← Back to the security portal
COMODO TECHNOLOGY
Security Awareness Training & HIPAA Compliance
Client Compliance & Security Playbook
HIPAA Security Incident
Response Action Plan
Practice Name: HIPAA Security Officer:
Effective Date: Next Review Date:
Immediate action on a suspected breach
If you suspect a ransomware infection, unauthorized account access, or exposure of patient information: do NOT turn the computer off. Disconnect the network cable or switch off Wi-Fi, then call Comodo immediately: (916) 740-1407. If you cannot reach anyone, email help@comodotechnology.com or use live chat, monitored at any time, including nights and weekends. Powering down destroys the forensic evidence needed to determine whether patient data was actually accessed.

1 · Incident Severity Classification & Triage

SeverityExamplesComodo ActionHIPAA Escalation
SEV-1
Critical
Ransomware, active practice-management or EHR breach, stolen unencrypted laptop containing patient data, widespread phishing. Isolate the network, revoke Microsoft 365 sessions, preserve memory and logs, begin forensic capture. Trigger the 4-Factor Risk Assessment. Notify practice leadership and legal counsel within 2 hours.
SEV-2
High
Targeted credential theft, lost encrypted tablet, a fax or email of multiple charts sent to the wrong recipient. Reset credentials, remote-wipe the device, run a deep audit-log review. Document containment and assess whether patient data was actually accessed or viewed.
SEV-3
Moderate
A single spam click with no credentials entered; malware blocked at the endpoint before execution. Run an endpoint scan, re-verify the user's multi-factor setup, review endpoint telemetry. Log in the practice's incident register as a non-reportable security event.

2 · The 6-Phase Incident Response Workflow

  1. Identification & Intake. Staff notices something wrong — locked files, an unexpected login prompt, a misdirected chart — and alerts the HIPAA Security Officer and Comodo within 15 minutes.
  2. Containment. Disconnect affected workstations from the network to stop ransomware spreading; revoke active Microsoft 365 sessions and reset affected passwords; suspend the compromised user inside the practice-management system (your EHR or practice management system).
  3. Eradication & Forensic Logging. Comodo engineers pull endpoint and Microsoft 365 audit logs, remove malware artifacts, and verify backup integrity before anything is restored.
  4. Recovery. Restore from a verified clean backup. Validate clinical workflows, imaging, and e-prescribing before any device returns to patient-facing service.
  5. 4-Factor Breach Risk Assessment. Leadership and counsel evaluate: (1) the nature and extent of the information involved; (2) who the unauthorized person was; (3) whether the information was actually acquired or viewed; and (4) the extent to which the risk has been mitigated.
  6. Notification & Documentation. If the assessment concludes a reportable breach occurred, follow Section 3 below — then file the full incident record for the required retention period.
Breach risk assessment factors per 45 CFR § 164.402. Incident response procedures required under 45 CFR § 164.308(a)(6).
COMODO TECHNOLOGY
Security Awareness Training & HIPAA Compliance
Page 2 of 2
Notification Duties &
Emergency Contacts

3 · Breach Notification Requirements

ScenarioWhat Must Happen
Affected individuals Written notice to each affected individual without unreasonable delay and no later than 60 calendar days from discovery of the breach.
500 or more records Notify HHS/OCR at the same time as individual notice. Prominent media notification is also required if 500 or more residents of a single state or jurisdiction are affected.
Fewer than 500 records Log in the practice's internal incident register and submit to HHS/OCR within 60 days of the end of the calendar year in which the breach was discovered.
California practices California's Confidentiality of Medical Information Act imposes its own notification duties that can be stricter and faster than federal HIPAA rules. Confirm state obligations with counsel alongside the federal timeline.
Federal breach notification timelines per 45 CFR §§ 164.404–164.408. State obligations vary — this document does not constitute legal advice.

4 · Emergency Contact Matrix

RoleContact NamePhoneEmail
Comodo Technology
SUPPORT & SECURITY EMERGENCY
Call first on any suspected breach · 8am–6pm Mon–Fri (916) 740-1407 help@comodotechnology.com
Comodo Technology
Direct Escalations
Nights, weekends and holidays — answered (916) 745-5592 help@comodotechnology.com
Comodo Technology
Email & Chat
After hours, nights & weekends — monitored 24/7 help@comodotechnology.com
Practice HIPAA Security Officer
Practice Owner / Managing Doctor
HIPAA / Breach Legal Counsel
Cyber Insurance CarrierPolicy #:

5 · Annual Maintenance Checklist

  • Review and re-date this plan at least once per year.
  • Confirm every contact above is current — especially after staff turnover.
  • Verify all staff completed security awareness training this year.
  • Confirm backups have been test-restored, not just reported as successful.
  • Re-confirm your cyber insurance policy limits and notification deadlines.
  • Retain this plan and all incident records for 6 years.
Retention requirement: HIPAA requires Security Rule documentation — including this plan, incident records, and staff training completion records — to be retained for six years from the date of creation or the date it was last in effect, whichever is later. 45 CFR § 164.316(b)(2)(i).
Support & Security Emergency · 8am–6pm PT, Mon–Fri
(916) 740-1407
Direct Escalation · Nights & Weekends
(916) 745-5592
After Hours · Email & Chat 24/7
help@comodotechnology.com