Evidence explainer

Infection, immunity, and cancer

How Investigators Read an Outbreak: Case Definitions, Attack Rates, and the Epidemic Curve

A case definition decides who counts, an attack rate measures how often illness follows a shared source, and the epidemic curve plots onsets over time. Each has one predictable way of misleading.

Fully reviewed by Jasaman (Jasmin) Tojjar, MD, PhD

On this page
  1. Key points
  2. The starting question: who counts?
  3. Turning cases into a rate
  4. The picture over time
  5. Where each tool misleads
  6. Reading them together

Investigators read an outbreak by pairing three tools. A case definition decides who counts as ill, an attack rate measures how often illness follows a shared source, and an epidemic curve plots when people got sick. Used together they turn a pile of reports into a testable story about how an illness spread. Used alone, each one can point you the wrong way without warning.

Key points#

The starting question: who counts?#

Every outbreak investigation opens with a deceptively simple question. Out of all the people feeling unwell, who actually has the illness under study? The answer is a case definition, a standard set of criteria that anyone on the team can apply the same way. The U.S. Centers for Disease Control and Prevention, whose long-running Principles of Epidemiology course codifies these methods, describes a case definition as clinical criteria paired with limits on time, place, and person. In plain terms, that means a named set of symptoms or laboratory findings, within a defined stretch of dates, in a defined area, among a defined group.

Definitions are usually built in tiers. A confirmed case carries laboratory proof. A probable case shows the typical picture or a clear epidemiologic link to a confirmed case. A suspected case clears only a looser clinical bar. Think of it as three concentric rings, from a small certain core outward to a wide provisional edge.

The tiers exist because a case definition is a dial between catching everything and catching only the real thing. Early on, investigators turn the dial toward sensitivity, counting confirmed, probable, and suspected cases together to size up the problem quickly. Later, when they start testing what caused it, they often turn the dial toward specificity and restrict the analysis to confirmed cases, because stray false positives can drown out a genuine signal.

Turning cases into a rate#

Counting the ill is only half the arithmetic. To judge whether a particular source is to blame, investigators convert counts into an attack rate, which is simply the number of new cases divided by the number of people who could have been affected over the period in question. In a foodborne investigation the everyday version is the food-specific attack rate, the share of people who ate a given dish and then fell ill. The CDC teaching example is a gathering where 30 of the 99 guests who ate potato salad became sick, an attack rate of about 30 percent.

A single rate says little on its own. Its value comes from comparison. Investigators calculate the attack rate among people who ate a suspect dish and, separately, among people who did not, then set one against the other. A rate that is much higher among those who ate the dish points toward it. For illnesses that pass between people, a related figure, the secondary attack rate, counts cases among close contacts divided by the number of contacts, which captures how readily the illness spreads onward.

The picture over time#

Plot each case by its date of onset and the histogram you get, the epidemic curve, takes on a shape that rules some stories in and others out.

The curve also does hidden quantitative work. In a point-source outbreak with a known agent, investigators can count backward from the peak by one average incubation period, and backward from the first case by the shortest incubation period, to bracket the likely window during which people met the source. That bracketed window often tells them which meal or event to interrogate.

Where each tool misleads#

The reason these tools travel together is that each carries a specific, predictable blind spot.

The case definition can distort the count. A loose definition inflates the numbers and can sweep in unrelated illness, diluting the very signal the team is chasing. A tight, laboratory-anchored definition can miss the tail of milder cases and tilt the sample toward people with the access and the severity to get tested. And because the case definition determines who feeds every later calculation, changing it midstream can shift the whole apparent trajectory of an outbreak for reasons that have nothing to do with transmission.

The attack rate depends on a shaky denominator. The comparison only works if the team knows who was truly at risk, which usually rests on people recalling what they ate days earlier. Suspected sources also travel in pairs, so a salad and the dressing served with it can be statistically inseparable. And at a small gathering, a swing of two or three cases can move a rate dramatically, dressing up a chance pattern as a culprit.

The epidemic curve is only as honest as its onset dates. Reporting delays chop off the right-hand edge, making an ongoing outbreak look as if it is already easing. Fuzzy recall blurs the onset dates that define each bar. Weekend and holiday reporting gaps carve out artificial dips that mimic real drops in transmission. And a mixed situation, a point source that then seeds a few person-to-person cases, can smear into a single ambiguous hump, and an ambiguous hump will not choose between your hypotheses for you.

Reading them together#

The power of an outbreak investigation is triangulation, not any single measurement. The case definition fixes the population the other two tools work on. The attack rate measures how concentrated the risk is inside that population. The epidemic curve places the whole thing in time and proposes a mode of transmission to test. Any one of the three, read alone, can send a team down the wrong path. Read together, with each blind spot in plain view, they convert scattered reports of illness into a defensible account of what happened and why.

Sources and further reading

  1. CDC Principles of Epidemiology, Lesson 6 (Investigating an Outbreak)
  2. CDC Principles of Epidemiology, Lesson 3 (Attack Rate)
  3. CDC Principles of Epidemiology, Glossary

Questions and answers

Why do investigators change the case definition partway through?

Because the two halves of an investigation ask different things. Early on the goal is to find every possible case and gauge the size of the problem, which calls for a wide, sensitive definition. Once the team starts pinning down a cause, a narrower, confirmed-only definition keeps stray false positives from washing out a real association.

What does the shape of an epidemic curve actually tell you?

The shape narrows the plausible transmission stories. A single steep peak suggests one shared source at one time, a long plateau suggests an ongoing common source, and a series of rising peaks spaced by the incubation period suggests spread from person to person. The shape points toward a hypothesis, which is then tested against attack rates and other evidence rather than trusted on its own.