| Practice Name: |
HIPAA Security Officer: |
| Effective Date: |
Next Review Date: |
Immediate action on a suspected breach
If you suspect a ransomware infection, unauthorized account access, or exposure of patient information:
do NOT turn the computer off. Disconnect the network cable or switch off Wi-Fi, then call
Comodo immediately:
(916) 740-1407. If you cannot reach anyone, email
help@comodotechnology.com or use live chat, monitored at any time, including nights and weekends. Powering down destroys the forensic evidence
needed to determine whether patient data was actually accessed.
1 · Incident Severity Classification & Triage
| Severity | Examples | Comodo Action | HIPAA Escalation |
SEV-1 Critical |
Ransomware, active practice-management or EHR breach, stolen unencrypted laptop containing patient data, widespread phishing. |
Isolate the network, revoke Microsoft 365 sessions, preserve memory and logs, begin forensic capture. |
Trigger the 4-Factor Risk Assessment. Notify practice leadership and legal counsel within 2 hours. |
SEV-2 High |
Targeted credential theft, lost encrypted tablet, a fax or email of multiple charts sent to the wrong recipient. |
Reset credentials, remote-wipe the device, run a deep audit-log review. |
Document containment and assess whether patient data was actually accessed or viewed. |
SEV-3 Moderate |
A single spam click with no credentials entered; malware blocked at the endpoint before execution. |
Run an endpoint scan, re-verify the user's multi-factor setup, review endpoint telemetry. |
Log in the practice's incident register as a non-reportable security event. |
2 · The 6-Phase Incident Response Workflow
- Identification & Intake. Staff notices something wrong — locked files, an unexpected login prompt, a
misdirected chart — and alerts the HIPAA Security Officer and Comodo within 15 minutes.
- Containment. Disconnect affected workstations from the network to stop ransomware spreading; revoke
active Microsoft 365 sessions and reset affected passwords; suspend the compromised user inside the practice-management
system (your EHR or practice management system).
- Eradication & Forensic Logging. Comodo engineers pull endpoint and Microsoft 365 audit logs, remove
malware artifacts, and verify backup integrity before anything is restored.
- Recovery. Restore from a verified clean backup. Validate clinical workflows, imaging, and e-prescribing
before any device returns to patient-facing service.
- 4-Factor Breach Risk Assessment. Leadership and counsel evaluate: (1) the nature and extent of the
information involved; (2) who the unauthorized person was; (3) whether the information was actually acquired or viewed;
and (4) the extent to which the risk has been mitigated.
- Notification & Documentation. If the assessment concludes a reportable breach occurred, follow
Section 3 below — then file the full incident record for the required retention period.
Breach risk assessment factors per 45 CFR § 164.402. Incident response procedures required under 45 CFR § 164.308(a)(6).
3 · Breach Notification Requirements
| Scenario | What Must Happen |
| Affected individuals |
Written notice to each affected individual without unreasonable delay and no later than 60 calendar days
from discovery of the breach. |
| 500 or more records |
Notify HHS/OCR at the same time as individual notice. Prominent media notification is also required if 500 or more
residents of a single state or jurisdiction are affected. |
| Fewer than 500 records |
Log in the practice's internal incident register and submit to HHS/OCR within 60 days of the end of the
calendar year in which the breach was discovered. |
| California practices |
California's Confidentiality of Medical Information Act imposes its own notification duties that can be stricter and
faster than federal HIPAA rules. Confirm state obligations with counsel alongside the federal timeline. |
Federal breach notification timelines per 45 CFR §§ 164.404–164.408. State obligations vary — this document does not constitute legal advice.
4 · Emergency Contact Matrix
| Role | Contact Name | Phone | Email |
Comodo Technology SUPPORT & SECURITY EMERGENCY |
Call first on any suspected breach · 8am–6pm Mon–Fri |
(916) 740-1407 |
help@comodotechnology.com |
Comodo Technology Direct Escalations |
Nights, weekends and holidays — answered |
(916) 745-5592 |
help@comodotechnology.com |
Comodo Technology Email & Chat |
After hours, nights & weekends — monitored 24/7 |
— |
help@comodotechnology.com |
| Practice HIPAA Security Officer | | | |
| Practice Owner / Managing Doctor | | | |
| HIPAA / Breach Legal Counsel | | | |
| Cyber Insurance Carrier | Policy #: | | |
5 · Annual Maintenance Checklist
- Review and re-date this plan at least once per year.
- Confirm every contact above is current — especially after staff turnover.
- Verify all staff completed security awareness training this year.
- Confirm backups have been test-restored, not just reported as successful.
- Re-confirm your cyber insurance policy limits and notification deadlines.
- Retain this plan and all incident records for 6 years.
Retention requirement: HIPAA requires Security Rule documentation — including this plan, incident records,
and staff training completion records — to be retained for six years from the date of creation or the date it was last in
effect, whichever is later. 45 CFR § 164.316(b)(2)(i).