A suspected data breach can be one of the most stressful situations a dental practice faces. The worst response is to panic. The second-worst response is to start deleting evidence or randomly changing systems before the incident has been investigated.
Technical containment and HIPAA breach determination are related but separate tasks.
The first three steps happen before any notification decision is made.
Stop the incident from continuing: disconnect an affected computer, disable compromised accounts, block malicious network traffic, remove an affected device from the network, or contact your IT and security provider.
Do not destroy potentially useful evidence.
Establish what system was affected, what information was involved, when the incident occurred, who had unauthorized access, whether information was actually accessed or exfiltrated, and whether the threat is still active.
HHS explains that breach evaluation includes factors such as the nature of the PHI, who accessed it, whether it was actually acquired or viewed, and what mitigation occurred.
Not every cybersecurity incident automatically equals a reportable HIPAA breach.
Determine whether protected health information was involved and whether the information was unsecured.
Once the facts are established, HIPAA’s own process determines what happens next.
HHS states that an impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI was compromised.
That assessment needs to be documented.
Depending on the circumstances, notification obligations can involve affected individuals, HHS, media outlets in certain large breaches, and the covered entity when the incident occurs at a business associate.
HIPAA requires individual notification without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI, and for large breaches, HHS notification also has a 60-day requirement.
That does not mean a practice should wait 60 days. It is the federal outer limit in the circumstances described by HHS.
Maintain documentation showing what happened, what was investigated, what systems were affected, what PHI was involved, what risk assessment was performed, why notification was or was not required, what mitigation occurred, and what corrective actions were implemented.
Dental offices may exchange information with specialists, hospitals, labs, imaging providers, and other healthcare organizations. Your incident response plan should identify vendors and business associates that may need to participate in an investigation.
Keep a printable copy with your incident response plan.
Reference checklist for Tampa Bay dental practices.
Ekim IT Solutions serves Tampa Bay from our office at 600 N Westshore Blvd, Suite 701. We walk you through the right response steps, preserve the evidence that matters, and handle the notification timeline so nothing gets made worse in the panic.