Documents to Gather Before an OCR Onsite Investigation of a Reported HIPAA Breach
Risk Assessment Documentation
What to collect
- Your most recent enterprise-wide HIPAA Security Rule risk analysis (SRA), including scope, methodology, likelihood/impact scoring, and findings mapped to Security Rule Documentation requirements.
- The risk management plan that traces each SRA finding to mitigation tasks, owners, target dates, and completion evidence.
- Updates made since the incident (interim SRAs, targeted assessments, or gap analyses tied to the breach vector).
- An asset inventory and data-flow diagrams for systems that create, receive, maintain, or transmit ePHI.
- Vulnerability scan results, penetration tests, configuration baselines, and exception/risk-acceptance memos.
- Executive approvals, review dates, and documentation retention consistent with HIPAA’s six-year requirement.
How to present it
- Provide a clean narrative linking the incident to SRA findings and risk treatments.
- Include index pages that map controls to HIPAA Privacy Rule Compliance touchpoints where relevant (for example, minimum necessary).
Policies and Procedures
Core policy set
- Privacy Rule policies: uses and disclosures, authorizations, individual rights, minimum necessary, and sanctions.
- Security Rule Documentation: administrative, physical, and technical safeguards; change management; configuration management; and vendor oversight.
- Breach Notification policies: risk-of-compromise assessment steps, decision logs, notification timelines, and documentation standards for Breach Notification Records.
Evidence of governance
- Version histories, approval signatures, and effective dates that were in force at the time of the reported HIPAA breach.
- Distribution records and attestations that the workforce received and acknowledged the policies.
- Procedures specific to the incident vector (for example, email security, remote access, patching, device/media controls, and logging/monitoring).
Business Associate Agreements
What OCR expects to see
- An inventory of all Business Associates involved in creating, receiving, maintaining, or transmitting ePHI relevant to the incident.
- Executed agreements and amendments showing Business Associate Agreement Obligations, including:
- Permitted uses/disclosures of PHI and required safeguards.
- Prompt reporting of security incidents and breaches to the covered entity.
- Subcontractor flow-down of the same restrictions and conditions.
- Support for access, amendment, and accounting of disclosures.
- Availability of internal practices to HHS upon request.
- Return or destruction of PHI at termination and termination rights for material breach.
- Vendor due‑diligence records (risk questionnaires, audit reports, or security attestations) and any breach-related correspondence.
Workforce Training Records
Proof of competency
- Curricula and materials covering HIPAA Privacy Rule Compliance, Security Rule obligations, and breach response.
- Role‑based modules for high‑risk functions (IT, privacy, security, revenue cycle, clinicians).
- Completion logs with dates, scores, and attestations for new‑hire, annual, and ad‑hoc refresher training.
- Evidence of targeted training or corrective actions after the incident.
- Signed acknowledgments of policies and sanctions awareness.
Access Control Documentation
Technical Safeguards Evidence
- Access control standards (unique IDs, least privilege, RBAC/ABAC matrices), MFA enforcement, and password/authenticator policies.
- Provisioning/deprovisioning records, approval workflows for privileged access, and emergency access procedures.
- Endpoint, server, EHR, and database configuration baselines showing technical controls that protect ePHI.
- Remote access configurations (VPN/zero‑trust), session timeouts, and device/media restrictions tied to ePHI Access Monitoring.
Operational proof
- Periodic access reviews, recertifications, and segregation‑of‑duties documentation.
- Tickets or change records showing when access was granted, modified, or terminated for accounts implicated in the breach.
Incident Response Documentation
Incident Response Plan Documentation
- The approved plan, playbooks, roles, call trees, communication templates, and criteria for escalation to privacy/security leadership.
- Evidence of plan testing (tabletops or simulations) and lessons learned applied before the incident.
Case file for the reported breach
- The incident ticket, detection details, timelines for triage/containment/eradication/recovery, and forensic analysis.
- The four‑factor risk assessment supporting breach determination, plus mitigation actions taken.
- Breach Notification Records: individual letters, counts of affected persons, HHS submissions, media notices (if applicable), and any law‑enforcement holds.
- Corrective action plans, control improvements, and validation evidence after remediation.
Audit Logs and System Access Records
Logs to assemble
- Application/EHR audit trails showing who accessed which ePHI, when, from where, and what actions were taken.
- Identity, SSO/MFA, directory, and PAM logs; VPN/remote access; email and file storage; database and DLP; EDR/SIEM alerts associated with the event.
- Export/print/download events, failed logins, anomalous patterns, and any suppression or filter rules in effect during the timeframe.
- Time‑synchronization evidence (NTP), chain‑of‑custody notes, and retention settings proving log integrity.
Using logs for ePHI Access Monitoring
- Queries and reports that correlate user, device, and network activity to the suspected disclosure or exfiltration.
- Dashboards or summaries that demonstrate continuous monitoring and response aligned with Security Rule Documentation.
Summary and next steps
Compile a dated, indexed package that ties your risk analysis, policies, BAAs, training, access controls, incident response, and logs into a single narrative. This cohesive set shows OCR that you monitor ePHI, document decisions, and can prove guardrails worked—or were promptly corrected.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
FAQs
What specific documents does OCR require during an onsite breach investigation?
OCR typically requests your Security Rule risk analysis and risk management plan, Privacy/Security/Breach Notification policies, executed Business Associate Agreements, workforce training records, access control standards and provisioning logs, the full incident response case file (including the four‑factor risk assessment and Breach Notification Records), and audit logs that evidence ePHI Access Monitoring and Technical Safeguards Evidence.
How should organizations prepare risk assessment documentation for OCR review?
Deliver a current, enterprise‑wide SRA that explains scope, methodology, and findings, plus a risk management plan mapping each finding to mitigations with owners and dates. Include asset inventories, data flows, test results, approvals, and updates made after the breach so OCR can trace the incident to controls and corrective actions.
What are the required elements in Business Associate Agreements for OCR investigations?
BAAs must define permitted uses/disclosures, require appropriate safeguards, mandate prompt reporting of incidents/breaches, bind subcontractors to the same terms, support individual rights (access, amendment, accounting), allow HHS access to practices, address return or destruction of PHI at termination, and permit termination for material breach—clearly demonstrating Business Associate Agreement Obligations.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.