Control Objective
Handle security incidents affecting systems with ePHI through a repeatable lifecycle so damage is limited, evidence is preserved, and operations return safely.
Real-World Use Cases
How this control shows up in healthcare and HIPAA-covered environments.
Ransomware on a clinic file server
EDR alerts on encryption behavior. IR-4 playbook isolates the server, resets privileged credentials, engages backups per CP, and opens a parallel privacy assessment for possible ePHI exfiltration — not just IT restore.
Lost unencrypted laptop
A care manager reports a missing laptop with cached mail. Handling steps include remote wipe (AC-19), password resets, ticket timeline, and privacy’s four-factor breach assessment under HIPAA.
Inappropriate VIP chart access
AU-6 review finds unjustified views. IR-4 privacy playbook interviews the user, preserves EHR audit logs, applies sanctions process, and determines if notification duties apply.
Audit Considerations
Auditors want evidence of real handling — tickets, timelines, decisions — not only a policy. Map IR-4 artifacts to HIPAA § 164.308(a)(6).
HIPAA Mapping
How this NIST control supports HIPAA Security Rule expectations.
- 164.308(a)(6) Security Incident Procedures — identify and respond to known security incidents; mitigate harmful effects; document incidents and outcomes.
- 164.404–414 Breach Notification Rule — handling feeds risk assessment of unsecured PHI compromises.
- 164.308(a)(7) Contingency Plan — coordinate when incidents disrupt operations.
- 164.312(b) Audit Controls — logs support detection and analysis phases.