HIPAA breach log for a ride company: each incident, the four-factor test, and the yearly report to HHS
Overview
A HIPAA breach log records every privacy incident, including the ones that turn out not to be breaches. Each entry holds the discovery date, what happened, the exception or four-factor assessment behind the decision, the notices sent, and the fix. Breaches affecting fewer than 500 people are reported to HHS within 60 days after the year ends, and the records are kept six years.
On this page
What does a breach log have to prove?
The log must prove, for every privacy incident, either that each required notice went out or that the incident was not a breach. Under 45 CFR 164.414, a covered entity or business associate carries that burden. HHS says to keep the evidence for the “not a breach” side too: the risk assessment showing a low probability of compromise, or the exception that applied (HHS Breach Notification Rule). Who must be told, and by when, is in HIPAA for NEMT companies.
One log does three jobs:
- A record of every incident. Log the misdirected text, the lost manifest, and the wrong rider’s details sent to a facility, whether or not they turn out to be breaches. Security incidents, which include attempted unauthorized access, must also be documented with their outcomes (164.308(a)(6), 164.304). A column for the incident type lets one log hold both.
- A record of each decision. The exception relied on, or the four-factor assessment, written so a reviewer can follow it.
- The source of the yearly HHS report. A covered entity keeps a log of breaches affecting fewer than 500 people and reports them within 60 days after the end of the calendar year (164.408(c)).
The written procedure for reporting and deciding belongs in your HIPAA policy. This page is the log that procedure fills in, and the breach letter template covers the notices.
The log
Keep Part A as one running list for the year. Start a copy of Parts B to D for every row in Part A, even when the incident turns out to be nothing.
Part A: Running log (one row per incident)
| No. | Date discovered | Date it happened | What happened (one line) | People involved (estimate) | Type: privacy, security, or both | Decision | Notices sent (dates) | Closed |
|---|---|---|---|---|---|---|---|---|
Decision codes: P permitted use or disclosure, S secured (encrypted or destroyed), E1, E2, or E3 exception, L low probability shown by assessment, N notices sent, I incident only, no PHI involved.
Part B: Incident record
| Field | Entry |
|---|---|
| Log number | |
| Date and time first known to anyone on staff other than the person responsible | |
| Who found it and how it was reported | |
| Date or range it happened | |
| What happened, in plain words | |
| Where it happened: desktop, electronic record, email, laptop, network server, other portable device, paper, other | |
| Cause: hacking or IT incident, improper disposal, loss, theft, unauthorized access or disclosure | |
| Types of information: clinical (diagnosis, medications, other treatment), demographic (name, address, date of birth, driver’s license, Social Security number), financial (claims, card or bank numbers) | |
| Riders involved (number and list location) | |
| Safeguards in place before: none, privacy policies and training, security administrative, physical, or technical | |
| First steps to limit harm (recovered, deleted, locked, wiped) and dates | |
| Broker or health plan told on (their deadline) |
The first row of Part B starts the clock. It runs from the first day any workforce member or agent, other than the person responsible, knows of the incident or would know of it by looking with reasonable care (164.404(a)(2)). A prompt investigation that finds there was no breach ends the matter. HHS’s own example is a laptop reported stolen that turns up the next day in another office of the same company (74 FR 42749 to 42750), so write the result down and close the row.
Part C: The decision
Work through the steps in order and stop when one settles it.
- Was it a use or disclosure the Privacy Rule does not permit? If not, record why and close.
- Was the information unsecured? Electronic information encrypted as HHS guidance describes, with the key not breached, is secured, and so is paper that was shredded or otherwise destroyed so it cannot be read or rebuilt. Record how it was secured (74 FR 42740).
- Does one of the three exceptions fit? Write down which one and the facts that support it:
- E1. A workforce member or person acting under the company’s authority opened or used information unintentionally, in good faith and within the scope of their authority, and passed it no further.
- E2. A person authorized to access rider information at the company passed it by mistake to another authorized person at the same company, and it went no further. The same holds for two people at the same business associate.
- E3. You have a good faith belief that the person who got it could not reasonably have kept it.
- If no exception fits, run the four factors in the worksheet below. Without a low probability of compromise, the incident is a breach.
