Description
HIPAA, EU AI ACT, FDA | 45 CFR 164.308(a)(6)(ii), 164.402
HIPAA AI Incident Response Addendum Template
Document ID: HEL-AI-INC-001 • Version 1.2
A security incident response program satisfying 45 CFR 164.308(a)(6)(ii) and the Breach Notification Rule at 45 CFR Part 164, Subpart D was almost certainly built before the organization’s AI systems were in use. It has no classification framework for a prompt injection event, no defined trigger for taking a Tier 1 clinical AI system offline, and no reporting path for the EU AI Act’s serious incident obligations or FDA medical device reporting for an AI/SaMD system. When an AI incident happens, response teams improvise instead of following a documented procedure, which is the exact gap OCR and EU regulators look for during an investigation.
This addendum extends the existing incident response program across 16 sections without replacing it. It defines AI Incident and four severity tiers (Critical, High, Moderate, Low), workforce detection and reporting obligations with a 24-hour reporting window, a mandatory 48-hour system-offline assessment for suspected Tier 1 AI incidents, and the four-factor breach risk assessment (45 CFR 164.402(2)) applied specifically to AI-generated PHI exposure. It covers internal escalation to the AI Governance Committee, vendor and business associate AI incident reporting consistent with the AI-Specific BAA Addendum (HEL-AI-BAA-001), individual patient notification, HHS and media notification thresholds, and a state AI and breach notification law screening step. Multi-framework reporting requirements are addressed directly: EU AI Act serious incident reporting, FDA medical device reporting for AI/SaMD systems, and a precedence section resolving which framework’s timeline governs when more than one applies to the same incident.
What Is Included
Classification and Detection
- AI incident definitions and four-tier severity classification (Critical, High, Moderate, Low)
- Workforce detection and reporting obligations with a 24-hour reporting window
- 48-hour system-offline assessment procedure for suspected Tier 1 AI incidents
Risk Assessment and Escalation
- Four-factor breach risk assessment applied to AI incidents (45 CFR 164.402(2))
- Internal escalation and AI Governance Committee notification procedure
- Vendor and business associate AI incident reporting requirements
Multi-Framework Notification
- Individual patient notification, HHS and media notification thresholds, and state law screening
- EU AI Act serious incident reporting and FDA medical device reporting for AI/SaMD systems
- Investigation, corrective action, post-incident review, and documentation retention requirements
Who This Is For
Privacy officers and security officers who already have a HIPAA-compliant incident response program and need to extend it to cover AI systems without rebuilding it from scratch. Organizations operating Tier 1 clinical AI, generative AI tools, or AI vendors subject to EU AI Act or FDA SaMD oversight use this to close the AI-specific gap in their existing breach response plan.
This addendum assumes an existing Security Incident Response Policy and Breach Notification procedure are already in place. It does not replace those documents and should be adopted alongside the AI Governance Policy (HEL-AI-GOV-001) and AI-Specific BAA Addendum (HEL-AI-BAA-001) tiering definitions.
Format: Microsoft Word (.docx), fully editable • Delivered as an instant digital download • Document ID: HEL-AI-INC-001









Reviews
There are no reviews yet.