ISSGlobal / Resources / Perspectives / Incident Response Plan Under HIPAA: Why Compliance Restarts After a Ransomware Breach
Share
Perspectives

Incident Response Plan Under HIPAA: Why Compliance Restarts After a Ransomware Breach

Incident Response Plan Under HIPAA: Why Compliance Restarts After a Ransomware Breach

Incident Response Plan Under HIPAA: Key Takeaways

  • The HHS Office for Civil Rights (OCR) treats a ransomware attack that encrypts protected health information (PHI) as a presumed reportable breach unless you can demonstrate and document a low probability that the PHI was compromised.
  • The 60-day HIPAA breach notification deadline begins when the breach is discovered, not when the attacker first gains access to your systems.
  • Your incident response plan and pre-incident risk analysis become key evidence during an OCR investigation, demonstrating whether your organization took reasonable steps to protect PHI.
  • High-quality forensic evidence supports both your HIPAA four-factor risk assessment and your cyber insurance claim, helping determine the scope and impact of the incident.
  • An effective HIPAA incident response follows five essential steps: contain the threat, notify affected parties, reassess risk, remediate vulnerabilities, and document every action taken.
  • HIPAA requires breach-related documentation to be retained for six years in accordance with 45 CFR § 164.530(j).

The government Office of Civil Rights doesn’t evaluate your organization based solely on how you handle a ransomware breach. It examines the policies, procedures, and risk analyses you documented before the incident, along with your ability to prove that you followed them during the response.

That’s the point many healthcare organizations miss. The moment a security incident begins, your incident response plan stops being just a playbook. It becomes evidence that regulators will scrutinize.

HHS logged 772 large healthcare breaches in 2025, an annual record, with hacking and IT incidents behind more than 80% of them.

Which means the work that decides your outcome may have been completed months ago. What’s left is proving it happened.

What Actually Happens to HIPAA Compliance After a Ransomware Attack?

Nothing in 45 CFR literally resets.

Instead, three critical things happen: Your organization must demonstrate a low probability that protected health information (PHI) was compromised, multiple HIPAA notification deadlines begin running from the moment the incident is discovered, and the HHS Office for Civil Rights opens an investigation that reaches back into your compliance program.

That third point often catches healthcare organizations by surprise. OCR does not evaluate your response in isolation. Investigators examine your security posture before the attack, comparing your risk analysis, policies, and incident response plan with forensic evidence from the incident.

In other words, the risk analysis you completed in 2024 may be reviewed alongside the forensic report from last week to determine whether your organization met its HIPAA obligations before, during, and after the breach.

Here’s what the Breach Notification Rule requires once you discover a breach.

Notify Deadline Trigger Authority 
Affected individuals 60 days Discovery 45 CFR 164.404 
HHS OCR, 500+ affected 60 days Discovery 45 CFR 164.408 
HHS OCR, under 500 affected Annually, within 60 days of year end Discovery 45 CFR 164.408 
Media, 500+ in one state 60 days Discovery 45 CFR 164.406 
Business associate to covered entity 60 days BA discovery 45 CFR 164.410 

Discovery means the first day the breach becomes known or reasonably should have become known to the organization.

Pay close attention to the trigger date. Under HIPAA, each notification deadline begins when the breach is discovered, not when the attacker first gained access to your systems.

Why Does Your Incident Response Plan Decide the Outcome?

our incident response plan is the first document OCR asks for, and every decision you make afterward is measured against it.

An effective incident response plan does four things:

  • Names who can declare an incident and record the discovery time.
  • Defines evidence handling before restoration begins.
  • Assigns notification responsibility to a specific person.
  • Specifies that a decision log be maintained throughout the incident.

Many incident response plans fail on the second point. In the effort to restore clinical operations, teams often recover systems from backups before preserving forensic evidence.

Once affected systems are wiped or overwritten, the artifacts needed to demonstrate a low probability of compromise may be lost, making it significantly more difficult to support a HIPAA risk assessment or defend against regulatory scrutiny.

Investigators expect to see a recognized incident response framework, and the four-phase lifecycle outlined in NIST SP 800-61 gives them one: prepare, detect and analyze, contain and recover, and post-incident activity. OCR reviewers know this framework before they begin their investigation of your response.

Have your response plan reviewed.
Request now.

Is a Ransomware Attack Automatically a Reportable HIPAA Breach?

Generally, yes. OCR’s ransomware guidance, first issued in 2016, states that when ransomware encrypts patient data, the attacker is considered to have acquired possession of that information.

