Back to What's Changing

Incident Response Plan

A written game plan for the moment something goes wrong.

What it means

An Incident Response Plan is a written, step-by-step document describing exactly what your practice will do if you discover a breach, ransomware attack, or other security incident — who to call first, how to contain the damage, and how to notify patients and regulators.

Why it matters

HIPAA requires practices to notify affected patients within 60 days of discovering a breach. Without a plan in place ahead of time, that response happens under pressure and mistakes get made — missed deadlines, mishandled evidence, or poor communication that makes a bad situation worse.

What this looks like in practice

A written plan naming who is responsible for what
Clear steps for containing and investigating an incident
A notification process for patients, HHS, and media if required
The plan tested periodically, not just written and filed away
Not sure where your practice stands on this?

Get a free 30-minute readiness check — no pressure, just clarity on what you need.

Get My Free Readiness Check