Skip to main content
All playbooks
Playbook

A vendor that handles your PHI had a breach

Billing service, MSP, transcription vendor, answering service, cloud backup, marketing agency, interpreter service. The 60-day clock starts on you, the covered entity, the moment they tell you. Attribution, BAA enforcement, and patient notification are the next 60 days.

Last reviewed: May 2026

The first hour

  1. 1Get the BA's incident notification in writing. Email, letter, or fax — not a phone call. It must include the BA's discovery date, the data categories, the patient counts attributable to your practice, the BA's containment steps, and the BA's recommended notification posture.
  2. 2Note the exact moment you received the notification. Your 60-day patient-notification clock starts from the date you knew or should have known.
  3. 3Pull the BAA. Tag the clauses that matter: notification clock, data-categories disclosure, patient-list disclosure, patient-notification responsibility assignment, and indemnification.
  4. 4Open a written communication channel with the BA — email, with cc to your privacy officer and (if relevant) counsel. Phone is for speed; paper is for protection.
  5. 5Notify your cyber insurance carrier. Many policies cover BA-driven breaches as if they were your own.
  6. 6Ask the BA in writing for the affected patient list — not an aggregate count, the actual list with data elements per patient and date range. The BAA usually requires it; OCR will expect you to have it.
  7. 7Begin drafting your patient notification letter. The 60-day clock is a ceiling, not a target — week-two notifications land better than week-eight notifications with identical content.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • The BA's written incident notification, with timestamps.
  • Your signed BAA and any amendments.
  • The affected patient list and data-element breakdown received from the BA.
  • The written four-factor risk assessment.
  • Copies of every patient notification letter, the mailing dates, OCR portal submission, and any state AG submissions. Six-year retention.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Is it really our problem if the BA was the one breached?+

Yes. Under HIPAA, the covered entity and the business associate each have independent obligations. The BA is liable for the breach; the practice is liable for picking and managing the BA, and for notifying patients on time once the BA notifies you.

What if the BA refuses to send the patient list?+

The BAA usually requires it. Refusal is a BAA breach in its own right — escalate via your cyber insurer's panel attorney, document the refusal, and (in larger incidents) consider termination and civil action. Without the list, your notification will be incomplete and OCR will notice.

Can we let the BA notify our patients on their own?+

Only if the BAA explicitly assigns notification to them, and even then confirm in writing they have started and review the language. Patients almost always react better to a letter from their doctor's office than from a vendor they may not recognize.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.