Skip to main content
Email Breach Response Checklist for Privacy OfficersBreach Notification
6 min readFor Privacy Officers

Email Breach Response Checklist for Privacy Officers

DAP Health's $1.3 million settlement following a 2024 email server breach affecting 129,048 individuals highlights a harsh reality for nonprofit healthcare organizations: breach response costs often far exceed prevention expenses. If your organization faces unauthorized access to email systems containing PHI, you need a structured response plan to address immediate containment and long-term legal exposure.

This checklist guides you through managing an email-related PHI breach, from initial detection to settlement considerations. It's designed for Privacy Officers who must coordinate technical, legal, and notification tasks under time constraints.

Purpose of This Checklist

Use this checklist when you've confirmed or suspect unauthorized access to email systems containing PHI. It covers:

  • Immediate containment and forensic preservation
  • Breach risk assessment under the Breach Notification Rule
  • State-specific notification requirements (California example included)
  • Documentation for potential class action defense
  • Post-incident security improvements

While this isn't a substitute for legal counsel, it ensures you meet regulatory deadlines and preserve evidence while assembling your response team.

Prerequisites

Before using this checklist, ensure:

  • Incident confirmation: Your IT team has identified suspicious activity or unauthorized access to email systems.
  • Initial scope estimate: You have a rough idea of which email accounts or servers were accessed, even if data exfiltration details are unclear.
  • Response team identified: You have contact information for your breach counsel, forensic vendor, and executive decision-makers.
  • Business Associate Agreements on file: If a Business Associate manages email hosting, you have current BAAs and their incident response contacts.

The Checklist

Phase 1: Containment and Forensics (Days 0-3)

Immediate Actions

  • Isolate affected email servers or accounts to prevent further access.
  • Preserve all logs: email server logs, authentication logs, firewall logs, endpoint detection logs.
  • Engage a forensic vendor to image affected systems before any remediation.
  • Document the timeline: when suspicious activity was first detected, when access was confirmed, who was notified.
  • If a Business Associate manages your email, notify them per your BAA and request their incident response documentation.

Evidence Collection

  • Capture screenshots of any alerts, unauthorized login attempts, or anomalous activity.
  • Export a list of all email accounts on the affected server.
  • Identify folders or mailboxes containing PHI (clinical correspondence, billing records, patient lists).
  • Document security controls in place: multi-factor authentication status, encryption, access logging.

Phase 2: Risk Assessment (Days 3-10)

Breach Determination

  • Apply the four-factor risk assessment under 45 CFR § 164.402:
    • Nature and extent of PHI involved (names, SSNs, diagnoses, treatment records).
    • Identity of the unauthorized person who accessed PHI.
    • Whether PHI was actually acquired or viewed.
    • Extent to which risk has been mitigated.
  • Document your risk assessment in writing, even if you conclude no breach occurred.
  • If you determine this isn't a breach under HIPAA, document why (e.g., encrypted data, access logs show no viewing).

Scope Quantification

  • Work with forensics to determine how many individuals' PHI was in accessible files.
  • Identify exposed data elements: SSNs, dates of birth, driver's license numbers, health insurance information, diagnoses, treatment details.
  • Separate counts: HIPAA-regulated PHI vs. additional state-regulated data (e.g., California CMIA covers broader health information).

Phase 3: Notification Planning (Days 10-30)

Regulatory Deadlines

  • If breach affects 500+ individuals: OCR notification required within 60 days of discovery.
  • Individual notifications must begin within 60 days of discovery.
  • Media notice required if breach affects 500+ residents of a state or jurisdiction.
  • Business Associate notification: if you're a Business Associate, notify the Covered Entity without unreasonable delay (and no later than 60 days).

State Law Compliance (California Example)

  • California CMIA requires notification "without unreasonable delay" and no later than required by HIPAA.
  • California also requires notification to the Attorney General if breach affects 500+ California residents.
  • Check if your state has stricter timelines or additional content requirements beyond HIPAA.

