Description
Breach Investigation Procedures
HIPAA Breach Notification Rule — 45 CFR 164.404, 164.410 | Editable Word Template
A breach determination is only as reliable as the investigation behind it. The Breach Investigation Procedures template establishes a documented, repeatable process for gathering and evaluating the facts of a suspected breach — from identifying what happened and who was involved, to scoping the affected PHI and determining whether notification obligations have been triggered.
The template is structured to work in sequence with the Breach Decision Matrix, providing the factual record that the matrix analysis depends on. It includes defined steps, fillable fields for investigator notes, and built-in prompts that keep the investigation aligned with what the Breach Notification Rule actually requires covered entities and business associates to establish.
What Is Included
- Incident intake section capturing discovery date, reporting source, and initial incident description
- Scope assessment for identifying affected individuals, PHI elements involved, and timeframe of exposure
- Evidence and fact-gathering log with structured fields for documenting sources reviewed and findings
- Workforce interview record section for capturing statements relevant to the investigation
- Containment and mitigation actions log
- Investigation timeline fields for tracking key dates against the 60-day notification window under 45 CFR 164.404(b) and 164.410(b)
- Summary of findings section with signature and date fields for the investigating officer
- Instructions for use and cross-reference fields for linking to associated breach response documents
Who This Is For
Privacy officers, security officers, compliance directors, and legal counsel at covered entities and business associates who are responsible for conducting or overseeing breach investigations. Particularly useful for organizations that lack a formalized investigation procedure and need a defensible, documented process ready for immediate use.
Delivered as an editable Microsoft Word (.docx) file. Available immediately after purchase.




