Government Accountability Office (GAO) Data Breach Reporting Survey



NOTE: New deadline to return surveys is February 11.

Link to survey



Congress has asked the U.S. Government Accountability Office (GAO), the nonpartisan investigative arm of the Congress, to review the number of data breaches that covered entities have reported to the Department of Health and Human Services (HHS) since 2015. In part, GAO is seeking to answer what challenges related to HHS’s data breach reporting requirements, if any, have covered entities reported and what efforts has HHS taken to address them.

To help inform this work, GAO is requesting input from Covered Entities and Business Associates in the healthcare sector. We are interested in your experiences with complying with HHS’s data breach reporting requirements and HHS’s efforts to improve the data breach reporting process. Health-ISAC, Health Sector Coordinating Council (HSCC), and American Hospital Association (AHA) have agreed to distribute these questions on behalf of GAO. The questions are from GAO and the responses will be provided in aggregate to GAO by these organizations. The only specific, individually identifiable information about your organization provided to GAO will be your email address if you voluntarily choose to share that information in the survey, or any identifiable information you provide in your responses to our open-ended questions. Please note GAO will not attribute specific comments to specific individuals and/or organizations in their report.

When using SurveyMonkey, your responses are securely stored in SurveyMonkey’s SOC 2 accredited data centers that adhere to security and technical best practices. SurveyMonkey ensures that collected data is transmitted over a secure HTTPS connection. Data at rest is encrypted using industry-standard encryption algorithms and strength. More on SurveyMonkey’s security and data privacy protection can be found here.

To meet GAO’s reporting requirements, we are requesting that you provide responses to this questionnaire by 4PM EST on Friday, February 11, 2022. We are requesting only one survey submission from each covered entity or business associate.

Thank you in advance for your assistance in our work and if you have any questions, please contact David Matcham at or Keith Kim at



Thank you for taking the time to participate in the survey.  It should take you about 2 minutes.

Translate »