Applied Behavioral Analysis Services (ABAS)

ABAS Compliance Program

Policies, standards, and program documents
SOP-002

Breach Response Operation

Version 1.0Approved by Executive Director · 2026-08-19Review cycle: Annual

Overview

This procedure operates the response to a suspected breach of protected health information or of personal information: the report, containment, the risk assessment, the notification lanes, and the record. It begins when any workforce member suspects a breach and ends when the Privacy & Security Officer closes the incident with its documentation complete. The rules this procedure executes are printed in POL-014 (Breach Notification and Response). The notices it sends are prepared from the Breach Notification Templates Pack (CFM-014).

Roles

Every workforce member reports a suspected breach to the Privacy & Security Officer the same day it is suspected and takes the immediate mitigation within reach.

The Privacy & Security Officer owns the response: directs containment, runs the risk assessment, selects the notice lanes, prepares every notice, and files the record. Electronic containment actions run under the officer's administrative access.

The Executive Director approves every external notice before it is sent and directs any media notice. If an incident involves the Privacy & Security Officer, or the seat is vacant, the Executive Director performs the officer's steps in this procedure.

The Compliance Officer opens and maintains the incident's compliance ticket under POL-003-SOP and runs any sanction or corrective action that follows the incident.

A business associate that discovers a breach reports it to the Privacy & Security Officer immediately, identifies each affected individual to the extent possible, and supplies the information ABAS needs to notify.

Notice Lanes

Each confirmed breach is notified on every lane its facts trigger. A single incident can trigger several lanes at once.

Lane Trigger Clock Instrument
Affected individuals (HIPAA)Confirmed breach of unsecured PHIWithout unreasonable delay, no later than 60 days after discoveryCFM-014 Form 2
HHS, fewer than 500 individualsConfirmed breach of unsecured PHILogged when confirmed. The calendar year's log files through the HHS breach portal within 60 days after the year endsCFM-014 Form 3
HHS, 500 or more individualsConfirmed breach of unsecured PHIFiled when the individual notices are sent, no later than 60 days after discoveryCFM-014 Form 3
MediaBreach involving more than 500 residents of one stateNo later than 60 days after discoveryCFM-014 Form 3, media lane
Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation (OCABR)Security breach of a Massachusetts resident's personal informationAs soon as practicable, never delayed to determine the resident countCFM-014 Form 4
Affected Massachusetts residentsSecurity breach of a Massachusetts resident's personal informationAs soon as practicable, never delayed to determine the resident countCFM-014 Form 5
Payer or business associateA contract or business associate agreement requires noticeThe agreement's clockCFM-014 Form 6
Cyber liability carrierA cyber liability policy is in forceThe policy's clockThe carrier's claim process

The objects the procedure handles:

Object What it is Where it lives
Compliance ticketThe incident's working file under POL-003-SOPThe support ticket system
Breach Risk Assessment (CFM-014 Form 1)The four-factor assessment and the notification determinationThe ticket file
Breach logThe running log of confirmed unsecured-PHI breaches affecting fewer than 500 individualsHIPAA-compliant cloud storage
HHS breach portalThe federal filing surface for both HHS lanesocrportal.hhs.gov
Massachusetts filing formsThe Attorney General's and OCABR's online data breach reporting formsmass.gov

Procedure

Step 1: Report and immediate mitigation

The workforce member who causes or discovers a suspected breach takes the immediate mitigation within reach: stop and close the record, retrieve or delete the information, ask the unintended recipient to return it and confirm no further disclosure. The member reports to the Privacy & Security Officer the same day: privacy@abaswma.org or 413-461-7120, or any POL-003 reporting channel. When in doubt, the member reports. The Privacy & Security Officer decides whether the incident is a breach.

Step 2: Ticket

The Compliance Officer or designee opens a compliance ticket for the incident the day the report arrives, following POL-003-SOP intake: the narrative preserved verbatim, access restricted. Privacy tickets route to the Privacy & Security Officer. The ticket is the incident's working file. Every artifact this procedure produces files there.

Step 3: Containment

The Privacy & Security Officer directs containment the same day the report arrives. For electronic incidents the officer acts under administrative access: lock the affected account, disable sharing on the affected record, isolate the affected device, or remotely wipe a lost device. For paper incidents the officer retrieves the document or obtains the recipient's written confirmation that it was returned or destroyed.

The officer preserves the evidence the assessment needs before any wipe, reset, or restoration. If an active intrusion such as ransomware is suspected, the officer disconnects affected systems from the network and preserves them unaltered for investigation.

