You find out on Monday morning that something happened.
Maybe an employee's email account was compromised.
Maybe a laptop containing patient information disappeared.
Maybe your billing company calls to tell you they experienced a cybersecurity incident.
Or maybe your IT provider discovers that someone accessed an account they should not have.
The first reaction is often:
"Do we have to report this?"
That's an important question.
But it is not the only question—and it should not be the first thing your practice tries to answer on its own.
When an incident involves protected health information, HIPAA has specific requirements for determining whether a breach occurred, documenting what happened, and, when required, notifying affected individuals and the U.S. Department of Health and Human Services.
And some of those notification deadlines can extend no later than 60 days after discovery of the breach.
The key is understanding what that actually means.
First: A Security Incident Is Not Automatically a Reportable Breach
This distinction matters.
Your practice may experience a security incident without ultimately determining that HIPAA breach notification is required.
For example, perhaps someone sends a phishing email to an employee, but your security systems block it before anything is accessed.
That's a security incident.
Or perhaps an employee accidentally sends patient information to the wrong person.
Now there may be an impermissible disclosure that needs to be evaluated.
HIPAA's Breach Notification Rule generally presumes that an impermissible use or disclosure of protected health information is a breach unless the practice can demonstrate, through the required risk assessment, that there is a low probability that the PHI was compromised.
That means the process should not be:
Something happened → immediately decide it wasn't serious → move on.
Nor should it be:
Something happened → panic and assume every patient must be notified.
The right response is:
Contain it. Investigate it. Assess it. Document it. Then determine the appropriate notification requirements.
What Does "Discovery" Mean?
One reason timing matters so much is that HIPAA's notification requirements are tied to the discovery of a breach.
You should not assume the clock starts only when leadership finishes investigating the incident or when someone formally labels it a breach.
That is why practices need an established incident-response process.
If an employee notices suspicious activity on Tuesday but nobody reports it until Friday, you have already lost valuable time.
If your IT company detects unauthorized account activity but the message sits unread for several days, the problem does not pause while everyone is busy seeing patients.
The faster the right people know, the faster the practice can determine what happened and what needs to happen next.
The 60-Day Rule Isn't Quite as Simple as It Sounds
You may have heard that HIPAA gives organizations "60 days to report a breach."
That statement is incomplete.
For affected individuals, notification must be provided without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI.
The 60 days are an outside limit—not automatically a 60-day waiting period.
The requirements for notifying HHS depend partly on the size of the breach.
If 500 or more individuals are affected
The HHS Secretary must generally be notified without unreasonable delay and no later than 60 calendar days after discovery.
If fewer than 500 individuals are affected
The practice can generally report those breaches to HHS annually. Those reports are due no later than 60 days after the end of the calendar year in which the breaches were discovered.
There may also be a media-notification requirement when a breach affects more than 500 residents of a state or jurisdiction.
This is one reason practices should involve qualified legal and compliance professionals when determining notification obligations rather than relying on a simplified internet checklist.
What Should Your Practice Do First?
When an incident happens, your first priority is not writing notification letters.
It's understanding and containing the incident.
Depending on what happened, that could mean:
Disabling a compromised account
Resetting passwords
Revoking active sessions
Disconnecting an affected workstation
Preserving logs and other evidence
Blocking malicious activity
Contacting an affected vendor
Determining whether additional accounts were accessed
Identifying what information may have been involved
This is where having an IT provider that understands healthcare environments matters.
You don't want to start deleting files, rebuilding computers, or changing systems without understanding whether those actions could destroy information needed to investigate the incident.
Then Determine What Information Was Involved
Not every incident carries the same level of risk.
Consider the difference between:
An attacker gaining temporary access to an employee's unused test account.
And:
An attacker gaining access to an email account containing patient names, insurance information, medical records, appointment details, and attachments.
Those are very different situations.
The investigation needs to establish things like:
What information was involved?
How many individuals may have been affected?
Who may have accessed the information?
Was the information actually viewed or acquired?
Was the information protected in a way that made it unreadable or unusable to an unauthorized person?
You need facts before you can make a responsible breach determination.
Don't Forget About Your Vendors
A breach does not have to start inside your practice.
Eye care practices rely heavily on third parties:
Billing companies
Patient communication systems
IT providers
Laboratories
Payment processors
Marketing platforms
When a business associate experiences a breach involving your protected health information, the business associate generally has notification obligations to the covered entity. HHS notes that while a covered entity can delegate certain notification tasks to a business associate, the covered entity remains responsible for ensuring required individual notifications occur.
That makes your business associate agreements and vendor-management processes important long before an incident occurs.
When a vendor calls and says, "We've had a breach," your practice needs to know:
What data did they hold for us?
Whose data was affected?
What information will they provide for our investigation?
Who is responsible for notification?
Those questions are much easier to answer when responsibilities were defined before the incident.
Document What You Did
Documentation is one of the most overlooked parts of incident response.
HIPAA's Security Rule requires regulated entities to identify and respond to suspected or known security incidents, mitigate harmful effects when practicable, and document security incidents and their outcomes.
So keep a record.
Document:
When the incident was discovered
Who was notified
What systems or accounts were involved
What containment actions were taken
What information was potentially affected
What the investigation found
How the breach determination was made
What corrective actions were implemented
Which notifications were made, if required
Months or years later, "We think we handled it" is not nearly as useful as a documented incident record showing what happened and what the practice did about it.
Don't Let Fear Stop Employees From Reporting Something
There is also a human side to all of this.
Employees sometimes delay reporting incidents because they are embarrassed.
They clicked the link.
They sent the file to the wrong person.
They approved a suspicious MFA request.
They lost the laptop.
They don't want to get in trouble.
That delay can make an incident much harder to contain.
Your employees should know:
If something goes wrong, tell us immediately.
You can address the mistake later.
First, protect the practice and the patients.
A culture where employees report quickly is far safer than one where people hide problems because they are afraid of being blamed. Cybersecurity training should make that expectation clear before an incident happens.
Your Breach Plan Should Exist Before the Breach
The worst time to decide who handles a security incident is while one is happening.
Your practice should already know:
Who calls IT?
Who contacts legal or compliance counsel?
Who contacts the cyber insurance carrier?
Who coordinates with vendors?
Who documents the incident?
Who determines whether notification is required?
Who communicates with patients if notification becomes necessary?
That does not mean every employee needs to become a HIPAA expert.
It means everyone needs to know their role.
Preparation Buys You Time When Time Matters
A breach can be stressful, especially when patient information may be involved.
The answer is not to memorize every HIPAA deadline.
The answer is to build a process so that when something happens, the right people are involved quickly enough to make the right decisions.
At IT4Eyes, we help eye care practices build the technology side of that process—security monitoring, access controls, backups, documentation, vendor coordination, and incident response.
Because when an incident happens, one of the most dangerous questions a practice can ask is:
"What are we supposed to do now?"
The better time to answer that question is before you ever need the answer.
