A ransomware attack doesn't end when you restore your systems. DaVita's $15 million settlement following an April 2025 incident that exposed information belonging to nearly 2.4 million people shows how one breach can lead to years of notification, remediation, and litigation costs. The Interlock ransomware group used double extortion, removing data before encrypting systems, turning a technical incident into a long-term compliance crisis.
You need a response checklist that addresses both immediate containment and the legal obligations that follow. This template guides your team through critical actions in the first 72 hours and the weeks that follow.
Purpose of This Checklist
This checklist is for Privacy Officers responding to a confirmed ransomware incident involving potential Protected Health Information (PHI) exposure. It's designed for when you learn that an attacker has accessed your systems, whether through encryption, data exfiltration, or both.
The checklist focuses on compliance obligations under the Breach Notification Rule, documentation requirements, and coordination with legal counsel. It's not a technical remediation guide; your IT security team handles containment and recovery. Your job is to determine whether a breach occurred, who must be notified, and how to document every decision.
Prerequisites
Before using this checklist, confirm:
- You have a confirmed security incident. Your IT team has identified unauthorized access, encryption, or evidence of data removal. Don't wait for complete forensic findings to start this process.
- You know your notification thresholds. Review 45 CFR § 164.404 requirements: notification to individuals, OCR, and potentially media if 500 or more residents of a state or jurisdiction are affected.
- You have access to your risk assessment framework. You'll need to evaluate whether the incident constitutes a breach under the four-factor risk assessment outlined in the Breach Notification Rule.
- Legal counsel is available. Some decisions, particularly around law enforcement delay requests or settlement negotiations, require attorney involvement.
The Checklist
Hour 0-4: Immediate Assessment
☐ Convene your breach response team. Include your Privacy Officer, security lead, legal counsel, and executive sponsor. Establish a communication protocol and designate one person to maintain the incident log.
☐ Document the discovery time and method. Record when you learned of the incident, who reported it, and what triggered the discovery. This timestamp matters for notification deadlines.
☐ Identify affected systems and data types. Work with IT to determine which servers, databases, or applications were accessed. List the PHI elements potentially exposed: names, Social Security numbers, clinical information, insurance details, laboratory results.
☐ Preserve all logs and forensic evidence. Instruct IT to capture system logs, access records, and any attacker communications before systems are wiped or restored from backup.
☐ Request a preliminary scope estimate. How many individuals might be affected? You don't need precision yet, but you need to know if you're looking at 50 people or 50,000.
Hour 4-24: Breach Determination
☐ Apply the four-factor risk assessment. Evaluate: (1) nature and extent of PHI involved, (2) unauthorized person who accessed the PHI, (3) whether PHI was actually acquired or viewed, (4) extent to which risk has been mitigated. Document your analysis for each factor.
☐ Determine if the incident qualifies as a breach. If your assessment shows a low probability that PHI was compromised, document why notification isn't required. If there's any uncertainty, presume breach.
☐ Check for law enforcement delay requests. If FBI or other agencies are investigating, they may request a notification delay. Get this in writing and document the specific timeframe.
☐ Identify the breach date. Under the Breach Notification Rule, this is the date you discovered the incident, not when it occurred. Your 60-day notification clock starts now.
Day 1-10: Notification Planning
☐ Segment your affected population. Separate individuals by state to determine media notification requirements. Create lists for: (a) residents where 500+ are affected in a single state, (b) all other affected individuals, (c) deceased individuals whose next of kin must be notified.
☐ Draft individual notification letters. Include: (1) brief description of what happened, (2) types of PHI involved, (3) steps you're taking in response, (4) what individuals should do, (5) contact information for questions. Avoid technical jargon and defensive language.
☐ Prepare substitute notice if addresses are insufficient. If you lack contact information for 10 or more individuals, plan for substitute notice via website posting and major media in affected areas.
☐ Draft your OCR breach report. Log into the HHS Breach Portal. Prepare to submit within 60 days if 500 or more individuals are affected, or by March 1 of the following year if fewer than 500.
☐ Prepare media notice if required. If 500+ residents of a state or jurisdiction are affected, draft a media release for prominent outlets in that area. This must go out simultaneously with individual notice.
Day 10-30: External Notification
☐ Mail individual notification letters. Send by first-class mail within 60 days of discovery. If you're offering credit monitoring or identity protection services, include enrollment instructions and codes.
☐ Submit OCR breach report. File through the Breach Portal. Include: number affected, brief incident description, types of PHI involved, whether law enforcement delayed notification.
☐ Issue media notice if required. Provide to major print and broadcast outlets in affected states. Include a toll-free number for inquiries.
☐ Post prominent website notice. Even if not required for substitute notice, post information about the incident, what you're doing, and how individuals can get help.
☐ Staff your response line. Ensure trained personnel can answer questions about the breach, enrollment in protective services, and individual rights.
Day 30-90: Documentation and Remediation
☐ Maintain a complete incident file. Include: initial discovery documentation, forensic reports, risk assessment, notification letters, OCR submission confirmation, media releases, call center logs, and all internal communications.
☐ Track notification delivery. Log returned mail and update addresses where possible. Send substitute notice for individuals you cannot reach.
☐ Document remediation steps. Record every security improvement, policy change, training session, and technical control implemented in response. This becomes evidence of good faith if litigation follows.
☐ Prepare for potential litigation. Coordinate with legal counsel on document retention, privilege considerations, and insurance notification. The DaVita settlement came more than a year after discovery; expect a long tail.
☐ Review Business Associate Agreements. If the breach originated with a Business Associate, review your agreement terms regarding indemnification, breach notification obligations, and termination rights.
How to Customize It
Adjust timeframes for your organization size. A 10-hospital system needs more time for notification logistics than a single clinic. Build in buffer time but never exceed the 60-day deadline.
Add state-specific requirements. Some states impose notification obligations beyond HIPAA. Insert checkboxes for state attorney general notifications, shorter deadlines, or specific content requirements.
Incorporate your incident response plan references. Link each checklist item to the relevant section of your existing incident response documentation. This checklist should integrate with, not replace, your technical response procedures.
Tailor the risk assessment factors. The four-factor analysis is required, but you can add organization-specific considerations. For example, if you serve a particularly vulnerable population, document how that affects your breach determination.
Include your escalation criteria. Define when you elevate from your privacy team to executive leadership, when you engage outside counsel, and when you notify your board. The Interlock group's attacks on both DaVita and Kettering Health show that sophisticated actors often target multiple organizations; if peers in your region are hit, your board needs to know.
Validation Steps
After using this checklist during an incident, validate your response:
Confirm timely submission. Check that your OCR breach report shows as received within 60 days of discovery. Late filing invites scrutiny even if the breach itself was handled properly.
Verify notification completeness. Review returned mail logs and substitute notice execution. Can you demonstrate that you made reasonable efforts to reach every affected individual?
Audit your documentation. Could you reconstruct your breach determination six months from now? If OCR investigates, you'll need to show your work on the four-factor risk assessment.
Test your remediation claims. Don't just document that you implemented new controls; validate that they're working. If you told affected individuals you've strengthened encryption, make sure your IT team can prove it.
Review with legal counsel. Have your attorney examine the incident file for privilege issues, litigation exposure, and regulatory risk. The $15 million DaVita settlement and similar cases show that plaintiff firms actively pursue these matters.
Ransomware incidents generate compliance obligations that extend far beyond system recovery. Your technical team restores operations in days or weeks. Your legal and financial exposure persists for years. This checklist helps you meet your immediate obligations and build the documentation that protects your organization when the lawsuits arrive.



