Workforce reports a lost phone in minutes
A nurse follows IR-6 training and reports immediately. Wipe and resets finish before weekend exposure grows — reporting culture beats perfect technology.
IR-6 requires reporting information system security incidents to organization-defined authorities within organization-defined time periods, and reporting incident information to related providers or coordinating bodies as required. In healthcare this spans internal escalation, BA notifications, law enforcement when appropriate, and HIPAA breach notification to individuals, HHS/OCR, and media when thresholds are met.
Ensure the right people and organizations learn about incidents fast enough to respond, meet legal duties, and support coordinated defense.
How this control shows up in healthcare and HIPAA-covered environments.
A nurse follows IR-6 training and reports immediately. Wipe and resets finish before weekend exposure grows — reporting culture beats perfect technology.
A billing BA must notify the covered entity within 24–72 hours per BAA. IR-6 contract language plus a tested intake path lets privacy start HIPAA clocks without delay.
After risk assessment confirms a breach, IR-6 checklists drive individual notices, OCR submission, and media notice on HIPAA timelines — coordinated with leadership messaging.
Assessors check that reporting duties are known and evidenced. Late or missing documentation of notices is high severity under HIPAA breach rules.
How this NIST control supports HIPAA Security Rule expectations.
Follow your published channel (security/privacy hotline or ticket). Train that reporting early is mandatory, not optional.
No. IR-6 covers organization-defined authorities. OCR/individual notice applies when a breach of unsecured PHI meets HIPAA criteria.
Set this in the BAA — commonly measured in hours/days — so you can meet downstream HIPAA deadlines.
Related controls that commonly accompany IR-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.