Risk Management

HIPAA Incident Report Form

Document a privacy or security incident, tick the PHI identifiers involved, and run the 45 CFR §164.402 four-factor risk assessment. The form tells you whether you are holding a reportable breach or a documented incident - and produces the record you must keep for six years.

Cyanotype of a blank form and pen beside a desk phone, its handset seated in the cradle and the coiled cord curling across the deskFIG · 01
A blank form and pen beside a desk phone, its handset seated in the cradle.

What Is a HIPAA Incident Report Form?

A HIPAA incident report is the internal record a covered entity or business associate creates the moment PHI may have been used or disclosed in a way the Privacy Rule does not permit. It captures the facts, the containment steps, and - critically - the documented breach risk assessment that 45 CFR §164.402 requires before you can call an incident “not a breach.”

Every impermissible use or disclosure is presumed to be a breach unless you can show a low probability that the PHI was compromised. That presumption is why a generic security incident template is not enough for healthcare: the form has to walk you through the exceptions and the four factors, and produce a determination you can defend. If the answer is “breach,” our breach notification guide and notification letter generator pick up where this form ends.

Incident vs. Breach: Why the Distinction Matters

Incident

Any event where PHI may have been accessed, used, or disclosed outside the Privacy Rule. Always documented. Not always reportable.

Breach

An incident involving unsecured PHI that no exception covers and that fails the four-factor test. Triggers individual, HHS, and possibly media notice.

Most practices see far more incidents than breaches. A misdirected fax to another clinic that shreds it on the spot, a nurse who opens the wrong chart and closes it, a letter returned unopened - these are incidents that typically end as documented determinations. Snooping by a workforce member, a lost unencrypted laptop, or a ransomware event almost always end the other way. Either way the form goes in the file.

How to Use This Incident Report Form

  1. 1

    Log who found it and when

    Reporter, role, and three dates: when it happened, when it was discovered, and when it was reported internally. The discovery date starts the 60-day notification clock.

  2. 2

    Describe the incident and pick a cause category

    Plain facts only - who, what, where, how it was found. The cause category feeds your annual incident trend review and your next risk assessment.

  3. 3

    Tick every PHI identifier involved

    The checklist is the 18 identifiers from §164.514(b). Add clinical or financial content separately - a diagnosis is not an identifier, but it drives the harm analysis.

  4. 4

    Record containment steps

    What you did, when, and what proof you have. A signed destruction attestation is worth far more than a phone call in an OCR file review.

  5. 5

    Check the three exceptions, then run the four factors

    If an exception fits, the tool stops there. Otherwise rate each factor; the verdict badge flips to 'reportable breach' unless every factor supports low probability of compromise.

  6. 6

    Print, sign, and file for six years

    The Privacy Officer signs the determination. Keep the report with its evidence - you carry the burden of proof either way (§164.414(b)).

Do not let the assessment eat the clock. The 60 days in §164.404(b) are an outer limit, not a target, and they run from the day the incident was discovered - or should have been. Finish the determination in days, not weeks, and if you are a business associate, check your BAA: most shorten the reporting window to the covered entity to 5-10 days.

Retention and Burden of Proof

Keep it six years. §164.530(j)(2) requires documentation to be retained for six years from the date it was created or last in effect, whichever is later. That covers the incident report, the four-factor worksheet, attestations, and any notices sent.

You must prove it. Under §164.414(b) the covered entity or business associate carries the burden of demonstrating that notification was made - or that the incident did not qualify as a breach. An undocumented “we decided it wasn’t a breach” is treated as if no assessment happened, which is itself a violation and feeds directly into the penalty tiers.

Incidents under 500 individuals still go to HHS - as an annual log submitted within 60 days after the end of the calendar year. Build the log from these reports, and fold recurring cause categories into your next risk assessment and training plan.

Common Scenarios and How They Usually Come Out

Illustrative only - your facts control. The pattern to notice: who received it and whether you can prove it was not read move the needle more than anything else.

ScenarioTypical outcomeWhy
Fax sent to the wrong clinic; recipient is a covered entity, shredded it, signed attestationNot a breachRecipient bound by HIPAA (factor 2 low), evidence not read beyond cover (factor 3 low), fully mitigated (factor 4 low).
Billing statement mailed to the wrong patient; patient opened it and calledUsually a breachActually viewed by a private individual. Limited identifiers may lower harm, but the presumption rarely rebuts.
Front-desk staff pulls up a co-worker's chart out of curiosityBreachSnooping is not good-faith access within scope of authority; exception (1)(i) does not apply. Also a sanctions-policy event.
Laptop stolen from a car; full-disk encryption on, key not stored with deviceNot unsecured PHIEncrypted per HHS guidance, so the Breach Notification Rule is not triggered. Document the encryption evidence.
Ransomware encrypts the EHR server; no exfiltration evidence either wayPresumed breachOCR treats ransomware encryption of ePHI as an acquisition. 'Unknown' on factor 3 does not rebut the presumption.
Nurse mentions a diagnosis to the wrong nurse on the same unit; corrected immediatelyException (1)(ii)Inadvertent disclosure between two authorized people at the same entity, no further use.
Old patient files found in a dumpster behind the buildingBreachUnknown recipients, no mitigation possible, and improper disposal is a standalone Privacy Rule violation.

Encrypted-device cases depend on the encryption meeting HHS guidance (NIST-validated, key not compromised). See our encryption requirements guide. For messaging-related incidents, the Gmail and WhatsApp guides explain why unencrypted channels turn a slip into a breach.

Frequently Asked Questions

Patients can also report suspected violations directly to OCR - see how to file a HIPAA complaint. A clean, dated incident file is your best answer when that letter arrives. Keep the rest of your program in order with the compliance checklist and incident-response policy template.

Related Tools & Guides