Breach Investigation
A breach investigation is the process of examining a suspected or confirmed exposure of protected health information (PHI) to figure out what happened, how it occurred, who and what was affected, and what needs to be done to fix it. In the HIPAA context, it typically follows the discovery of an impermissible use or disclosure of PHI. In some cases, the government, specifically the HHS Office for Civil Rights (OCR), may also conduct its own investigation into a reported breach.
In HIPAA practice, a breach investigation is the structured analysis a covered entity or business associate performs after discovering a potential breach, generally an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of PHI, to determine the cause, scope, impact, and remediation requirements. The investigation typically informs the risk assessment used to evaluate whether the incident meets the regulatory threshold for a reportable breach and what notification obligations apply. Separately, HHS OCR conducts its own investigations of reported breaches; as reflected in the evidence, OCR investigates breaches of PHI (and Part 2 records) affecting 500 or more individuals. Note that the specific breach-assessment methodology, notification thresholds, and timelines are governed by the current Breach Notification Rule text and should be verified against current HHS guidance; state law and the HITECH Act may impose additional requirements. This entry addresses breach investigation generally and does not detail every procedural step or the full four-factor risk assessment.
Why it matters
A breach investigation is the pivotal step that determines whether an organization understands what actually happened to protected health information (PHI) after a suspected incident. Without a disciplined investigation, a covered entity or business associate cannot reliably determine the cause, scope, or impact of an event, and therefore cannot make a defensible decision about whether a reportable breach has occurred or what notification obligations apply. The quality of the investigation directly shapes the accuracy of the downstream risk assessment used to evaluate whether an impermissible use or disclosure meets the regulatory threshold for a reportable breach under the Breach Notification Rule.
The stakes are heightened because HHS Office for Civil Rights (OCR) conducts its own investigations of reported breaches. As reflected in the evidence, OCR investigates breaches of PHI (and Part 2 records) affecting 500 or more individuals. This means an organization's internal investigation is not the end of the matter; regulators may scrutinize both the underlying incident and the adequacy of the organization's response. A thorough, well-documented investigation generally puts an organization in a far stronger position to demonstrate diligence, whereas gaps in the record can raise questions about compliance.
Beyond regulatory exposure, breach investigations are often a race against time, particularly where unauthorized access or data exfiltration is involved. Reconstructing how an incident occurred and what was compromised becomes harder as evidence ages or is lost. Prompt, structured investigation typically supports both containment and the accuracy of any required notifications. Readers should note that specific thresholds, timelines, and assessment methodology are governed by the current Breach Notification Rule text and should be verified against current HHS guidance, and that state law and the HITECH Act may impose additional requirements.
Who it's relevant to
Inside Breach Investigation
Common questions
Answers to the questions practitioners most commonly ask about Breach Investigation.