Executive Summary
One-paragraph overview describing who discovered the incident, the date(s), estimated number of affected individuals, and whether PHI was compromised; written for nontechnical stakeholders and regulators.
A concise, accurate report reduces legal exposure, documents corrective action, preserves evidence for audits, and satisfies mandatory notification timelines under HIPAA and state breach laws. Timely, well-documented reporting helps limit penalties and supports investigation and remediation.
The report is prepared and reviewed by teams responsible for privacy, security, legal, and executive oversight.
Collaboration across privacy, IT security, legal, and communications ensures factual reporting and consistent notifications.
Typically signs or certifies the report after review; responsible for assessing HIPAA risk, coordinating notifications, and ensuring documentation matches investigation findings.
Executes legal review and signs when required; assesses regulatory exposure, interacts with outside counsel, and approves language for regulator-facing reports.
One-paragraph overview describing who discovered the incident, the date(s), estimated number of affected individuals, and whether PHI was compromised; written for nontechnical stakeholders and regulators.
Chronological events from initial detection to containment and remediation, including discovery date, investigation milestones, and notification dates.
Precise list of PHI categories involved (names, SSNs, medical records, billing data) and the systems, applications, or media where exposures occurred.
Estimate of affected individuals and potential harm (identity theft, financial risk, clinical impact) plus rationale for harm determination.
Steps taken to contain the incident, mitigate risk, update controls, and prevent recurrence; include responsible parties and completion dates.
Record of notifications to affected individuals, HHS OCR or state agencies, media notices if applicable, and attachments such as mailed letters or email logs.
| Template Field and Configuration Columns | Field | Configuration |
|---|---|
| Primary signer authentication and verification method | Email link | SMS code or 2FA |
| Document retention and audit trail settings | Retain PDF | Store audit log |
| Conditional fields, visibility, and logic rules | Show fields | Based on PHI categories |
| Notification routing, CC, and recipient order | Privacy, Legal, Exec | Sequential routing |
Confirm platform support for secure uploads, audit trails, and appropriate signer authentication before eSubmission.
Ensure the chosen platform can produce a tamper-evident signed copy and store audit logs for compliance purposes.
No later than 60 days after discovery in most cases (HIPAA Breach Notification Rule).
For 500+ individuals, send notification without unreasonable delay and typically within 60 days.
Keep a log of breaches affecting fewer than 500 individuals for annual submission to OCR.
Varies by state statute; confirm state-specific deadlines with counsel or regulator guidance.
When breaches affect large populations, media notice may be required under federal or state rules.
Identify scope and preserve evidence immediately.
Determine PHI categories and affected individuals.
Apply technical fixes and limit further exposure.
Prepare, sign, and deliver required notices.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk send | Yes (plan-dependent) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA support | Yes (BAA available) | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Envelope cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |