Your Medical Practice Was Hacked—Now the HIPAA Clock Is Ticking
The attack may be over, but the legal and regulatory response is just beginning.
Your medical practice has regained access to its systems. The electronic health record is working again. Appointments are being rescheduled, employees are catching up on documentation, and the waiting room is slowly returning to normal.
Then your forensic investigator delivers the finding everyone hoped to avoid: an unauthorized person may have accessed files containing patient information.
At that moment, the incident changes. It is no longer only a technology outage. It may be a reportable healthcare data breach, and multiple notification deadlines could already be running.
The decisions made during the first hours and days can affect patients, regulators, the practice’s reputation, and the final cost of the event. This is why every medical practice needs more than an IT company. It needs a coordinated breach-response plan.
A Cyberattack Does Not End When the Computers Come Back Online
Restoring systems is only one part of the response. A medical practice must also determine:
- What information was accessed or acquired
- Which patients or individuals were affected
- Whether protected health information was involved
- Whether the information was properly encrypted
- Whether notification is legally required
- Which federal and state regulators must be notified
- What must be included in patient notices
- Whether law enforcement should be involved
- How the incident should be documented
The practice cannot safely answer these questions based on assumptions. It may need digital-forensic investigators, privacy counsel, its cyber insurer, IT professionals, affected vendors, and other specialists working from the same response plan.
If your practice is still evaluating the operational and insurance impact of ransomware, begin with our guide: A Hacker Can Hold Your Patient Records Hostage—Is Your Florida Practice Covered?
When Does the HIPAA Breach Notification Clock Begin?
One of the most dangerous misconceptions is that a medical practice has 60 days to investigate before the notification period begins.
That is not the rule.
HHS guidance explains that the time period begins when the breach is known—or reasonably should have been known—not when the forensic investigation is finished. Sixty days is an outer limit for certain HIPAA notifications, not an automatic waiting period.
Under the HIPAA Breach Notification Rule, notification generally must be made without unreasonable delay and no later than 60 calendar days after discovery when the applicable requirements are met.
Waiting until day 60 without a defensible reason can create additional risk. HHS has specifically cautioned that waiting until the final day may itself constitute unreasonable delay in some circumstances.
Source: HHS Office for Civil Rights Cybersecurity Newsletter.
Does Every Security Incident Count as a HIPAA Breach?
Not every malfunction, suspicious email, or attempted intrusion is automatically a reportable breach. However, incidents involving unsecured protected health information require a formal analysis.
Under HIPAA, an impermissible acquisition, access, use, or disclosure of protected health information is generally presumed to be a breach unless the regulated organization demonstrates a low probability that the information was compromised.
That conclusion must be supported by a documented risk assessment. The assessment generally considers at least:
- The nature and extent of the information involved, including the types of identifiers and the likelihood that individuals could be identified.
- The unauthorized person who accessed or received the information.
- Whether the information was actually acquired or viewed.
- The extent to which the risk was mitigated.
This is not a box-checking exercise. A practice should not declare an incident “not reportable” simply because there is no immediate evidence that the attacker sold or misused patient information.
Why Ransomware Is Presumed to Be a Breach
Ransomware creates a particularly difficult HIPAA issue. HHS guidance explains that when ransomware encrypts electronic protected health information, an impermissible disclosure has occurred because the attacker has taken control of that information.
A breach is therefore presumed unless the organization can demonstrate, through the required risk assessment, that there is a low probability the protected health information was compromised.
The analysis may consider:
- The specific ransomware variant
- Whether data was viewed, removed, or exfiltrated
- Whether reliable audit logs exist
- Which systems and files were affected
- Whether the information was encrypted before the attack
- Whether backups were also accessed
- Whether credentials were stolen
- Whether the attacker maintained persistent access
The fact that the practice restored its files from backups does not, by itself, prove that patient information was not compromised.
Source: HHS Ransomware and HIPAA Fact Sheet.
Who Must Be Notified After a HIPAA Breach?
The answer depends on the number of affected individuals, their locations, the information involved, and other circumstances.
Affected Individuals
Covered entities generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a reportable breach.
The notification typically explains:
- What happened
- When the breach occurred and was discovered
- The types of information involved
- What the practice is doing in response
- What affected individuals can do to protect themselves
- How individuals can contact the practice with questions
The wording matters. A notice must satisfy legal requirements while communicating clearly to patients who may be angry, frightened, or confused.
The HHS Secretary
If a breach affects 500 or more individuals, the covered entity generally must notify the HHS Secretary without unreasonable delay and no later than 60 calendar days following discovery.
Breaches affecting fewer than 500 individuals must also be reported to the Secretary, but they may be reported within 60 days after the end of the calendar year in which the breach was discovered. A practice does not have to wait until year-end and may report sooner.
Source: HHS Breach Reporting Requirements.
The Media
If a breach affects more than 500 residents of a state or jurisdiction, HIPAA may also require notification to prominent media outlets serving that area.
That requirement can turn an internal crisis into a public reputational event. Practices should involve experienced breach counsel and communications professionals rather than improvising a public statement.
