Data breach response in healthcare: what the first 72 hours actually require

Data breach response in healthcare: what the first 72 hours actually require
No organization plans to have a breach. Every organization handling health data should have a plan for what happens in the first 72 hours after discovering one — because that's the window regulators actually measure you against, and it's far too short to figure out your process while you're living it.
The clock starts at discovery, not confirmation
Under GDPR, the 72-hour window to notify the relevant supervisory authority starts when the organization becomes aware of a breach — not when the investigation concludes, not when the full scope is understood. "Aware" generally means having a reasonable degree of certainty that a security incident has occurred and personal data was compromised, not absolute certainty about every detail. Under HIPAA in the US, the standard is different — breach notification to affected individuals is required without unreasonable delay and no later than 60 days — but the same principle holds: the notification obligation exists well before you have every answer.
This is precisely why organizations that treat "we'll figure out notification once we understand what happened" as their plan consistently miss these windows. Understanding the full scope of a breach often takes weeks. The regulatory clock doesn't wait for that.
What has to happen in parallel, immediately
- Containment. Cut off the access path — revoke compromised credentials, isolate affected systems — without destroying the evidence needed to understand what happened. These two goals are in tension and require a deliberate process, not improvisation.
- Scoping, in parallel with containment, not after it. What data was accessed, whose records were involved, and what an attacker (or a compromised agent, or an internal error) could have done with that access. This is where having audit logs of every system and agent action pays for itself — without them, scoping a breach is largely guesswork.
- Notification drafting starts immediately, even with incomplete information. Regulators generally accept a notification with the information available at the time, followed by updates as the investigation progresses. Waiting for complete information before notifying at all is the mistake that turns a contained incident into a regulatory enforcement action.
Why AI agents change what "scoping" requires
An agent that has access to multiple systems means a compromised agent credential could have touched records across all of them, not just one. Scoping a breach involving an agent means being able to answer, specifically: what did this agent's credential access, in what systems, over what window of time. This is only answerable quickly if every agent action was logged as it happened — which is the same audit trail that matters for day-to-day accountability, now earning its keep in the worst-case scenario.
The plan that actually works
A named incident response owner, a pre-drafted notification template that just needs the specifics filled in, a legal contact who already knows the organization's regulatory obligations before an incident happens, and — underneath all of it — logging thorough enough that "what happened" is a query, not an investigation. None of this prevents a breach. All of it determines whether the aftermath is a manageable, well-handled incident or a compounding crisis.
Comments (0)
No comments yet. Be the first to share your thoughts.