Incident details
Approximate date and time of incident
Location and system where the incident occurred
Was PHI involved?
No PHI was involved
Names
Dates (birth, admission, discharge, death)
Contact information (address, phone, email)
Social Security Numbers
Medical Record Numbers
Health plan beneficiary numbers
Account numbers
License / certificate numbers
Device identifiers / serial numbers
Biometric identifiers
Clinical / treatment information
Mental health records
Substance use disorder records
HIV/AIDS-related information
Other
Approximate number of individuals affected
— Select —
1-9
10-49
50-499
500+
unknown
Incident category
Misdirected communication (wrong recipient email/fax/mail)
Verbal disclosure to unauthorized person
PHI left in unsecured location
Unauthorized employee access (snooping)
PHI visible to unauthorized persons
Shared login credentials used
Lost device (laptop, phone, tablet, USB)
Stolen device
Lost / stolen paper records
Lost / stolen backup media
Hacking / IT incident
Malware / ransomware
Phishing attack
System misconfiguration
Software vulnerability
Unencrypted transmission of PHI
Database exposure
PHI not properly destroyed / shredded
Improper disposal of devices
PHI in regular trash
Vendor / contractor breach
Third-party system incident
Other
What contributed to this incident?
Human error
Lack of training / awareness
Process / workflow issue
Technology failure
Inadequate security controls
Policy not followed
Policy unclear / nonexistent
Intentional violation
External threat / attack
Other
Please describe the incident to the best of your ability
Any immediate actions taken?
PHI retrieved / secured?
Yes
No
Partially
Affected individuals notified?
Yes
No
Pending Review