Program status: in progress. These policies are written and operating, but Business Associate Agreements, the formal risk analysis, and final policy adoption are not yet complete. Nothing on this page is a claim of HIPAA compliance or certification.
1. Purpose and scope
This procedure governs how Tetherhealth.io, LLC responds when personal or health-related information may have been accessed, disclosed, altered, or lost without authorization. It is written to satisfy the HIPAA Breach Notification Rule (45 CFR §§164.400–414) and applicable U.S. state breach-notification laws, and it applies whether the incident happens in our own systems or at a sub-processor.
2. Definitions
- Security incident — any suspected or confirmed event that threatens the confidentiality, integrity, or availability of information or the systems holding it.
- Breach — an incident that resulted in unauthorized acquisition, access, use, or disclosure of protected information, unless a risk assessment shows a low probability that the information was compromised.
- Affected individual — any person whose information was, or may reasonably have been, involved.
3. Detection and reporting
Incidents reach us through automated alerts, log review, sub-processor notices, customer or partner reports, and outside security researchers. Every workforce member must report a suspected incident to the Privacy & Security Officer immediately and no later than 24 hours after discovery. Anyone outside the company can report one to ash@tetherhealth.io; we acknowledge reports within three business days.
4. Response timeline
- Within 24 hours of discovery — report received, incident logged, Privacy & Security Officer notified, and a response lead assigned.
- Within 72 hours — immediate containment: revoke compromised credentials, close the exposure, and and preserve logs and evidence prior to any remediation activity.
- Within 10 business days — investigation and written risk assessment completed, scope and affected individuals identified.
- Without unreasonable delay, and no later than 60 calendar days after discovery — notification to affected individuals when the assessment concludes a breach occurred.
- Within 30 days of closing the incident — corrective actions implemented and the post-incident review documented.
When we act as a business associate for a covered entity, we notify that customer without unreasonable delay and no later than 10 calendar days after discovery, so they can meet their own obligations, and we support their notifications with the facts we hold.
5. Risk assessment
Unless we treat the incident as a breach outright, we assess at least these four factors and document the conclusion:
- The nature and extent of the information involved, including how identifying and how sensitive it is.
- Who used the information or to whom it was disclosed.
- Whether the information was actually acquired or viewed.
- The extent to which the risk has been mitigated.
Information that was properly encrypted and whose keys were not compromised is not treated as a breach.
6. Notification to affected individuals
Notice is sent by email to the address on the account, with an in-app notice as well. If we lack current contact details for ten or more people, we post a substitute notice on our website for 90 days. Each notice includes, in plain language:
- What happened and the date it happened and was discovered.
- What types of information were involved.
- What we have done to contain it and what we are doing to prevent a recurrence.
- What the person can do to protect themselves.
- Contact information for inquiries, including a telephone number or email address monitored by personnel.
7. Notification to regulators and media
- 500 or more individuals — notice to the Secretary of the U.S. Department of Health and Human Services without unreasonable delay and no later than 60 calendar days after discovery, plus notice to prominent media outlets serving the affected state or jurisdiction.
- Fewer than 500 individuals — logged and reported to the Secretary within 60 days after the end of the calendar year in which the breach was discovered.
- State authorities — notified where state law requires it, on the timeline that law sets.
8. Documentation
Every incident is documented with the timeline, the facts, the risk assessment and its conclusion, the notifications sent, and the corrective actions taken — including incidents determined not to be breaches, with the reasoning. Records are retained for at least six years.
9. Post-incident review and prevention
Within 30 days of closing an incident, we conduct a non-punitive post-incident review documenting the sequence of events, the control failures that permitted the incident, and the technical, procedural, or training changes required to prevent recurrence. Each corrective action is assigned an owner and a completion date and is tracked to closure under the administrative safeguards policy.
10. Ownership and review
The Privacy & Security Officer owns this procedure and reviews it at least annually, and after any incident that tested it.
