Phase 10: Incident Response
Applies to: All staff across any phase of the patient engagement workflow - this module applies whenever a suspected PHI, PII, or financial data incident is identified, regardless of which phase is active
Sequence note: Phases 0-4 sequential; phase 10 anytime; not all phases apply
What you'll learn
- Recognize what constitutes a reportable incident or breach and initiate the 4-hour reporting requirement immediately upon awareness
- Identify the correct escalation contacts and follow the 'See It, Report It, Don't Touch It' protocol without attempting independent investigation or remediation
- Apply the correct severity classification, containment steps, and post-incident documentation timelines from the Security Incident Response Guide and PHI Handling SOP
Lesson
What Counts as a Reportable Incident
Any suspected PHI, PII, or financial data incident must be treated as reportable from the moment of awareness. This includes suspected exposures - not just confirmed breaches. The 4-hour reporting clock starts at the moment of awareness, not at the moment of confirmation. Do not wait for certainty before reporting; the determination of whether a breach occurred is made by Legal/Compliance, not by the staff member who identified the concern.
Source: slide 35 - PHI Handling and HIPAA Safeguards_Final_8-2026
See It, Report It, Don't Touch It
The incident response protocol follows three steps. First, See It: identify the suspected incident and note the time of awareness. Second, Report It: report to BOTH the EVP Director of IT AND the Director of Privacy and Information Security at privacy@assembledintelligence.co within 4 hours of awareness; a written follow-up is required within 24 hours. Third, Don't Touch It: do not attempt to investigate or remediate the issue independently - IT handles containment and evidence preservation. No external communication about any incident is permitted without explicit approval from the Privacy Lead and Executive Leadership.
Source: slide 35 - Security Incident Response Guide_Final_8-2026
HARD STOP - No Independent Investigation, No External Communication
Staff must not attempt to investigate, remediate, or contain a suspected incident on their own. IT is responsible for containment and evidence preservation. Equally, no external communication about any incident - including to clients, vendors, or the public - may occur without approval from the Privacy Lead and Executive Leadership. Unauthorized external communication is a separate violation from the incident itself.
Source: slide 35 - Security Incident Response Guide_Final_8-2026
Severity Classification and Response Times
All incidents are classified by severity. P1 (confirmed breach or outage) requires an immediate response. P2 (major impact, limited to a function or system) requires a response within 4 hours. P3 (suspicious activity, limited impact) requires a response within 1 business day. P4 (minor issues, self-contained) requires a response within 48 hours. P5 (informational) requires a response by the next business day. The severity level determines response urgency but does not change the 4-hour initial reporting requirement for any suspected PHI/PII/financial data incident.
Source: slide 36 - Security Incident Response Guide_Final_8-2026
Breach Notification Requirements
Regulatory breach notification obligations depend on the data type and jurisdiction. Under GDPR, the supervisory authority must be notified within 72 hours of awareness; affected individuals must be notified without undue delay if the breach poses a high risk to them. HIPAA breach notification is assessed per the PHI Handling and HIPAA Safeguards SOP and Security Incident Response Guide Section 12. State law requirements vary by jurisdiction. Notification decisions are made exclusively by Legal and Compliance - staff do not determine notification obligations independently.
Source: slide 36 - FINAL - Assembled Intelligence - Incident Response Plan V2
Containment Steps
Once a suspected incident is reported, IT leads containment. Containment steps include: isolating affected systems or accounts, disabling compromised credentials, and preserving evidence before any cleanup is performed. Staff should not attempt any of these steps independently. Evidence preservation must occur before any remediation or cleanup - acting prematurely can destroy forensic evidence needed to assess scope and meet regulatory requirements.
Source: slide 37 - Security Incident Response Guide_Final_8-2026
Post-Incident Review and Documentation Requirements
After incident closure, a post-incident review must be completed within 5 business days. Root cause analysis, remediation actions, and any procedure updates must be documented within 30 days of incident closure. All incident records must be retained for a minimum of 6 years. These timelines are non-negotiable and apply regardless of incident severity.
