Skip to main content
All playbooks
Playbook

Coordinating the carrier IR vendor with the OCR portal filing

The incident is contained. Now sequence the carrier-mandated IR vendor with the OCR portal, the state AG filings, and the patient notifications. Small practices stumble here on sequencing, not on the work itself.

Last reviewed: May 2026

The first hour

  1. 1Confirm carrier notification went through. Most cyber policies require notice within 24–72 hours of becoming aware of a potential incident. The coverage clock starts at notification, not at filing.
  2. 2Get the assigned breach coach (the carrier's panel attorney) on the phone. They direct the panel forensic firm, the panel notification vendor, and any state-specific counsel. Treat them as the project manager for the regulatory work.
  3. 3Confirm the engagement letter scope. The panel attorney's engagement is usually under attorney-client privilege, which protects the forensic findings from discovery in subsequent litigation. Route communications through them — files sent direct to your broker can lose the privilege.
  4. 4Map every regulator who needs notification and the clock for each: HHS OCR, state AG (CA/NY/TX/FL/others on 30–45 days), state medical board, CMS if Medicare-data was involved, HHS media notification if 500+ in one jurisdiction.
  5. 5Confirm the IR vendor's report scope: attacker access dates, activity dates, data accessed or exfiltrated, root cause, remediation, recommendations. This is the evidence base for the OCR filing and the claim.
  6. 6Draft the patient notification letter with the panel attorney. Include the data elements, mitigation, what the patient can do, a toll-free number, and (where SSN/financial data is involved) a credit-monitoring offer.
  7. 7Send the patient notifications by first-class mail (or consented electronic delivery) BEFORE filing the OCR portal — OCR's first question is when patients were notified, and an early portal filing is awkward to explain.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Carrier notification email with policy number, discovery date, and case number.
  • Engagement letter from the panel attorney establishing privilege scope.
  • IR vendor forensic report — attacker timeline, data accessed, root cause, remediation.
  • Patient notification letter, mailing log, and any electronic-delivery consent records.
  • OCR portal submission confirmation, state AG submission confirmations, and the cyber-insurance claim file. Six-year retention.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Should we use the carrier's panel vendor or our own counsel?+

Almost always the panel. Panel vendors are pre-negotiated rates, they have done this hundreds of times, and the engagement keeps privilege intact. Use your own counsel only if there is a specific reason — and clear it with the carrier first or you risk the claim.

When exactly do we file the OCR portal?+

After the patient notifications are out the door. OCR's first question on any submission is when patients were notified. A portal filing ahead of the patient mailing is awkward to explain, and you are still inside the 60-day federal window either way.

Do we have to offer credit monitoring?+

Not under HIPAA. But for breaches involving SSN or financial data it is the de facto standard, several state laws require it, and the carrier's panel will usually recommend it as the cheapest path to limiting follow-on litigation. The carrier may pay for it.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.