If a cyber liability policy is in force, the officer reports the incident to the carrier on the policy's clock.

Step 4: Risk assessment

The Privacy & Security Officer completes the Breach Risk Assessment (CFM-014 Form 1) for every reported incident. The assessment determines whether unsecured PHI is involved, whether a POL-014 exception applies, the probability of compromise under the four factors, and whether the incident is a security breach of personal information under M.G.L. c. 93H.

If the assessment concludes no notice is required, the officer documents the determination and its facts on Form 1 and the ticket proceeds to Step 7.

If the assessment confirms a breach, the officer records every notice lane the facts trigger and proceeds to Step 5.

Step 5: Notification

The Privacy & Security Officer prepares each triggered notice from the Breach Notification Templates Pack and issues it on its clock in the Notice Lanes table. The Executive Director approves each external notice before it is sent. If the cyber liability policy in force requires the carrier's consent before a notice, the officer obtains that consent first.

If a law enforcement official states that notification would impede a criminal investigation or threaten national security, the officer delays the affected notices under POL-014 Section 9 and documents the request.

As facts develop after a notice is sent, the officer supplements the notice on the same lane.

Step 6: Credit monitoring

If a Massachusetts security breach involves a Social Security number, the Privacy & Security Officer contracts third-party credit monitoring for each affected resident: at no cost to the resident, for at least 18 months, with the enrollment information delivered in the resident notice. The officer files the credit monitoring compliance certification with the Attorney General and OCABR. Enrollment is never conditioned on a waiver of the resident's right to a private action.

Step 7: Documentation and closure

The Privacy & Security Officer files the complete record set in the ticket: the report, the containment record, the Breach Risk Assessment, each notice with its date and delivery method, and any law-enforcement delay documentation. Confirmed unsecured-PHI breaches affecting fewer than 500 individuals are entered in the breach log. Sanctions and corrective action route through POL-003-SOP resolution. The Compliance Officer closes the ticket when the record set is complete.

Gates

Six gates hold across every incident.

  1. An external notice is sent only with the Privacy & Security Officer's preparation and the Executive Director's approval. No other workforce member notifies clients, families, regulators, media, or any outside party.
  2. A notification determination stands only on a completed Breach Risk Assessment (CFM-014 Form 1) on file. A breach of unsecured PHI is presumed until the assessment documents a low probability of compromise or an applicable exception.
  3. Individual HIPAA notices issue no later than 60 days after discovery. The clock runs from the discovery date. An unfinished investigation does not extend it.
  4. Massachusetts notice is never delayed to determine the total number of residents affected.
  5. The Massachusetts resident notice never states the nature of the breach or the number of residents affected. The HIPAA individual notice and the Massachusetts resident notice are separate instruments. Where both apply, the resident receives both.
  6. Where a cyber liability policy in force requires the carrier's consent before notification, that consent precedes the notices the policy names.

Records

Every artifact of an incident files in its compliance ticket: the report, the containment record, the Breach Risk Assessment, each notice with its date and delivery method, substitute-notice documentation, the credit monitoring certification, and law-enforcement delay documentation. The ticket file is stored and access-controlled under POL-003-SOP.

The breach log holds every confirmed breach of unsecured PHI affecting fewer than 500 individuals, with the fields the HHS portal filing requires. The Privacy & Security Officer maintains the log and submits the calendar year's entries within 60 days after the year ends.

The Privacy & Security Officer retains all breach documentation for six years. Each notified individual keeps the notice they received; a copy of each notice files in the ticket.

Competency

A workforce member performs this procedure independently only after demonstrating it to the Executive Director or their designee. Each skill in the table is demonstrated unaided and error-free on two occasions, and at least one occasion uses a scenario the member has not seen in training.

Skill Demonstration
Receive and log a reportOpens the ticket, preserves the narrative verbatim, restricts access, and routes the ticket
Direct containmentSelects and directs the correct containment for one electronic and one paper scenario, preserving evidence before any wipe or reset
Run the risk assessmentCompletes Form 1 on scenarios that include one exception case, one presumption-stands case, and one personal-information case
Select notice lanesNames every triggered lane, its clock, and its instrument for a scenario, including one scenario that triggers several lanes
Prepare the noticesPrepares an individual notice carrying every required element, and the Massachusetts pair with no content crossing between them
Close the recordFiles the complete record set, enters the breach log where required, and states the retention period

The workforce reporting duty in Step 1 is trained under POL-014's training requirement, outside this table.