HIPAA Incident Report Form
Document a privacy or security incident, tick the PHI identifiers involved, and run the 45 CFR §164.402 four-factor risk assessment. The form tells you whether you are holding a reportable breach or a documented incident - and produces the record you must keep for six years.
Pre-filled with a realistic misdirected-fax example. Edit any field - the report and the breach verdict update in real time. Nothing you type leaves your browser.
Reporter & Tracking
What Happened
PHI Involved
Identifiers involved (the 18 HIPAA identifiers, §164.514(b))
Step 1: Does a statutory exception apply?
45 CFR §164.402(1)(i)-(iii)
If any exception fits, the incident is not a breach by definition and the four-factor test is unnecessary. Be conservative - OCR reads these narrowly.
Step 2: Four-factor risk assessment
45 CFR §164.402(2)(i)-(iv)
HIPAA Privacy & Security Incident Report
Incident IR-2026-014 · Breach determination under 45 CFR §164.402 · Retain 6 years (§164.530(j))
Documented incident - not a breach (low probability of compromise)
The four-factor assessment supports a low probability that the PHI was compromised. No individual, HHS, or media notification is required. Retain this determination for six years - you carry the burden of proof under §164.414(b).
Reporter & Tracking
Reported by: Dana Whitfield, Front Desk Lead
Contact: ext. 214 / dwhitfield@northlakefamilymed.example
Assigned to: Marcus Bell, Privacy Officer
Location / system: Northlake Family Medicine - front office fax station
Timeline
Occurred: August 20, 2026
Discovered: August 21, 2026
Reported internally: August 21, 2026
Discovery lag: 1 day. The 60-day notification clock runs from discovery, or from when it should have been discovered with reasonable diligence (§164.404(a)(2)).
Incident Description
Cause category: Misdirected fax
Individuals affected: 1
A 6-page referral packet for a patient was faxed to a cardiology office one digit off from the intended number. The receiving office (a dermatology practice) called our main line the next morning to report the misdirected fax.
PHI Involved
Encryption: Unsecured
- ■Names
- ■Dates directly related to an individual (DOB, admission, discharge, death)
- ■Telephone numbers
- ■Medical record numbers
- ■Health plan beneficiary numbers
Clinical / financial content: Referral reason (chest pain work-up), current medication list, and last two office visit notes.
Containment & Mitigation
Called the receiving practice within 30 minutes of discovery. Their office manager confirmed the fax was placed in a locked bin unread beyond the cover sheet, shredded it while on the phone, and signed our destruction attestation (returned by fax 2026-08-21 11:42). Corrected the cardiology number in the fax directory and re-sent the referral. Re-trained staff on confirming fax numbers from the verified directory only.
Breach Risk Assessment (§164.402)
Statutory exceptions claimed: None
| Factor | Finding | Risk |
|---|---|---|
| §164.402(2)(i) Nature and extent of the PHI | Some clinical or demographic detail, but low re-identification or harm potential | Medium |
| §164.402(2)(ii) The unauthorized person who received or used it | Another HIPAA covered entity, business associate, or federal agency | Low |
| §164.402(2)(iii) Whether the PHI was actually acquired or viewed | Evidence it was NOT viewed (forensics, unopened return, recipient attestation) | Low |
| §164.402(2)(iv) Extent to which the risk has been mitigated | Fully mitigated: PHI retrieved or destroyed with a signed attestation, access revoked, device wiped | Low |
| Composite risk (0 = lowest, 8 = highest): | 1 | |
Rationale: Recipient is a HIPAA covered entity bound by the Privacy Rule, reported the error unprompted, and provided a signed destruction attestation. No SSN, financial, or specially protected categories were included.
Privacy Officer signature
Date of determination
Retention: keep this report, the risk assessment, and all supporting evidence (attestations, logs, screenshots) for at least six years from the date of creation or last effective date (45 CFR §164.530(j)). Under §164.414(b) the covered entity bears the burden of proving either that notification was made or that the incident was not a breach.
FIG · 01What Is a HIPAA Incident Report Form?
A HIPAA incident report is the internal record a covered entity or business associate creates the moment PHI may have been used or disclosed in a way the Privacy Rule does not permit. It captures the facts, the containment steps, and - critically - the documented breach risk assessment that 45 CFR §164.402 requires before you can call an incident “not a breach.”
Every impermissible use or disclosure is presumed to be a breach unless you can show a low probability that the PHI was compromised. That presumption is why a generic security incident template is not enough for healthcare: the form has to walk you through the exceptions and the four factors, and produce a determination you can defend. If the answer is “breach,” our breach notification guide and notification letter generator pick up where this form ends.
Incident vs. Breach: Why the Distinction Matters
Incident
Any event where PHI may have been accessed, used, or disclosed outside the Privacy Rule. Always documented. Not always reportable.
Breach
An incident involving unsecured PHI that no exception covers and that fails the four-factor test. Triggers individual, HHS, and possibly media notice.