Source: slide 37 - PHI Handling and HIPAA Safeguards_Final_8-2026
Scenario
You are a project manager in the middle of Phase 3 Screening. While reviewing a shared folder, you notice that a spreadsheet containing names, contact information, and health condition details for 14 prospective patients was accidentally shared with a link set to 'Anyone with the link.' You do not know how long the link has been active or whether anyone outside the organization accessed it. It is 2:00 PM on a Tuesday.
You have just discovered the exposed spreadsheet. You are not sure whether anyone actually accessed it. What should you do first?
Incorrect. Remediating the sharing link yourself violates the 'Don't Touch It' rule. Evidence preservation must occur before any changes are made to the system. IT is responsible for containment.
Incorrect. The 4-hour reporting clock starts at the moment of awareness, not at the moment of confirmed access. Waiting for confirmation before reporting is a protocol violation and may cause the 4-hour window to be missed.
Correct. Report to both required contacts within 4 hours of awareness. Do not attempt to remediate, investigate, or touch the file settings independently. IT will lead containment and evidence preservation.
Incorrect. No external communication about any incident - including direct outreach to affected individuals - is permitted without approval from the Privacy Lead and Executive Leadership. Notification decisions are made exclusively by Legal and Compliance.
After reporting to IT and the Director of Privacy and Information Security, your manager asks you to write a note to the client explaining there may have been a data issue, so they are not surprised. The Privacy Lead has not yet been consulted. What do you do?
Incorrect. No external communication about any incident - including to clients - is permitted without explicit approval from both the Privacy Lead and Executive Leadership, regardless of how factual or brief the message is.
Correct. External communication about an incident requires approval from the Privacy Lead and Executive Leadership before it is sent. Your manager's request does not override this control. Decline and explain the requirement.
Incorrect. Even a Legal-drafted message cannot be sent without prior approval from the Privacy Lead and Executive Leadership. The approval gate is on the sending of external communication, not only on its drafting.
Incorrect. Vague external communication still constitutes unauthorized external communication about an incident. There is no exception for messages that omit specifics.
Knowledge Check
Select an answer to see feedback. This is practice - it does not affect your score.
When does the 4-hour initial reporting window begin for a suspected PHI/PII/financial data incident?
Incorrect. Confirmation is not required to trigger the reporting obligation. The 4-hour clock starts at the moment of awareness, not confirmation.
Incorrect. Notifying Legal and Compliance is part of the process, but the clock starts earlier - at the moment of awareness.
Correct. The 4-hour reporting requirement begins at the moment of awareness of a suspected incident. Staff must not wait for confirmation before reporting.
Incorrect. Senior leader acknowledgment is not the trigger. The clock begins the moment the staff member becomes aware of the suspected incident.
To whom must a suspected incident be reported, and by what means?
Incorrect. The direct manager alone is not the required contact. The protocol requires reporting to two specific contacts: the EVP Director of IT and the Director of Privacy and Information Security.
Incorrect. Reporting only to the Director of Privacy and Information Security is insufficient. Both the EVP Director of IT and the Director of Privacy and Information Security must be notified.
Correct. Both the EVP Director of IT and the Director of Privacy and Information Security must be notified within 4 hours of awareness. A written follow-up is required within 24 hours.
Incorrect. A company-wide alert is not the required reporting mechanism. Notification goes to the two designated contacts.
Who makes breach notification decisions under GDPR, HIPAA, and applicable state laws?
Incorrect. Individual staff members do not determine notification obligations. That determination is made exclusively by Legal and Compliance.
Incorrect. The EVP Director of IT leads containment but does not determine regulatory notification requirements. That authority rests with Legal and Compliance.
Correct. Notification decisions are made exclusively by Legal and Compliance. Staff do not independently determine whether, when, or how affected parties or regulators must be notified.
Incorrect. The Privacy Lead is a key stakeholder but notification decisions require Legal and Compliance, not the Privacy Lead acting alone.
Key Controls Recap
- [RULE] What Counts as a Reportable Incident
- [WATCH OUT] HARD STOP - No Independent Investigation, No External Communication
- [RULE] Severity Classification and Response Times
- [WATCH OUT] Breach Notification Requirements
- [RULE] Post-Incident Review and Documentation Requirements
You've completed the Phase 10 learning module.
Return to Dayforce and take the Phase 10 quiz.