Under HIPAA, that creates a presumption that a reportable breach has occurred.

That presumption can be rebutted, but only if you can document a four-factor risk assessment demonstrating a low probability that the protected health information (PHI) was compromised.

The four factors, outlined in 45 CFR § 164.402, ask four straightforward questions:

  1. What information was involved, and how easily could someone identify a patient from it?
  2. Who received it?
  3. Did anyone actually acquire or view it, or did it sit there encrypted and untouched?
  4. How much of the risk have you since eliminated?

Each conclusion must be backed by evidence. Without forensic support, a claim that patient information was not compromised is unlikely to withstand OCR review because the burden rests with your organization to demonstrate a low probability of compromise.

There is one important exception. If the data was already encrypted to HHS standards before the attack, it is not considered unsecured PHI under HIPAA, so the Breach Notification Rule does not apply. Encryption applied by the attacker does not qualify.

OCR enforcement reflects both sides of the rule. In its settlement with Assured Imaging, the agency cited an inadequate risk analysis alongside a failure to provide timely breach notifications.

Engaging HIPAA compliance experts while forensic evidence is still available can make the difference between an assessment that withstands regulatory scrutiny and one that does not.

What Does a Forensic Investigation Have to Prove?

A forensic investigation has to answer three questions, and your HIPAA risk assessment depends on all of them.

What did the attackers access?

The answer determines who must be notified. Estimate too broadly and costs rise. Estimate too narrowly and regulatory risk rises.

When did they gain access?

Establishing the timeline reveals whether the incident was contained quickly or whether attackers remained undetected for weeks or months. It also helps establish when the breach was discovered and when HIPAA notification deadlines begin.

Did data leave the environment?

Most ransomware groups now exfiltrate data before encrypting systems, making it essential to determine whether protected health information (PHI) was accessed, copied, or removed.

Those answers are only as reliable as the evidence behind them. Memory captures, disk images, authentication records, and firewall and VPN logs should be preserved before systems are restored, with a documented chain of custody throughout the investigation.

That’s why the first 48 hours are often the most difficult. Clinical teams need systems back online, while investigators need evidence preserved. Your incident response plan should establish how those competing priorities are balanced before an attack ever occurs.

What Are the Five Steps of the Post-Breach HIPAA Reset Cycle?  

HIPAA breach notification timeline showing the 60-day notification clock beginning at discovery.
CISA’s StopRansomware guidance complements HIPAA’s breach response requirements.

Ransomware response works best as a sequence rather than a scramble.

CISA’s StopRansomware guidance closely aligns with HIPAA’s breach response requirements, making it a practical framework for healthcare organizations.

Step 1: Contain Without Destroying Evidence

Isolate affected systems from the network instead of powering them down. Shutting systems off can erase volatile memory, which often contains critical forensic evidence. Before rebuilding or restoring anything, capture forensic images of affected systems.

Step 2: Start the Notification Clock

Document the date the breach was discovered and who declared the incident. Notify your cyber insurance carrier immediately, as most policies require prompt notice to preserve coverage.

From there, report the incident to the FBI through IC3 and to CISA through StopRansomware.gov, then confirm whether state breach notification laws require action before HIPAA’s 60-day deadline.

Step 3: Reassess the Risk

Complete the HIPAA four-factor risk assessment using forensic evidence rather than assumptions, documenting the reasoning behind each conclusion.

Once that’s complete, update your enterprise risk analysis to reflect what the investigation uncovered.

OCR will compare your pre-incident risk analysis with the weaknesses identified during the breach.

Step 4: Remediate the Root Cause

Close the attack path, rotate any credentials the attackers may have accessed, and rebuild affected systems from known clean sources.

Then validate the remediation through penetration testing. From an auditor’s perspective, an untested fix is still only a plan.

Step 5: Document Everything

Retain the risk assessment, forensic report, notification decisions, remediation records, and corrective action plan.

Under 45 CFR § 164.530(j), HIPAA documentation must generally be retained for six years, and OCR investigations often continue long after technical recovery is complete.

How Long Does Ransomware Recovery Really Take?

Proposed HIPAA Security Rule updates including 72-hour recovery, encryption, MFA, vulnerability scans, and annual penetration testing.
HIPAA requires breach notifications within 60 days of discovery

Much longer than the outage itself. IBM’s 2026 Cost of a Data Breach Report found that the average breach takes 241 days to identify and contain.

That’s the technical incident. The compliance process often continues long after systems are restored.

