Skip to main content
Breach Notification Under Fire: Build Your 60-Day Response PlanBreach Notification
5 min readFor IT Security Leads

Breach Notification Under Fire: Build Your 60-Day Response Plan

When Tift Regional Health System notified 180,142 patients about a data breach in August 2023, the attack had happened nearly a year earlier. That delay became a core allegation in the class action lawsuit that cost the organization $1.2 million to settle, plus $4.5 million in remediation. For IT security leads, the message is clear: your incident response clock starts the moment you detect suspicious activity, not when you finish your investigation.

The Breach Notification Rule gives covered entities 60 days from discovery to notify affected individuals. Miss that window, and you're not just facing regulatory penalties from OCR. You're creating legal exposure that plaintiffs' attorneys will exploit in civil litigation.

The Problem: Discovery Doesn't Mean "Fully Investigated"

Here's where most security teams get tripped up. You discover suspicious activity on August 16. Your forensic team confirms unauthorized access occurred between August 11 and August 17. You know Protected Health Information (PHI) was in the compromised systems. That's discovery under the Breach Notification Rule, and your 60-day clock just started.

You can't pause that clock while you:

  • Complete a full forensic analysis
  • Determine exactly which files were accessed
  • Rebuild systems
  • Negotiate with law enforcement about disclosure timing

The notification deadline runs from when you knew or should have known that a breach occurred. If you've confirmed unauthorized access to systems containing PHI, you've discovered a breach.

What You Need Before Starting

Build these assets now, before an incident:

Notification templates: Cover all three scenarios (individual notification, media notification, OCR notification). Include merge fields for incident-specific details but lock in your legal review on the static portions.

Contact data governance: Know where your current patient contact information lives and how quickly you can extract it. If you're relying on an EHR vendor's notification service, test the export process quarterly.

Forensic retainer: Have a digital forensics firm under contract with pre-negotiated rates and response SLAs. Waiting until you're breached to find a firm costs you days you don't have.

Decision tree: Document who has authority to declare a breach, who approves notification content, and who signs off on OCR submission. Map the approval chain for normal business hours and after-hours incidents.

Budget authorization: Get pre-approval for breach notification costs up to a defined threshold. Mailing 100,000 letters costs roughly $60,000 to $80,000. You can't wait for a board meeting to authorize that spend.

Step-by-Step Implementation

Days 1-3: Containment and Initial Assessment

Isolate affected systems but preserve forensic evidence. Your first priority is stopping ongoing exfiltration, not determining the full scope.

Document your discovery timeline in writing. Note the date and time you first detected suspicious activity, when you confirmed unauthorized access, and when you verified PHI was in the affected systems. These timestamps will matter if OCR or plaintiffs' counsel scrutinizes your response.

Engage your forensic firm immediately. Their initial assessment should answer: (1) Was there unauthorized access? (2) Were systems containing PHI affected? (3) Is there evidence of exfiltration? You need those answers within 72 hours to make notification decisions.

Days 4-10: Scope Determination

Your forensic team should provide a preliminary scope estimate. You won't have perfect information, but you need enough to start building notification lists. If the investigation shows unauthorized access to a database containing 200,000 patient records, plan to notify 200,000 patients unless you have specific evidence limiting the exposure.

Pull contact information for affected individuals. Verify mailing addresses against USPS National Change of Address data if you're using postal mail. For email notification (only permissible if patients previously agreed to electronic communication), scrub your list against bounce records.

Draft your notification content. The Breach Notification Rule requires ten specific elements in individual notifications. Don't get creative with the format; use the model notice language from HHS and customize only the incident-specific details.

Days 11-30: Legal and Regulatory Coordination

If your breach affects 500 or more individuals, you'll notify OCR and potentially media outlets. Prepare your OCR breach report form in parallel with individual notifications. The data elements overlap, so you're not duplicating work.

For breaches affecting 500 or more residents of a state, you must notify prominent media outlets in that state. Identify which outlets qualify as "prominent" in your service area now. It's typically the major newspaper and TV stations, but document your rationale.

Review your notification content with legal counsel. They should verify you're not admitting liability while still meeting the rule's requirements for describing what happened and what you're doing about it.

Days 31-60: Execute Notification

Mail individual notifications by certified mail if you're offering identity theft services or cash settlements (as Tift Regional Health did). First-class mail is acceptable for standard breach notifications, but proof of mailing matters if you face litigation.

Submit your breach report to OCR through their web portal on the same day you mail individual notifications. Don't submit early; the rule ties OCR notification to individual notification timing.

Issue media notification if required. A press release to wire services and direct notification to local outlets satisfies this requirement. Post the same content on your website's homepage for at least 90 days.

Validation: How to Verify It Works

Track three metrics:

Notification delivery rate: Aim for under 5% returned mail. Higher return rates suggest your contact data needs work.

Timeline compliance: Your OCR breach report timestamp should fall within 60 days of your documented discovery date. If it doesn't, you've missed the deadline.

Content completeness: Every notification should include all ten required elements from 45 CFR § 164.404(c). Audit a sample before bulk mailing.

Maintenance and Ongoing Tasks

Quarterly contact data audits: Verify you can extract current mailing addresses for your full patient population within 48 hours. Test the process, don't assume it works.

Annual template updates: Review your notification templates against current HHS guidance. OCR occasionally updates model notice language.

Tabletop exercises twice yearly: Walk through a breach scenario with your response team. Focus on decision points and timeline management, not just technical containment.

Vendor notification clauses: Ensure your Business Associate Agreements require your vendors to notify you of breaches within 10 days of discovery. You can't meet your 60-day obligation if your vendor sits on a breach for 45 days before telling you.

The Tift Regional Health System settlement shows that notification timing isn't just a regulatory checkbox. It's evidence in civil litigation. Build your 60-day response plan now, when you have time to think clearly. You won't have that luxury when you're staring at ransomware on your screens at 2 AM.

You Might Also Like