Most practices see far more incidents than breaches. A misdirected fax to another clinic that shreds it on the spot, a nurse who opens the wrong chart and closes it, a letter returned unopened - these are incidents that typically end as documented determinations. Snooping by a workforce member, a lost unencrypted laptop, or a ransomware event almost always end the other way. Either way the form goes in the file.
How to Use This Incident Report Form
- 1
Log who found it and when
Reporter, role, and three dates: when it happened, when it was discovered, and when it was reported internally. The discovery date starts the 60-day notification clock.
- 2
Describe the incident and pick a cause category
Plain facts only - who, what, where, how it was found. The cause category feeds your annual incident trend review and your next risk assessment.
- 3
Tick every PHI identifier involved
The checklist is the 18 identifiers from §164.514(b). Add clinical or financial content separately - a diagnosis is not an identifier, but it drives the harm analysis.
- 4
Record containment steps
What you did, when, and what proof you have. A signed destruction attestation is worth far more than a phone call in an OCR file review.
- 5
Check the three exceptions, then run the four factors
If an exception fits, the tool stops there. Otherwise rate each factor; the verdict badge flips to 'reportable breach' unless every factor supports low probability of compromise.
- 6
Print, sign, and file for six years
The Privacy Officer signs the determination. Keep the report with its evidence - you carry the burden of proof either way (§164.414(b)).
Do not let the assessment eat the clock. The 60 days in §164.404(b) are an outer limit, not a target, and they run from the day the incident was discovered - or should have been. Finish the determination in days, not weeks, and if you are a business associate, check your BAA: most shorten the reporting window to the covered entity to 5-10 days.
Retention and Burden of Proof
Keep it six years. §164.530(j)(2) requires documentation to be retained for six years from the date it was created or last in effect, whichever is later. That covers the incident report, the four-factor worksheet, attestations, and any notices sent.
You must prove it. Under §164.414(b) the covered entity or business associate carries the burden of demonstrating that notification was made - or that the incident did not qualify as a breach. An undocumented “we decided it wasn’t a breach” is treated as if no assessment happened, which is itself a violation and feeds directly into the penalty tiers.
Incidents under 500 individuals still go to HHS - as an annual log submitted within 60 days after the end of the calendar year. Build the log from these reports, and fold recurring cause categories into your next risk assessment and training plan.
Common Scenarios and How They Usually Come Out
Illustrative only - your facts control. The pattern to notice: who received it and whether you can prove it was not read move the needle more than anything else.
| Scenario | Typical outcome | Why |
|---|---|---|
| Fax sent to the wrong clinic; recipient is a covered entity, shredded it, signed attestation | Not a breach | Recipient bound by HIPAA (factor 2 low), evidence not read beyond cover (factor 3 low), fully mitigated (factor 4 low). |
| Billing statement mailed to the wrong patient; patient opened it and called | Usually a breach | Actually viewed by a private individual. Limited identifiers may lower harm, but the presumption rarely rebuts. |
| Front-desk staff pulls up a co-worker's chart out of curiosity | Breach | Snooping is not good-faith access within scope of authority; exception (1)(i) does not apply. Also a sanctions-policy event. |
| Laptop stolen from a car; full-disk encryption on, key not stored with device | Not unsecured PHI | Encrypted per HHS guidance, so the Breach Notification Rule is not triggered. Document the encryption evidence. |
| Ransomware encrypts the EHR server; no exfiltration evidence either way | Presumed breach | OCR treats ransomware encryption of ePHI as an acquisition. 'Unknown' on factor 3 does not rebut the presumption. |
| Nurse mentions a diagnosis to the wrong nurse on the same unit; corrected immediately | Exception (1)(ii) | Inadvertent disclosure between two authorized people at the same entity, no further use. |
| Old patient files found in a dumpster behind the building | Breach | Unknown recipients, no mitigation possible, and improper disposal is a standalone Privacy Rule violation. |
Encrypted-device cases depend on the encryption meeting HHS guidance (NIST-validated, key not compromised). See our encryption requirements guide. For messaging-related incidents, the Gmail and WhatsApp guides explain why unencrypted channels turn a slip into a breach.
Frequently Asked Questions
Patients can also report suspected violations directly to OCR - see how to file a HIPAA complaint. A clean, dated incident file is your best answer when that letter arrives. Keep the rest of your program in order with the compliance checklist and incident-response policy template.
Related Tools & Guides
HIPAA Breach Notification Rule Guide
Timelines, the four-factor test in depth, HHS and media notice rules, and what to say in the letter.
Breach Notification Letter Generator
Produce the §164.404(c) individual notice once this form says 'reportable breach'.
HIPAA Risk Assessment Tool
Fold incident trends into your annual Security Rule risk analysis.
Common HIPAA Violations
The incidents that show up most in OCR enforcement, and how each one starts.
HIPAA Fine Calculator
Estimate 2026 civil penalty exposure by tier and violation count.