An incident response plan with the four-factor breach assessment worksheet, notification decision tree, and 60-day clock tracker built in.
What is in the download
- Format: DOCX
- Length: 14 page(s) / file(s)
- Includes: rule citations, fill-in guidance in the margin, and a completed example
- Licence: free to modify and use commercially
What is in the template
The plan implements §164.308(a)(6) — identify, respond, mitigate, document — and carries you through the Breach Notification Rule if an incident crosses that line. The sections, in the order you would use them at 2 a.m.: roles and contacts (incident lead, technical lead, communications, counsel, each with a deputy); the intake channel and severity triage; containment and mitigation steps by incident type — lost device, phishing compromise, misdirected disclosure, ransomware; the incident log format that satisfies the documentation requirement for every event, including the ones that never become breaches.
Then the breach machinery. The four-factor worksheet walks the §164.402 assessment — nature and extent of the PHI, the unauthorised recipient, whether PHI was actually acquired or viewed, and mitigation — with space for written reasoning per factor and a named decision-maker, because the rule presumes an impermissible disclosure is a breach until your documented analysis shows a low probability of compromise. The notification decision tree routes the outcome: individuals within 60 days of discovery, HHS within the same window for breaches affecting 500 or more (annual log otherwise), media for 500+ in a state or jurisdiction. The clock tracker records the discovery date and counts forward, because “without unreasonable delay” is the operative standard and 60 days is a ceiling, not a target. A post-incident review page closes the loop into corrective actions.
How to use it
- Read it end to end before filling anything in.
- Delete every clause describing a control you do not have. An untrue policy is evidence against you.
- Assign an owner and a review date to each section.
- Publish it, collect acknowledgements against the version number, and retain both for six years.
One addition specific to this document: exercise it. A tabletop walk-through once a year — pick a scenario, run the plan, note what broke — turns the DOCX into a capability, and the exercise record is itself evidence for your annual review.
How to customise it
Fill the roles with names, not titles alone, and give every name a deputy — incidents respect nobody’s holiday. Make the intake channel match how your people actually communicate: an email alias nobody reads is a detection failure by design, so wire the reporting path into the chat tool or phone line staff already use, and say in training that reporting is praised, not punished. Adapt the incident-type playbooks to your real stack, and delete scenarios that cannot apply. Set your business associate reporting obligations both directions: if you are the covered entity, record the contractual windows your BAAs give each vendor; if you are the business associate, the plan must trigger customer notification within whatever window your BAAs promise — check them before filling in a number. And put counsel’s details in before you need them; the four-factor call on a close case is exactly when you want advice on privilege and wording.
Common mistakes
- Only planning for breaches. The §164.308(a)(6) obligation covers every security incident. An empty incident log reads as “no detection”, not “no incidents”.
- Assuming rather than assessing. Skipping the four-factor worksheet because “it was obviously low risk” leaves you with a conclusion and no defence. The written reasoning is the protection.
- Starting the clock late. Discovery is when anyone in the organisation knew or should have known — the unescalated help-desk ticket already started it.
- Drafting notifications mid-crisis. The template’s letter skeletons exist because prose written under adrenaline, before counsel review, is how organisations make a bad week worse.
- No post-incident loop. An incident that changes nothing in the risk assessment or the policy set will repeat.
Related templates
The plan leans on its neighbours: the risk assessment tells you which incidents to expect, the training deck teaches the workforce to report into it, and the encryption policy determines whether a lost device is an entry in the log or a notification exercise. The full regulatory walkthrough — incident versus breach, the four factors, the clocks — is in the incident response guide.
The honest limitation
A template is a starting point, not a program. It cannot record who acknowledged it, prove it was followed, or update itself when your environment changes. Those three things are what the platform does, and they are the difference between having documents and having compliance.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.