Skip to main content
Category: Breach Notification

Breach Investigation

Also known as: Security Breach Investigation, Breach Investigation Process
Simply put

A breach investigation is the process of examining a suspected or confirmed exposure of protected health information (PHI) to figure out what happened, how it occurred, who and what was affected, and what needs to be done to fix it. In the HIPAA context, it typically follows the discovery of an impermissible use or disclosure of PHI. In some cases, the government, specifically the HHS Office for Civil Rights (OCR), may also conduct its own investigation into a reported breach.

Formal definition

In HIPAA practice, a breach investigation is the structured analysis a covered entity or business associate performs after discovering a potential breach, generally an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI, to determine the cause, scope, impact, and remediation requirements. The investigation typically informs the risk assessment used to evaluate whether the incident meets the regulatory threshold for a reportable breach and what notification obligations apply. Separately, HHS OCR conducts its own investigations of reported breaches; as reflected in the evidence, OCR investigates breaches of PHI (and Part 2 records) affecting 500 or more individuals. Note that the specific breach-assessment methodology, notification thresholds, and timelines are governed by the current Breach Notification Rule text and should be verified against current HHS guidance; state law and the HITECH Act may impose additional requirements. This entry addresses breach investigation generally and does not detail every procedural step or the full four-factor risk assessment.

Why it matters

A breach investigation is the pivotal step that determines whether an organization understands what actually happened to protected health information (PHI) after a suspected incident. Without a disciplined investigation, a covered entity or business associate cannot reliably determine the cause, scope, or impact of an event, and therefore cannot make a defensible decision about whether a reportable breach has occurred or what notification obligations apply. The quality of the investigation directly shapes the accuracy of the downstream risk assessment used to evaluate whether an impermissible use or disclosure meets the regulatory threshold for a reportable breach under the Breach Notification Rule.

The stakes are heightened because HHS Office for Civil Rights (OCR) conducts its own investigations of reported breaches. As reflected in the evidence, OCR investigates breaches of PHI (and Part 2 records) affecting 500 or more individuals. This means an organization's internal investigation is not the end of the matter; regulators may scrutinize both the underlying incident and the adequacy of the organization's response. A thorough, well-documented investigation generally puts an organization in a far stronger position to demonstrate diligence, whereas gaps in the record can raise questions about compliance.

Beyond regulatory exposure, breach investigations are often a race against time, particularly where unauthorized access or data exfiltration is involved. Reconstructing how an incident occurred and what was compromised becomes harder as evidence ages or is lost. Prompt, structured investigation typically supports both containment and the accuracy of any required notifications. Readers should note that specific thresholds, timelines, and assessment methodology are governed by the current Breach Notification Rule text and should be verified against current HHS guidance, and that state law and the HITECH Act may impose additional requirements.

Who it's relevant to

Privacy and Security Officers
These roles typically lead or coordinate the internal breach investigation, ensuring that the cause, scope, and impact of an incident are analyzed and that the findings inform the risk assessment used to determine notification obligations. Thorough documentation is generally important both for internal decision-making and for demonstrating diligence to regulators.
Compliance Officers
Compliance staff generally oversee whether the investigation and any resulting notifications align with the current Breach Notification Rule and organizational policy. They should also account for the possibility that state law or the HITECH Act may impose additional requirements beyond HIPAA and confirm current thresholds and timelines against HHS guidance.
Business Associates and Subcontractors
Because impermissible uses or disclosures can occur on the business associate side, these organizations may need to conduct their own investigations and report findings to the covered entity, with obligations generally flowing through the business associate agreement. The specific reporting terms should be confirmed against the applicable agreement and current regulatory requirements.
Incident Response and IT Security Teams
When unauthorized access or data exfiltration is suspected, technical teams often work against time to reconstruct how an incident occurred and what was compromised. Their forensic findings typically feed the broader breach investigation and the assessment of scope and impact.
Legal Counsel
Counsel commonly advises on whether an incident meets the reportable-breach threshold, on notification obligations, and on how to respond to an OCR investigation, including breaches affecting 500 or more individuals, which OCR investigates. Counsel can also help identify additional obligations arising under state law or the HITECH Act.

Inside Breach Investigation

Risk Assessment of Impermissible Use or Disclosure
A core component in which the covered entity or business associate evaluates whether an impermissible use or disclosure of PHI constitutes a reportable breach. Under the Breach Notification Rule, an impermissible use or disclosure is generally presumed to be a breach unless the entity demonstrates a low probability that the PHI has been compromised based on a risk assessment.
Four-Factor Analysis
The Breach Notification Rule generally requires assessment of at least four factors: the nature and extent of the PHI involved (including identifiers and likelihood of re-identification), the unauthorized person who used or received the PHI, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. Practitioners should confirm the specific factors against the current regulatory text.
Scope and Data Identification
Determining what PHI was involved, in which form (electronic, paper, or oral), whose information was affected, and how many individuals may be impacted. Note that the Breach Notification Rule addresses PHI broadly, not solely ePHI as under the Security Rule.
Exception Analysis
Evaluation of whether one of the regulatory exceptions to the definition of breach applies, such as certain unintentional acquisitions by workforce members, certain inadvertent disclosures between authorized persons, or situations where the recipient could not reasonably have retained the information. These exceptions have specific regulatory definitions that differ from common usage.
Roles and Responsibility
Identification of whether the incident occurred at a covered entity, a business associate, or a subcontractor, since notification obligations differ. A business associate that discovers a breach generally must notify the covered entity, and the specific timing and content flow through the business associate agreement and the regulation.
Documentation of the Investigation
Recording the facts gathered, the risk assessment performed, the conclusion reached (breach or no breach), and the basis for that determination. Documentation is generally necessary to demonstrate compliance and to support the burden of proof that rests on the entity.
Notification Determination
The output of the investigation that drives whether notifications to affected individuals, HHS OCR, and in some cases the media are required, and within what timeframe. Specific deadlines and thresholds should be verified against current HHS guidance, as figures are adjusted over time.

