Skip to main content
Possible incident

Something happened and you need clear next steps

A suspicious email someone clicked, a missing laptop, an unfamiliar login. Most of these turn out to be manageable. The first job is finding out what actually occurred.

Sound familiar?

  • A staff member entered credentials on a page that turned out to be fake
  • A device with access to patient data went missing
  • Records were emailed or faxed to the wrong recipient
  • Someone spotted a login from a place nobody was working from
What happens next

How we help

Establish the facts

We work through logs, accounts, and access with your IT provider to determine what was reached and by whom.

Assess notification

A documented breach risk assessment under the Breach Notification Rule, so the decision to notify or not is recorded and defensible.

Close the gap

A short list of changes that prevent the same route from being used again, plus documentation of what was done.

Initial fact-finding usually happens within days of the call. If you are in an active emergency with systems encrypted or unavailable, call rather than fill out a form: (000) 000-0000 (placeholder).

Common questions

The first 48 hours checklist

What to preserve, who to call, and what to document when something looks wrong. Placeholder download.

One email with the download. No newsletter unless you ask.

Ready to talk?

A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.

Book a scoping call