Notification Content Preparation

  • Draft individual notification letter including:
    • Brief description of what happened and when you discovered it.
    • Types of PHI involved.
    • Steps individuals should take (credit monitoring, password changes).
    • What your organization is doing to prevent future incidents.
    • Contact information for questions.
  • Arrange credit monitoring or identity theft protection services if SSNs or financial data were exposed.
  • Prepare substitute notice plan if you lack sufficient contact information for affected individuals.

Phase 4: Legal Exposure Management (Days 30-90)

Class Action Preparation

  • Preserve all documents related to:
    • Your cybersecurity policies and procedures before the breach.
    • Security assessments or audits conducted in the prior three years.
    • Budget requests for email security improvements that were approved or denied.
    • Training records for staff with email access to PHI.
  • Document your pre-breach security posture: Was MFA enabled? Was email encrypted? What access controls existed?
  • Coordinate with breach counsel on litigation hold notices for relevant staff.

Settlement Documentation (If Applicable)

  • Track all breach-related costs: forensics, legal fees, notification expenses, credit monitoring.
  • Document remediation steps taken post-breach (new email security tools, policy updates, staff training).
  • If settlement discussions begin, ensure you have cost documentation to support any financial terms.

Phase 5: Post-Incident Improvements (Days 90+)

Technical Remediation

  • Implement MFA on all email accounts with access to PHI.
  • Enable email encryption for messages containing PHI.
  • Deploy email security tools: advanced threat protection, anti-phishing filters, data loss prevention.
  • Review and restrict access: Who actually needs email access to PHI?

Policy and Training Updates

  • Update your Incident Response Plan with lessons learned.
  • Revise email security policies to address identified gaps.
  • Conduct staff training on email phishing recognition and secure PHI handling.
  • Schedule quarterly phishing simulations to test awareness.

Customizing the Checklist

For Small Organizations (Under 50 Staff)

  • Combine Phase 1 and Phase 2 into a single week if you have limited forensic needs.
  • Consider outsourcing notification services rather than managing mailings in-house.
  • Focus post-incident improvements on high-impact, low-cost controls: MFA, phishing training, access restrictions.

For Multi-State Organizations

  • Add a state law matrix to Phase 3: list every state where affected individuals reside and note notification deadlines, Attorney General notification requirements, and content mandates.
  • Assign a team member to track each state's requirements and confirm compliance.

For Business Associates

  • Add a "Covered Entity Notification" step at the beginning of Phase 1 (within 24 hours of discovery).
  • Include BAA review: Does your agreement specify notification timelines or content requirements beyond HIPAA?

For California Organizations

  • Add California Attorney General notification to Phase 3 checklist.
  • Note that California CMIA applies to any entity that "creates, maintains, preserves, stores, or transmits" medical information, which is broader than HIPAA's Covered Entity definition.

Validation Steps

Before Completing Your Response:

  1. Regulatory compliance check: Confirm you've met all notification deadlines (OCR, individuals, media, state AGs). Missing a 60-day deadline can result in penalties even if your breach response was otherwise solid.

  2. Documentation audit: Review your breach file. Do you have written documentation of your risk assessment, forensic findings, notification dates, and remediation steps? This documentation is your defense if OCR investigates or plaintiffs file suit.

  3. Technical verification: Test your new email security controls. Can staff still send unencrypted PHI via email? Can they access email without MFA? If yes, your remediation is incomplete.

  4. Training confirmation: Have all staff with email access to PHI completed updated training? Document completion dates and training content.

  5. Legal review: Have breach counsel review your response for any gaps in notification, documentation, or remediation that could increase liability exposure.

The DAP Health settlement illustrates the consequences of email security gaps leading to unauthorized access: a $1.3 million payout, years of financial recovery, and reputational damage affecting community trust. Use this checklist to ensure your response minimizes both regulatory exposure and the likelihood of costly litigation. Investing in prevention costs less than responding to a breach, but a thorough response is less costly than inadequate measures followed by penalties and settlements.

You Might Also Like