Establishing secure connection…Loading editor…Preparing document…

Healthcare Breach Report

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

HEALTHCARE BREACH REPORT

Use this form to report an incident involving actual or suspected unauthorized access, use, or disclosure of protected health information (PHI). Complete all applicable sections. Submission of this report initiates an authorized internal investigation and any required notifications under applicable law. Provide as much detail as available at the time of submission.

Reporting Entity / Facility

              

Reporter Contact

Affected Individual

Date of Birth:   Phone:

Incident Details

Date breach occurred:   Date discovered:   Time discovered:

     
        

        
        
        

Risk Assessment & Potential Harm

     

     

Mitigation & Notifications

        
        

        

Legal Certification & Attestation

I certify, under penalty of law, that the information provided in this report is true and complete to the best of my knowledge. I understand this report may be used to determine whether further notifications or regulatory filings are required under applicable state and federal law. I acknowledge that knowingly submitting false information may subject me to civil or criminal penalties under applicable law. This report does not waive patient rights to pursue remedies available under law.

By checking the box below, the signer affirms they are authorized to submit this report either as the affected individual, an authorized personal representative, or a designated organizational representative. If the signer is a personal representative or guardian, indicate relationship in the signature block below.

Internal Use / Investigator Notes

Signature of Affected Individual or Authorized Representative

Printed Name: Signature:

Relationship to patient (if not patient): Date:

Enter text✕

What a Healthcare Breach Report Is and when it’s used

A Healthcare Breach Report documents an unauthorized acquisition, access, use, or disclosure of protected health information (PHI) that compromises privacy or security. The report summarizes what happened, which PHI types were involved, how many individuals were affected, corrective actions taken, and the timeline from discovery to notification. Organizations use the report to meet federal HIPAA breach-notification obligations, state breach laws, and to provide evidence to regulators, counsel, and affected individuals. A clear report supports incident response, remediation, and recordkeeping for compliance and potential audits.

Why a clear Healthcare Breach Report matters for compliance

A concise, accurate report reduces legal exposure, documents corrective action, preserves evidence for audits, and satisfies mandatory notification timelines under HIPAA and state breach laws. Timely, well-documented reporting helps limit penalties and supports investigation and remediation.

Why a clear Healthcare Breach Report matters for compliance

Which roles typically prepare or approve a Healthcare Breach Report

The report is prepared and reviewed by teams responsible for privacy, security, legal, and executive oversight.

  • Hospital privacy and compliance teams — coordinate internal investigation and notifications to patients and regulators.
  • Business associates and vendors — provide incident details and remediation for covered entity reporting.
  • Legal counsel and risk officers — evaluate liability, public disclosures, and regulator communications.

Collaboration across privacy, IT security, legal, and communications ensures factual reporting and consistent notifications.

Primary signers and approvers

Chief Privacy Officer

Typically signs or certifies the report after review; responsible for assessing HIPAA risk, coordinating notifications, and ensuring documentation matches investigation findings.

General Counsel

Executes legal review and signs when required; assesses regulatory exposure, interacts with outside counsel, and approves language for regulator-facing reports.

Core sections to include in a professional Healthcare Breach Report

A structured report improves clarity and traceability. Include an executive summary, factual timeline, technical findings, impact assessment, remediation actions, and notification records so reviewers can quickly understand scope and response.

Executive Summary

One-paragraph overview describing who discovered the incident, the date(s), estimated number of affected individuals, and whether PHI was compromised; written for nontechnical stakeholders and regulators.

Incident Timeline

Chronological events from initial detection to containment and remediation, including discovery date, investigation milestones, and notification dates.

PHI and Systems

Precise list of PHI categories involved (names, SSNs, medical records, billing data) and the systems, applications, or media where exposures occurred.

Impact Assessment

Estimate of affected individuals and potential harm (identity theft, financial risk, clinical impact) plus rationale for harm determination.

Remediation Actions

Steps taken to contain the incident, mitigate risk, update controls, and prevent recurrence; include responsible parties and completion dates.

Notifications and Evidence

Record of notifications to affected individuals, HHS OCR or state agencies, media notices if applicable, and attachments such as mailed letters or email logs.