HIPAA requires breach notifications within 60 days of discovery, after which OCR may open an investigation that can continue for months as regulators review your policies, risk analyses, forensic findings, and response records.

Healthcare organizations should also watch what’s ahead. HHS’s proposed updates to the HIPAA Security Rule would introduce stricter requirements, including 72-hour system restoration, mandatory encryption, multi-factor authentication, six-month vulnerability scans, and annual penetration testing.

The proposal has not been finalized, but it signals where regulatory expectations are heading.

Shorten your recovery timeline.
Contact Our Experts

How Does Documentation Affect Your Cyber Insurance Claim?

Your insurer can only reimburse what you can prove. A forensic report, a documented incident timeline, and evidence that the security controls listed in your policy were operating at the time of the attack all help support a claim.

The same documentation can also expose gaps. If your application stated that multi-factor authentication protected remote access, but investigators find an unsecured VPN account was the entry point, the discussion can quickly shift from claim approval to coverage disputes.

The file doesn’t disappear once the claim is settled. Insurers often review the same evidence during renewal, looking for proof that the root cause was fully addressed and that corrective actions have been tested.

Can You Build Incident Response Capability After the Fact?

Partially. You can bring in forensic expertise, strengthen monitoring, and improve documentation after an attack.

What you can’t recreate is a tested incident response plan that existed before the breach, which is exactly what OCR will examine.

That makes recovery a two-part process. First, contain and investigate the current incident. Then address the weaknesses that allowed it to happen, so the next investigation finds a stronger security program instead of the same gaps.

For many healthcare organizations, that means adding capabilities they don’t have in-house.

ISS365 provides 24/7 monitoring, detection, and response, while 7-Layer Staffing extends internal teams with cybersecurity specialists experienced in regulated environments.

Why Do Healthcare Organizations Call ISSGLOBAL After a Breach?

Because responding to a breach requires both technical investigation and regulatory compliance, and many providers specialize in only one.

A forensic firm may determine what happened but stop short of producing a defensible HIPAA risk assessment. A compliance consultancy may understand the regulations but lack the technical evidence to support its conclusions.

ISSGlobal brings both together. Our forensic analysts establish the scope of the incident, determine how attackers gained access, and assess whether data was exfiltrated.

Our compliance specialists translate those findings into the documentation OCR expects, including the four-factor risk assessment, breach notifications, and corrective action plans.

Our advisory approach is technology-agnostic, so recommendations are based on your environment rather than a specific product.

Whether supporting HIPAA, NIST, SOC 2, FedRAMP, or PCI DSS initiatives, we help organizations strengthen their security posture while meeting regulatory obligations.

Will Your Incident Response Plan Hold Up Under Review?

Eventually, every incident response plan becomes evidence. Not on the night of the attack, but during an OCR investigation, when regulators review your response with the benefit of hindsight.

What they’re looking for is straightforward. Who declared the incident? When was it discovered? How was forensic evidence preserved before systems were restored? What did the four-factor risk assessment conclude, and what evidence supported those conclusions?

The plans that withstand scrutiny have one thing in common: they were tested before they were needed.

The organizations that navigate a breach most successfully aren’t always the ones that recover the fastest. They’re the ones that can demonstrate a consistent, well-documented response from discovery through remediation.

If your incident response plan hasn’t been tested against a realistic ransomware scenario, now is the time to find out whether it will hold up under review.

Talk to an ISSGlobal specialist about strengthening your incident response program
Contact

Frequently Asked Questions About Incident Response Plans and HIPAA Breaches

Short answers to what teams ask us most in the first week.

1. Is a ransomware attack automatically a HIPAA breach?

It’s presumed to be one. You can rebut the presumption only with a documented four-factor risk assessment showing low probability of compromise.

2. How long do you have to report a HIPAA breach after ransomware?

Sixty days from discovery for individual notification, and for OCR when 500 or more people are affected. Some state laws require 30 days.

3. Does paying the ransom remove the notification requirement?

No. Payment doesn’t change whether an impermissible disclosure occurred, and it doesn’t move any notification deadline.

4. What are the four factors in a HIPAA breach risk assessment?

The nature and extent of the information, who received it, whether it was actually acquired or viewed, and the extent of mitigation. All four appear in 45 CFR 164.402.

5. Does encrypted patient data exempt you from breach notification?

Only when you encrypted it yourself to HHS standards, which removes it from the unsecured category. Encryption applied by an attacker gives you no exemption.

*This article provides general information about HIPAA requirements and does not constitute legal advice. Consult qualified counsel regarding your organization’s specific obligations.