Breach Response Operation
Overview
This procedure operates the response to a suspected breach of protected health information or of personal information: the report, containment, the risk assessment, the notification lanes, and the record. It begins when any workforce member suspects a breach and ends when the Privacy & Security Officer closes the incident with its documentation complete. The rules this procedure executes are printed in POL-014 (Breach Notification and Response). The notices it sends are prepared from the Breach Notification Templates Pack (CFM-014).
Roles
Every workforce member reports a suspected breach to the Privacy & Security Officer the same day it is suspected and takes the immediate mitigation within reach.
The Privacy & Security Officer owns the response: directs containment, runs the risk assessment, selects the notice lanes, prepares every notice, and files the record. Electronic containment actions run under the officer's administrative access.
The Executive Director approves every external notice before it is sent and directs any media notice. If an incident involves the Privacy & Security Officer, or the seat is vacant, the Executive Director performs the officer's steps in this procedure.
The Compliance Officer opens and maintains the incident's compliance ticket under POL-003-SOP and runs any sanction or corrective action that follows the incident.
A business associate that discovers a breach reports it to the Privacy & Security Officer immediately, identifies each affected individual to the extent possible, and supplies the information ABAS needs to notify.
Notice Lanes
Each confirmed breach is notified on every lane its facts trigger. A single incident can trigger several lanes at once.
| Lane | Trigger | Clock | Instrument |
|---|---|---|---|
| Affected individuals (HIPAA) | Confirmed breach of unsecured PHI | Without unreasonable delay, no later than 60 days after discovery | CFM-014 Form 2 |
| HHS, fewer than 500 individuals | Confirmed breach of unsecured PHI | Logged when confirmed. The calendar year's log files through the HHS breach portal within 60 days after the year ends | CFM-014 Form 3 |
| HHS, 500 or more individuals | Confirmed breach of unsecured PHI | Filed when the individual notices are sent, no later than 60 days after discovery | CFM-014 Form 3 |
| Media | Breach involving more than 500 residents of one state | No later than 60 days after discovery | CFM-014 Form 3, media lane |
| Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation (OCABR) | Security breach of a Massachusetts resident's personal information | As soon as practicable, never delayed to determine the resident count | CFM-014 Form 4 |
| Affected Massachusetts residents | Security breach of a Massachusetts resident's personal information | As soon as practicable, never delayed to determine the resident count | CFM-014 Form 5 |
| Payer or business associate | A contract or business associate agreement requires notice | The agreement's clock | CFM-014 Form 6 |
| Cyber liability carrier | A cyber liability policy is in force | The policy's clock | The carrier's claim process |
The objects the procedure handles:
| Object | What it is | Where it lives |
|---|---|---|
| Compliance ticket | The incident's working file under POL-003-SOP | The support ticket system |
| Breach Risk Assessment (CFM-014 Form 1) | The four-factor assessment and the notification determination | The ticket file |
| Breach log | The running log of confirmed unsecured-PHI breaches affecting fewer than 500 individuals | HIPAA-compliant cloud storage |
| HHS breach portal | The federal filing surface for both HHS lanes | ocrportal.hhs.gov |
| Massachusetts filing forms | The Attorney General's and OCABR's online data breach reporting forms | mass.gov |
Procedure
Step 1: Report and immediate mitigation
The workforce member who causes or discovers a suspected breach takes the immediate mitigation within reach: stop and close the record, retrieve or delete the information, ask the unintended recipient to return it and confirm no further disclosure. The member reports to the Privacy & Security Officer the same day: privacy@abaswma.org or 413-461-7120, or any POL-003 reporting channel. When in doubt, the member reports. The Privacy & Security Officer decides whether the incident is a breach.
Step 2: Ticket
The Compliance Officer or designee opens a compliance ticket for the incident the day the report arrives, following POL-003-SOP intake: the narrative preserved verbatim, access restricted. Privacy tickets route to the Privacy & Security Officer. The ticket is the incident's working file. Every artifact this procedure produces files there.
Step 3: Containment
The Privacy & Security Officer directs containment the same day the report arrives. For electronic incidents the officer acts under administrative access: lock the affected account, disable sharing on the affected record, isolate the affected device, or remotely wipe a lost device. For paper incidents the officer retrieves the document or obtains the recipient's written confirmation that it was returned or destroyed.
The officer preserves the evidence the assessment needs before any wipe, reset, or restoration. If an active intrusion such as ransomware is suspected, the officer disconnects affected systems from the network and preserves them unaltered for investigation.
