Scope
Define what constitutes a reportable breach, include data categories (PII, PHI, financial), systems in scope, and criteria for escalating incidents to contractual notice obligations and quantitative thresholds for the number of affected records.