showing a folder with a warning icon and an alert bell connecting to the Tampa Bay skyline representing data breach notification steps for Tampa Bay dental practices.

A suspected data breach can be one of the most stressful situations a dental practice faces. The worst response is to panic. The second-worst response is to start deleting evidence or randomly changing systems before the incident has been investigated.

Containment and Compliance Are Different Jobs

Technical containment and HIPAA breach determination are related but separate tasks.

Not sure your practice could contain a breach and preserve evidence properly? Find out in 15 minutes if you’re truly prepared.
Schedule a Discovery Call →

The Immediate Response: Steps 1 Through 3

The first three steps happen before any notification decision is made.

1
Step 1: Contain the Incident

Stop the incident from continuing: disconnect an affected computer, disable compromised accounts, block malicious network traffic, remove an affected device from the network, or contact your IT and security provider.

Do not destroy potentially useful evidence.

2
Step 2: Determine What Happened

Establish what system was affected, what information was involved, when the incident occurred, who had unauthorized access, whether information was actually accessed or exfiltrated, and whether the threat is still active.

HHS explains that breach evaluation includes factors such as the nature of the PHI, who accessed it, whether it was actually acquired or viewed, and what mitigation occurred.

3
Step 3: Determine Whether PHI Was Involved

Not every cybersecurity incident automatically equals a reportable HIPAA breach.

Determine whether protected health information was involved and whether the information was unsecured.

The Compliance Determination: Steps 4 Through 6

Once the facts are established, HIPAA’s own process determines what happens next.

4
Step 4: Conduct the Required Risk Assessment

HHS states that an impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI was compromised.

That assessment needs to be documented.

5
Step 5: Determine Who Must Be Notified

Depending on the circumstances, notification obligations can involve affected individuals, HHS, media outlets in certain large breaches, and the covered entity when the incident occurs at a business associate.

6
Step 6: Watch the 60-Day Deadline

HIPAA requires individual notification without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI, and for large breaches, HHS notification also has a 60-day requirement.

That does not mean a practice should wait 60 days. It is the federal outer limit in the circumstances described by HHS.

Step 7: Document Everything

Maintain documentation showing what happened, what was investigated, what systems were affected, what PHI was involved, what risk assessment was performed, why notification was or was not required, what mitigation occurred, and what corrective actions were implemented.

Tampa Bay Practices Have Additional Coordination Considerations

Dental offices may exchange information with specialists, hospitals, labs, imaging providers, and other healthcare organizations. Your incident response plan should identify vendors and business associates that may need to participate in an investigation.

Incident Response Sequence

Keep a printable copy with your incident response plan.

  1. Contain the incident.
  2. Preserve evidence.
  3. Determine what systems and PHI were involved.
  4. Perform the required risk assessment.
  5. Determine notification obligations.
  6. Document the investigation and corrective actions.
Print This Checklist

Dental Data Breach Incident Response Sequence

Reference checklist for Tampa Bay dental practices.

  1. Contain the incident.
  2. Preserve evidence.
  3. Determine what systems and PHI were involved.
  4. Perform the required risk assessment.
  5. Determine notification obligations.
  6. Document the investigation and corrective actions.

Frequently Asked Questions

Not necessarily. HIPAA’s breach determination depends on the facts, including whether unsecured PHI was involved and whether an applicable exception or low-probability-of-compromise determination applies.
For a reportable breach of unsecured PHI, individual notification must generally occur without unreasonable delay and no later than 60 days after discovery.
HHS treats ransomware as a security incident and it may also constitute a breach depending on the circumstances. A documented investigation and risk assessment are essential.
Facing a suspected breach and not sure what to do in the first hour?

Ekim IT Solutions serves Tampa Bay from our office at 600 N Westshore Blvd, Suite 701. We walk you through the right response steps, preserve the evidence that matters, and handle the notification timeline so nothing gets made worse in the panic.

Calm, correct steps when a breach is suspected.
Get breach response support →