If a cyber liability policy is in force, the officer reports the incident to the carrier on the policy's clock.
Step 4: Risk assessment
The Privacy & Security Officer completes the Breach Risk Assessment (CFM-014 Form 1) for every reported incident. The assessment determines whether unsecured PHI is involved, whether a POL-014 exception applies, the probability of compromise under the four factors, and whether the incident is a security breach of personal information under M.G.L. c. 93H.
If the assessment concludes no notice is required, the officer documents the determination and its facts on Form 1 and the ticket proceeds to Step 7.
If the assessment confirms a breach, the officer records every notice lane the facts trigger and proceeds to Step 5.
Step 5: Notification
The Privacy & Security Officer prepares each triggered notice from the Breach Notification Templates Pack and issues it on its clock in the Notice Lanes table. The Executive Director approves each external notice before it is sent. If the cyber liability policy in force requires the carrier's consent before a notice, the officer obtains that consent first.
If a law enforcement official states that notification would impede a criminal investigation or threaten national security, the officer delays the affected notices under POL-014 Section 9 and documents the request.
As facts develop after a notice is sent, the officer supplements the notice on the same lane.
Step 6: Credit monitoring
If a Massachusetts security breach involves a Social Security number, the Privacy & Security Officer contracts third-party credit monitoring for each affected resident: at no cost to the resident, for at least 18 months, with the enrollment information delivered in the resident notice. The officer files the credit monitoring compliance certification with the Attorney General and OCABR. Enrollment is never conditioned on a waiver of the resident's right to a private action.
Step 7: Documentation and closure
The Privacy & Security Officer files the complete record set in the ticket: the report, the containment record, the Breach Risk Assessment, each notice with its date and delivery method, and any law-enforcement delay documentation. Confirmed unsecured-PHI breaches affecting fewer than 500 individuals are entered in the breach log. Sanctions and corrective action route through POL-003-SOP resolution. The Compliance Officer closes the ticket when the record set is complete.
Gates
Six gates hold across every incident.
- An external notice is sent only with the Privacy & Security Officer's preparation and the Executive Director's approval. No other workforce member notifies clients, families, regulators, media, or any outside party.
- A notification determination stands only on a completed Breach Risk Assessment (CFM-014 Form 1) on file. A breach of unsecured PHI is presumed until the assessment documents a low probability of compromise or an applicable exception.
- Individual HIPAA notices issue no later than 60 days after discovery. The clock runs from the discovery date. An unfinished investigation does not extend it.
- Massachusetts notice is never delayed to determine the total number of residents affected.
- The Massachusetts resident notice never states the nature of the breach or the number of residents affected. The HIPAA individual notice and the Massachusetts resident notice are separate instruments. Where both apply, the resident receives both.
- Where a cyber liability policy in force requires the carrier's consent before notification, that consent precedes the notices the policy names.
Records
Every artifact of an incident files in its compliance ticket: the report, the containment record, the Breach Risk Assessment, each notice with its date and delivery method, substitute-notice documentation, the credit monitoring certification, and law-enforcement delay documentation. The ticket file is stored and access-controlled under POL-003-SOP.
The breach log holds every confirmed breach of unsecured PHI affecting fewer than 500 individuals, with the fields the HHS portal filing requires. The Privacy & Security Officer maintains the log and submits the calendar year's entries within 60 days after the year ends.
The Privacy & Security Officer retains all breach documentation for six years. Each notified individual keeps the notice they received; a copy of each notice files in the ticket.
Competency
A workforce member performs this procedure independently only after demonstrating it to the Executive Director or their designee. Each skill in the table is demonstrated unaided and error-free on two occasions, and at least one occasion uses a scenario the member has not seen in training.
| Skill | Demonstration |
|---|---|
| Receive and log a report | Opens the ticket, preserves the narrative verbatim, restricts access, and routes the ticket |
| Direct containment | Selects and directs the correct containment for one electronic and one paper scenario, preserving evidence before any wipe or reset |
| Run the risk assessment | Completes Form 1 on scenarios that include one exception case, one presumption-stands case, and one personal-information case |
| Select notice lanes | Names every triggered lane, its clock, and its instrument for a scenario, including one scenario that triggers several lanes |
| Prepare the notices | Prepares an individual notice carrying every required element, and the Massachusetts pair with no content crossing between them |
| Close the record | Files the complete record set, enters the breach log where required, and states the retention period |
The workforce reporting duty in Step 1 is trained under POL-014's training requirement, outside this table.