Skip to main content

Incident Reporting

How to Record an Incident in Readily

Z
Written by Zenobia

Please follow this link to a video to discover Incident Reporting in Readily.

NOTE: The video shows the HIPAA stream, but the FWA and Compliance streams are the exact same within their corresponding sub-modules.

Overview

The Incidents module is your centralized record for HIPAA privacy incidents. Instead of emails and spreadsheets, every incident is logged as a case with a complete record: how it reached Privacy, what happened, how it was assessed, and how it was resolved. Each case is assigned a HIPAA Privacy Case # automatically, and every change is timestamped for audit readiness.

Incidents reach the Privacy team through the channels you already use — the daily email, Teams, a HIPAA notification — and are then recorded in Readily by the Privacy

team. The module is the system of record, not the front door.

Use it to:

- Record suspected or confirmed privacy incidents

- Track each case from intake through assessment and close-out

- Run Risk Assessment

- Track DHCS reporting and the 10-day PIR clock

- Maintain an audit-ready log of all incidents and outcomes

Before You Start

Gather the basics. The case is created and numbered the moment you start typing, so you can leave and come back — but intake goes faster with these on hand:

- Date of Incident and Date of Knowledge (when it was discovered) — these are

often different, and both matter for the reporting clock

- Date Reported to Privacy — when it reached your team; this is the anchor date for

reports

- Incident Category — Email, Mail, Phone, Other Electronic, Stolen / Lost Device,

Referred to Provider, No Privacy Issue, or Other

- Description of Case — a concise, factual summary

- Supporting documentation — for an Email or Mail incident, a copy of the misdirected

document is required

- Number of Members Involved, and how many are minors

- Line of Business

- Intake Method — how the incident reached you (Email, Teams chat, HIPAA Notification, Quality Suite, Other)

Notifications & Emails

Readily sends a small, fixed set of emails. Everything automatic goes out on a single 8:00 AM Pacific run each morning; everything else is sent the moment someone is given work on a case. Nothing is ever sent to a member, a provider, a vendor or the person who reported the incident — member notifications and DHCS submissions are recorded in Readily, not sent from it.

Daily 8am summary — the cases you follow

- What triggers it: any change in the previous 24 hours to a case you follow. Nothing

changed, no email.

- When: once a day, at 8:00 AM Pacific.

- What's in it: the net change over the day, not every save. A status that moved Open → Pending → Closed reads as Open → Closed, and a field edited and put back doesn't appear at all. One email covers every HIPAA case you follow — a long list is trimmed to the busiest cases with a count of the rest. Attachments are not listed as field changes.

- To follow one case: use Following at the top of the case.

- To follow every HIPAA case: use Alerts on the HIPAA list. It covers cases opened later too, and a Privacy lead can enrol colleagues from the same panel. Switching yourself off is sticky — a later enrolment by someone else will not switch you back on.

- Only people with HIPAA access receive it; the 8am run re-checks permission before

sending. HIPAA and FWA are never combined into one email.

Daily 8am task reminders

- What triggers it: an incomplete task due in exactly 3 days. One digest per person

covering all their tasks — not one email per task.

- When: the same 8:00 AM Pacific run, so the morning's mail arrives as one block.

What is never sent automatically

- No email on case creation, status change or close-out — including to the person who reported the incident.

- No email for notes, attachments or Activity Log entries on their own — they reach

followers in the 8am summary

Did this answer your question?