← Back to Blog

The First 24 Hours After You Suspect a Breach

The Worst Time to Plan Is During the Emergency

A staff member calls: a workstation is behaving strangely, files have odd extensions, or someone clicked something and now there is a ransom note. Or your monitoring flags that your credentials surfaced on the dark web. The clock just started, and what you do in the next 24 hours matters more than almost anything you will do afterward. The problem is that this is precisely when clear thinking is hardest — which is exactly why this needs to be decided in advance. Read this now. Print it. Put it where your team can find it.

Hour 0–1: Contain, Don't Destroy

The instinct under attack is to wipe the affected machine and "make it go away." Resist it. Your first job is to contain the incident while preserving evidence — the two have to happen together.

  • Isolate, don't power off. Disconnect the affected device from the network — unplug the network cable, disable Wi-Fi — to stop spread. But do not shut it down or start deleting; powering off can destroy evidence in memory, and wiping it destroys the forensic trail you may legally need.
  • Disable compromised accounts, don't delete them. If a credential is suspected stolen, disable the account and force a password reset. Deleting it erases the audit trail of what it did.
  • Stop the bleeding at the perimeter if an external connection is implicated — block the suspicious traffic, but keep the logs.

Hour 1–3: Activate Your People

This is where a prepared practice pulls ahead. Pull out your incident contact sheet — the one-page list of who to call — and start working it. (If you do not have one yet, building it is the first of this week's tips.) You need to engage, in roughly this order:

  • The incident lead — one person who owns coordination and decisions, so the response does not fragment.
  • Your IT/security provider — whoever can investigate and contain at a technical level. Speed matters; do not wait for business hours if the incident is live.
  • Your cyber-insurance carrier — many policies require prompt notification and provide a breach coach and approved forensic vendors. Calling late can jeopardize coverage. This is often the most overlooked early call.
  • Legal counsel — ideally privacy-experienced, to guide the determination of whether this is a reportable breach and to protect privilege over the investigation.

Hour 3–12: Investigate and Scope

With the right people engaged, the question shifts from "what is happening" to "how far does it go." The goal of this phase is to understand scope, because scope drives every obligation that follows:

  • What was accessed or affected? Which systems, which accounts, and — the question that defines everything — was PHI involved?
  • How did they get in? Stolen credential, unpatched system, phishing, a vendor connection? You need this both to close the hole and to document it.
  • Is it still active? Confirm containment actually held and the attacker no longer has access.

This is the phase where your audit logs earn their entire existence. A practice that has been reviewing logs all along can answer these questions in hours. A practice that never collected or reviewed them is left guessing — and "we could not determine the scope" is both an operational failure and a compliance one, because the breach-notification rules often presume PHI was compromised when you cannot prove otherwise.

Hour 12–24: Document and Decide

By the end of the first day, the emergency should be contained and the focus moves to the record and the obligations:

  • Write everything down, with timestamps. What you found, when, who did what, and why each decision was made. This contemporaneous record is invaluable later — for the insurer, for counsel, and potentially for OCR. Start it at hour zero and keep it running.
  • Begin the breach risk assessment. With counsel, work through whether this is a reportable breach under HIPAA — the formal four-factor analysis of the nature of the PHI, who accessed it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated.
  • Note the clock. If it is a reportable breach, HIPAA requires notification to affected individuals and HHS without unreasonable delay and no later than 60 days from discovery — and if a business associate's breach affects your PHI, the notification obligation flows to you. Knowing this on day one prevents a second, self-inflicted violation later.

The Real Lesson: This Is a Document You Write Beforehand

Every item above is something you can decide today, calmly, instead of inventing at 2 a.m. with a ransom note on the screen. The practices that come through incidents with their reputation, their coverage, and their compliance posture intact are not the ones that never got hit — given the threat landscape, getting hit is increasingly a matter of when. They are the ones who had a plan, knew who to call, preserved their evidence, and could prove what happened. The first 24 hours are won or lost before the incident ever begins.

Related Reading

Call to Action

Would your team know exactly what to do in the first hour? Schedule a walkthrough to see how HIPAA Security Suite helps you build an incident response plan and keep the logs that make scoping a breach possible, or take the 3-minute readiness quiz.

Ready to simplify your HIPAA compliance?

See how HIPAA Security Suite can protect your organization.

Request a Demo