Business Associates and Covered Entities
If the incident occurs at a business associate, the business associate generally must notify the covered entity. The applicable agreement may impose additional responsibilities and shorter contractual deadlines.
The practice should not assume that a vendor will handle everything. Responsibility must be determined under HIPAA, applicable state law, the business-associate agreement, and the underlying service contract.
Florida Practices May Face a Separate 30-Day Requirement
HIPAA is not the only law that may apply.
The Florida Information Protection Act, found in section 501.171 of the Florida Statutes, imposes separate requirements involving breaches of personal information.
Depending on the circumstances, Florida law can require notice to affected individuals and notification to the Florida Department of Legal Affairs. The statute generally uses a 30-day period following determination of a breach or reason to believe a breach occurred.
For breaches affecting 500 or more individuals in Florida, notification to the Department of Legal Affairs may also be required within the statutory period.
This creates a critical planning problem: a practice focused only on HIPAA’s 60-day outer limit could overlook a shorter state deadline.
Federal and state obligations must be evaluated together. A HIPAA conclusion does not automatically resolve every Florida notification question.
Source: Florida Statutes § 501.171.
The First 24 Hours: What a Medical Practice Should Do
A practice should follow its incident-response plan and obtain qualified professional guidance. The following steps provide a general framework, not a substitute for legal or cybersecurity advice.
- Contain the incident. Isolate affected systems without unnecessarily destroying evidence.
- Contact the cyber insurer. Many policies require prompt notice and use of approved response vendors.
- Preserve evidence. Do not wipe devices, delete suspicious emails, or rebuild servers before receiving forensic direction.
- Engage breach counsel. Privacy counsel can coordinate the legal analysis and help structure the investigation.
- Engage forensic specialists. Determine how the attacker entered, what systems were affected, and whether information was viewed or removed.
- Activate continuity procedures. Maintain safe patient care while systems are unavailable.
- Control communications. Designate who may speak with employees, patients, vendors, law enforcement, regulators, and the media.
- Document every decision. Record when the incident was discovered, who was contacted, what was learned, and why response decisions were made.
Five Mistakes That Make a Breach More Expensive
1. Waiting for Absolute Certainty
A practice may never obtain perfect information. Waiting for certainty can consume critical time while legal deadlines continue running.
2. Using an Unapproved Response Vendor
A cyber policy may require the practice to use approved counsel, forensic firms, negotiators, or notification vendors. Hiring independently before contacting the carrier could create a coverage dispute.
3. Destroying Forensic Evidence
Reformatting computers or deleting suspicious messages may eliminate information needed to determine the scope and source of the attack.
4. Making Premature Public Statements
Early statements can become inaccurate as the investigation develops. Communications should be truthful, carefully reviewed, and updated when necessary.
5. Assuming the Vendor Owns the Problem
The attack may have started at an EHR, billing, email, or IT vendor, but the medical practice may still have independent notification and patient-communication responsibilities.
What Cyber Insurance Can Provide During the Response
A well-structured cyber policy does more than reimburse the practice after an event. It can provide access to an established response network while the incident is unfolding.
Depending on the policy, that network may include:
- Privacy and breach-response counsel
- Digital-forensic investigators
- Ransomware negotiators
- Data-restoration specialists
- Patient-notification vendors
- Call-center services
- Credit or identity-monitoring services
- Public-relations professionals
- Regulatory defense resources
- Business-interruption coverage
The value is not merely writing a check. It is having qualified professionals available when the practice is under pressure and every hour matters.
Frequently Asked Questions
How quickly must a medical practice report a HIPAA breach?
Required notifications generally must be made without unreasonable delay. For breaches involving 500 or more individuals, notification to affected individuals and the HHS Secretary generally cannot occur later than 60 calendar days after discovery. Other requirements and shorter state deadlines may apply.
Does the HIPAA clock begin after the investigation is finished?
No. HHS explains that the period begins when the incident is known or reasonably should have been known, not when the forensic investigation is complete.
Is every ransomware attack automatically reportable?
Ransomware involving electronic protected health information creates a presumption of a breach. The organization may overcome that presumption only by documenting a low probability that the information was compromised through the required risk assessment.
Does Florida have a separate breach-notification law?
Yes. Florida Statutes § 501.171 may impose separate notification requirements and a shorter 30-day timeframe. The applicability of the law should be reviewed with qualified counsel.
Will cyber insurance pay for HIPAA breach notification?
Many cyber policies can cover specified legal, forensic, notification, call-center, monitoring, and regulatory-defense expenses. Coverage depends on the policy’s terms, conditions, limits, exclusions, and reporting requirements.
A Breach-Response Plan Should Not Begin After the Breach
Review your medical practice’s cyber coverage before a ransomware attack, stolen credential, vendor breach, or lost device starts the notification clock.
Explore Medical Practice Cyber Insurance
This article provides general educational information and is not legal, cybersecurity, or insurance advice. Breach obligations vary according to the facts, jurisdictions, contracts, and applicable laws. Consult qualified privacy counsel regarding a specific incident.
