For Privacy Officers
Incident management
Log security and privacy incidents, then review, investigate, and resolve them (Step 11).
An incident is something like an unauthorized disclosure of Protected Health Information (PHI). Incidents need to be tracked and handled correctly, and the portal makes that a breeze.
Scroll to the bottom-most option on your left and select Incident Management System (or click dashboard Step 11). From the landing page you can Report or Review incidents. While that page is open, new reports pop up as a notice.
Report an incident
Privacy Officers use Incident Management > Report. Employees use Report Incident in their sidebar (see Reporting an incident).
Top to bottom, here's what you fill in:
- Incident Title: a good, explanatory title.
- Description: what occurred, in general terms.
- Date Discovered: when you became aware of a potential violation.
- Date Reported: today.
- Date Privacy Officer Made Aware: usually today.
- Location: in the office? A remote office?
- Affected Systems: a computer? An unencrypted email that got sent?
- Number of Affected Individuals: how many people were affected.

Hit Submit Incident Report. Your report is filed and your Privacy Officer is alerted by email.
The report form attaches the reporter's name, and there's no file upload on it. You set the severity during review.
Review and manage incidents
Open Review
Incident Management > Review. Tiles show Open, Investigating, Resolved, and Critical counts. Filter by status, severity, and category.
Open an incident
Click it and a panel slides in from the right so you can review what happened quickly.
Add findings
Note findings with Add a comment... and Add (comments are internal), or hit Edit in the upper right.
Update or close it
In edit mode, set Severity (Low, Medium, High, Critical) and Status (Open, Investigating, Resolved, Closed), and write Resolution Notes. To close an incident, change the status dropdown to Closed and hit Save.
What the portal does and doesn't do
The portal records incidents and tracks their status. It doesn't decide whether an incident is a reportable breach or calculate notification deadlines. That call depends on the facts.
- For how the Breach Notification Rule works, see the Support Center.
- For help with a specific incident, email hello@oneguyconsulting.com or book a call. Full-Scope plans include incident response guidance.
Each year on December 27, if your organization logged incidents in the past 12 months, the portal emails your Privacy Officer and admin accounts a reminder about submitting to the HHS OCR portal.