- Decide and sign. Name who decided and the date.
| Factor | Questions to answer | Your answer | Points to low probability? |
|---|---|---|---|
| 1. What and how much | Which identifiers? Any diagnosis, treatment, Social Security number, or card number? Could it be re-identified from context? | ||
| 2. Who got it | Another provider, plan, or agency bound to protect it, or a stranger, a rider, a rider’s employer? | ||
| 3. Seen or only exposed | Was it opened, read, copied, or sent on? Does a check show it was never accessed? | ||
| 4. How far it is contained | Was it returned, deleted, or destroyed? Do you hold written assurance, such as a confidentiality agreement? |
Overall conclusion (all four weighed together):
Decided by and date:
Part D: Notices and fixes
| Item | Entry |
|---|---|
| Decision: breach or not, and the reason in one sentence | |
| Rider letters sent (date, number, method) | |
| Substitute notice needed and given (fewer than 10 or 10 or more) | |
| Broker or health plan notified (date, who) | |
| Media notice needed (more than 500 residents of one state) | |
| HHS notice: now (500 or more) or on the yearly list (fewer than 500) | |
| Law enforcement delay (who, date, written or oral) | |
| Fix made to stop a repeat (policy, setting, training, sanction) and date | |
| Copies filed (letters, police report, assessment, proof of mailing) |
How to decide the four factors, one at a time
Each factor asks something specific, and HHS’s explanation of the rule gives examples (78 FR 5642 to 5643). The text below turns them into questions a dispatcher can answer.
- What and how much. Sensitive information raises the probability. HHS names Social Security and card numbers, and detailed clinical information such as diagnosis, medications, and test results, and warns that many kinds of health information are sensitive, not only the obvious ones. A rider’s name, address, and the clinic they visit tells a reader about their care. A first name and a pickup time may not identify anyone. If there are few direct identifiers, ask whether the recipient could work out who the person is from other information.
- Who got it. A recipient who must protect the information in a similar way, such as a HIPAA-covered clinic or a federal agency under the Privacy Act, points toward a lower probability. HHS’s contrast is a diagnosis list sent to an employer, who may match dates to absences from work.
- Seen or only exposed. HHS says a stolen laptop that is recovered, and a forensic review shows nobody opened the information, can support the finding that it was not acquired. A letter opened by the wrong person is different: they read it enough to know it was misdirected.
- How far it is contained. Getting the recipient’s assurance that the information will not be used or shared, through a confidentiality agreement or similar means, or that it was destroyed, counts. HHS adds that assurances from an employee, an affiliated business, a business associate, or another covered entity may be relied on, while assurances from some other third parties may not be enough.
HHS expects the assessment to be thorough, completed in good faith, and the conclusion reasonable. If it does not show a low probability of compromise, notification is required (78 FR 5643). HHS also says you have discretion to skip the assessment and send the notices. If you take that route, log the incident as N and note that no assessment was done.
Four examples and the route each takes
These are invented incidents built on situations HHS discusses. The route is the decision code the log would show.
- A wrong-clinic fax. A trip sheet goes to the wrong physician office, which phones the same day to say it received it in error and destroyed it. No exception fits, but HHS says a company may show a low probability after the assessment, since the recipient reported the error and destroyed the fax. Route: L, with the four answers written down.
- A manifest in the mail. A trip list mailed to a rider’s old address comes back unopened. HHS says this can fall under the exception for information the recipient could not reasonably have kept. Route: E3. If the envelope never came back, or the recipient opened it and called, it needs the four factors.
- A trip sheet handed to the wrong rider. The driver realizes at once and takes it back before the rider reads it. HHS’s own example is a nurse who hands one patient another’s discharge papers and recovers them quickly. Route: E3, if you can reasonably conclude the rider could not have read or kept it.
- A phone taken from a van, no lock. Nobody can show the data was never opened, and the phone is gone. Route: N, with the notices dated and filed.
What goes to HHS each year
Breaches that touch fewer than 500 people are reported to HHS once a year: the deadline is 60 days after the calendar year in which you discovered them ends. For discoveries in 2026, that is March 1, 2027. You may report as soon as you discover one. HHS asks for a separate notice for each incident, and allows several to be submitted on the same date (HHS, content reviewed February 13, 2026). Breaches of 500 or more people go on a different clock, with the rider letters, and the breach letter template covers it.
