§164.308(a)(6)
Security Incident Procedures
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Identify and respond to suspected or known security incidents, mitigate harmful effects, and document incidents and outcomes.
Points of focus
- Recognize and route events that may involve ePHI
- Contain and mitigate harmful effects
- Document investigation, response, and lessons learned
Implementation notes
Add ePHI scope, affected individuals, acquisition indicators, and legal escalation to incident templates; preserve cloud and application evidence and exercise the handoff between engineering, privacy, and customer teams. Operationalize recognize and route events that may involve ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain incident response plan with hipaa decision points with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that the engineering incident process restores service but never assesses ephi compromise Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample incident response plan with hipaa decision points with dates and named reviewers. Be ready to walk through how you detect and correct: the engineering incident process restores service but never assesses ephi compromise
Evidence auditors typically request:
- Incident response plan with HIPAA decision points
- Incident tickets, timelines, and ePHI impact assessments
- Tabletop exercise records and corrective actions
Common gaps
- The engineering incident process restores service but never assesses ePHI compromise
- Evidence is spread across chat and ephemeral logs with no durable incident record
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.308(a)(6) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.308(a)(6)