Step-by-step: how to complete the Healthcare Breach Report

Follow these sequential steps to gather facts, document decisions, and complete the report before notifications.

  • 01
    Gather evidence: Collect logs, access records, and copies of exposed files.
  • 02
    Assess PHI exposure: Identify PHI categories and estimate affected individuals.
  • 03
    Document remediation: Record containment measures and system fixes.
  • 04
    Prepare notifications: Complete required notices to individuals and agencies.

Typical submission workflow for a final report

A consistent internal workflow reduces delays and ensures all stakeholders review before external filing.

  • Draft report: Populate facts, timeline, and initial impact assessment.
  • Internal review: Privacy, legal, and IT review the draft and request edits.
  • Sign and certify: Authorized official signs to attest to the report's accuracy.
  • Submit to agencies: Send to HHS OCR, state agencies, and affected individuals as required.

Digital workflow settings to streamline reporting

Configure templates, authentication, and routing once so every report follows the same controls and audit trail.

Template Field and Configuration Columns Field | Configuration
Primary signer authentication and verification method Email link | SMS code or 2FA
Document retention and audit trail settings Retain PDF | Store audit log
Conditional fields, visibility, and logic rules Show fields | Based on PHI categories
Notification routing, CC, and recipient order Privacy, Legal, Exec | Sequential routing

Technical requirements for eSubmission and secure sharing

Confirm platform support for secure uploads, audit trails, and appropriate signer authentication before eSubmission.

  • File formats: PDF or DOCX preferred
  • Integrations: Supports CRM and storage integrations
  • Authentication: Email link, SMS, or SSO

Ensure the chosen platform can produce a tamper-evident signed copy and store audit logs for compliance purposes.

Key reporting timelines to track

Timely reporting is legally significant; start internal timelines at discovery and track external notification due dates.

Notification to individuals:

No later than 60 days after discovery in most cases (HIPAA Breach Notification Rule).

HHS OCR notification:

For 500+ individuals, send notification without unreasonable delay and typically within 60 days.

Small-breach reporting:

Keep a log of breaches affecting fewer than 500 individuals for annual submission to OCR.

State agency deadlines:

Varies by state statute; confirm state-specific deadlines with counsel or regulator guidance.

Media notice requirement:

When breaches affect large populations, media notice may be required under federal or state rules.

Milestones from detection to final reporting

Track these numbered stages to ensure the investigation and notifications proceed on a clear timeline.

01

Detection and initial triage

Identify scope and preserve evidence immediately.

02

Investigation and impact analysis

Determine PHI categories and affected individuals.

03

Containment and remediation

Apply technical fixes and limit further exposure.

04

Notifications and regulator filings

Prepare, sign, and deliver required notices.

Common mistakes to avoid when preparing the report

  • Incomplete timelines that omit discovery or containment dates, undermining claims of timely response and increasing regulatory scrutiny.
  • Underestimating affected individuals by using guesses without documented sampling or logs, which can lead to supplemental notices and credibility loss.
  • Failing to document remediation steps or assigning responsibilities, making it hard to demonstrate corrective action to regulators.
  • Not preserving original evidence such as system logs or A/V recordings, which may be essential for forensic review and legal defense.

Potential penalties and risks from incorrect or late reporting

HIPAA civil fines: Significant monetary penalties
OCR enforcement action: Investigations and corrective plans
State penalties: AG fines and consumer remedies
Class action risk: Lawsuits and settlement exposure
Operational disruption: Resource diversion and remediation costs
Reputational harm: Loss of trust and business

Comparison: eSignature providers for completing and delivering Healthcare Breach Reports

Key vendor features and pricing models affect cost, HIPAA support, bulk-notice capability, and envelope limits; signNow is listed first for comparison consistency.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free trial 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk send Yes (plan-dependent) Varies by plan Varies by plan Varies by plan Varies by plan
Audit trail Yes Yes Yes Yes Yes
HIPAA support Yes (BAA available) Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Envelope cap No cap 100 envelopes/user/year Varies by plan Varies by plan Varies by plan

Frequently asked questions about Healthcare Breach Reports

Answers to common questions on timing, required content, eSignature use, and record retention when preparing a Healthcare Breach Report.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users