The online form asks for facts the log should already hold. HHS’s sample of the portal’s questions lists these screens. Copy from the log instead of retyping from memory:
| Form screen | What it asks | Where it sits in your log |
|---|---|---|
| General | Initial report or addendum, and a tracking number for an addendum | Part E, below |
| Contact | Whether you are a covered entity, a business associate filing for one, or a covered entity filing for its business associate, and a point of contact | Your privacy official’s details |
| Breach | Breach and discovery dates, number of people, type, location, kinds of information, a description (4,000 characters), safeguards before | Part B |
| Notice and actions | Dates of individual notice, substitute or media notice, and the actions taken | Part D |
| Attestation | A signed statement that the information is accurate | The privacy official, on the filing date |
The form’s attestation text says that for breaches affecting more than 500 people, some of the answers are posted on the HHS website, so write the description for a stranger. HHS’s sample of the questions dates from 2017, so check the live portal when you file.
Part E: Yearly HHS filing record
| Log no. | Date filed | Confirmation or tracking number | Filed by | Addendum filed later (date) |
|---|---|---|---|---|
Keeping the log six years
Keep the required documentation six years, counted from the day it was created or the last day it was in effect, whichever comes later (164.530(j)). For a covered entity that includes the log, each assessment, the exception relied on, copies of every letter, and proof of filing. The Security Rule sets the same six years for its documents, including security incident records (164.316).
Close each year’s log on its own page, sign it, and file it with the rest of the HIPAA records on your record retention schedule. Put the HHS filing date on your compliance calendar, and the broker clocks beside each incident row.
Pulling the rider list in HealthRide
When an incident involves a day’s manifest or trip list, the list of people affected comes from the trip record. The trip log in HealthRide’s reports exports to a spreadsheet or a print-ready PDF and shows who was scheduled that day. What each person on the team can see depends on their role, and HealthRide records every change.
Frequently asked questions
- Should I log an incident I decide is not a breach?
- Yes. When there is an impermissible use or disclosure, the covered entity or business associate carries the burden of showing either that every required notice went out or that the incident was not a breach. HHS says to keep the risk assessment that showed a low probability of compromise, or the exception that applied. Without the log row, you cannot prove a decision you made correctly.
- What are the four factors in the risk assessment?
- They are the nature and extent of the information involved, including the types of identifiers and the chance of re-identification; who used it or received it; whether it was actually acquired or viewed; and how far the risk has been reduced. The rule requires at least these four, and HHS expects them weighed together, done in good faith, and ended with a reasonable conclusion.
- Can I skip the risk assessment and just send the notices?
- Yes. HHS says covered entities and business associates have discretion to send the required notifications after an impermissible use or disclosure without first performing a risk assessment. The assessment exists to avoid notices where the information was very likely not compromised. If you notify without it, log the incident, the notices, and why you chose that route.
- Was a lost phone with a passcode a breach?
- It depends on whether the data counts as secured. HHS guidance treats electronic information as secured when it is encrypted to the standard it describes and the key was not breached. A screen lock alone is not what that guidance names. Find out how the phone was set up, record it, and if the data was not secured, run the four factors.
- What is the deadline for reporting a small breach to HHS?
- For a breach touching fewer than 500 people, file by 60 days after December 31 of the year you found it. Breaches discovered in 2026 are due by March 1, 2027. You can file sooner, and you must submit a separate notice for each incident, though you may file several on one date.
- How long must the log be kept?
- Six years from when it was created or when it was last in effect, whichever is later, for the required documentation of a covered entity. That includes the log, the risk assessments, the exceptions you relied on, copies of letters, and proof of filing with HHS. Keep rows for non-breaches too, since they are the proof of your decisions.
- Does a business associate need its own breach log?
- Yes, in practice. The yearly HHS report is a covered entity duty, though HHS says a business associate may submit a breach report on a covered entity's behalf. A business associate still carries the same burden of proving it made the required notice or that the incident was not a breach, and broker contracts often require fast reports. A log with dates and decisions is how you show both.