Common questions

Answers to the questions practitioners most commonly ask about Breach Investigation.

Does every impermissible use or disclosure of PHI automatically count as a reportable breach?
No. Under the Breach Notification Rule, an impermissible use or disclosure of PHI is generally presumed to be a breach, but that presumption can be overcome. A breach investigation typically includes a risk assessment to determine whether there is a low probability that the PHI has been compromised, and certain regulatory exceptions may also apply. Only after that analysis does an organization determine whether notification obligations are triggered. Readers should confirm the specific risk assessment factors against the current regulatory text.
If we're HITRUST CSF certified, does that mean our breach investigation process satisfies HIPAA?
Not by itself. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification may help demonstrate that controls exist to support breach detection and response, but it does not establish HIPAA compliance on its own. A breach investigation must still meet the obligations set out under the HIPAA Breach Notification Rule and be defensible to HHS OCR, and additional requirements may arise under state law or the HITECH Act.
Who is responsible for conducting the breach investigation when a business associate is involved?
Responsibility generally depends on the defined relationship and the terms of the business associate agreement. In most cases a business associate that discovers an incident is obligated to investigate and report to the covered entity, while the covered entity typically retains ultimate responsibility for determining whether notifications are required. Subcontractors may have parallel obligations flowing through their agreements. The specific allocation of investigation and reporting duties should be confirmed in the applicable business associate agreement.
What should a breach investigation typically document?
A breach investigation generally documents what was discovered and when, the nature and extent of the PHI involved, who used or received the information, whether the information was actually acquired or viewed, and the extent to which risk has been mitigated. It also typically records the reasoning behind any conclusion that the presumption of breach was overcome or that an exception applied. Thorough documentation is generally important because it may need to be produced to HHS OCR.
How quickly should an organization begin a breach investigation after discovering a potential incident?
Investigations should generally begin promptly upon discovery, because notification timelines under the Breach Notification Rule typically run from the point of discovery rather than from the conclusion of the investigation. Delaying the investigation does not extend those deadlines. Specific timeframes for notification should be verified against the current regulation, and note that state law may impose shorter or additional requirements.
Should the risk assessment used in a breach investigation apply to PHI in all forms or only electronic PHI?
The breach notification risk assessment generally applies to protected health information in all forms, including paper and oral PHI, not only electronic PHI. This differs from the HIPAA Security Rule, which governs only electronic PHI. When scoping a breach investigation, teams should account for all media in which the potentially compromised PHI existed rather than limiting the review to electronic systems.

Common misconceptions

If PHI was accessed by mistake, it automatically counts as a reportable breach.
An impermissible use or disclosure is generally presumed to be a breach, but the entity may rebut that presumption through a documented risk assessment demonstrating a low probability that the PHI was compromised. In addition, specific regulatory exceptions may apply, which can remove certain incidents from the definition of breach entirely.
Only electronic PHI incidents require a breach investigation.
The Breach Notification Rule applies to protected health information in all forms, including paper and oral PHI, not just ePHI. The narrower focus on ePHI belongs to the Security Rule, which is a separate rule with a different scope.
Business associates can leave breach investigation and notification entirely to the covered entity.
When a breach occurs at a business associate or subcontractor, that entity generally has its own obligations, typically including notifying the covered entity, and the specific responsibilities flow through the business associate agreement and the regulation. Achieving a certification such as the HITRUST CSF does not by itself satisfy these HIPAA obligations.

Best practices

Treat every impermissible use or disclosure of PHI as a presumed breach and document the four-factor risk assessment used to determine whether notification is required, since the burden of proof generally rests with the entity.
Assess PHI in all forms including paper and oral information, not only ePHI, and confirm the specific risk factors and exceptions against the current regulatory text rather than relying on memory.
Clarify roles early by determining whether the incident originated at a covered entity, business associate, or subcontractor, and follow the notification pathways defined in the applicable business associate agreements.
Maintain thorough, contemporaneous documentation of the facts, the analysis, the exceptions considered, and the final determination so the investigation can support a compliance demonstration to HHS OCR.
Verify current notification deadlines, thresholds, and any figures against current HHS guidance, since these are adjusted over time, and check whether state law or the HITECH Act imposes additional or stricter requirements.
Do not treat a HITRUST CSF certification or any single control as proof that a breach determination or notification obligation is satisfied; use frameworks to support, not replace, the regulatory analysis.