Skip to main content
CoreFolioHIPAA
How-to

HIPAA breach notification requirements: what your practice must do and when

The HIPAA Breach Notification Rule sets firm deadlines for notifying patients and regulators. Every obligation, deadline, and the four-factor analysis.

By CoreFolio

9-minute read

A security incident at your practice does not automatically mean you must send breach notification letters to patients and file a report with the U.S. Department of Health and Human Services (HHS). But the wrong assumption in the other direction — that a breach does not require notification when it does — is a HIPAA violation in its own right.

The HIPAA Breach Notification Rule (45 CFR §§ 164.400–164.414) creates a structured process for determining whether an incident constitutes a reportable breach, and if so, what must be done, for whom, and by when.

What the rule covers: unsecured PHI

The breach notification obligations apply only to “unsecured protected health information.” Under 45 CFR § 164.402, unsecured protected health information (PHI) is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified by HHS.1

HHS has specified two acceptable methodologies:

  • Encryption conforming to NIST Special Publication 800-111 (for data at rest) or SP 800-52/SP 800-77/SP 800-113 (for data in transit)
  • Destruction — paper media shredded or burned; electronic media cleared, purged, or destroyed per NIST SP 800-88

If the PHI involved in an incident has been encrypted to these standards, it is secured, and breach notification is not required. This is the primary operational incentive for implementing encryption.2

Step 1: determine whether a breach occurred

A breach is defined in 45 CFR § 164.402 as an impermissible acquisition, access, use, or disclosure of unsecured PHI — unless one of three exceptions applies:

Exception 1 — Unintentional access by a workforce member: An unintentional acquisition, access, or use of PHI by a workforce member acting under the authority of the covered entity, if made in good faith and within the scope of authority, and the information is not further used or disclosed impermissibly.

Exception 2 — Inadvertent disclosure to another authorized person: An inadvertent disclosure by a person authorized to access PHI at a covered entity or business associate (BA) to another person authorized to access PHI at the same entity, if the information received is not further used or disclosed impermissibly.

Exception 3 — Good faith belief of inability to retain: A disclosure to an unauthorized person where the covered entity has a good faith belief that the unauthorized person would not reasonably be able to retain the information.

If none of the three exceptions applies, the incident is presumed to be a reportable breach — unless the covered entity can demonstrate a low probability of PHI compromise using the four-factor analysis.

Step 2: the four-factor risk assessment

Under 45 CFR § 164.402(2), a covered entity may rebut the presumption of a reportable breach by demonstrating, through a documented risk assessment, that there is a low probability that PHI has been compromised.3 The assessment must consider at least four factors:

1. The nature and extent of the PHI involved — including the types of identifiers and the likelihood of re-identification. PHI including Social Security numbers, financial information, or sensitive diagnosis codes carries a higher risk weight than PHI limited to name and appointment dates.

2. Who used or accessed the PHI, or to whom the disclosure was made — whether the recipient was likely to use the PHI impermissibly based on what is known about their identity and purpose.

3. Whether the PHI was actually acquired or viewed — as opposed to only the opportunity existing. Technical evidence (logs, system records, forensic analysis) is relevant here.

4. The extent to which the risk to the PHI has been mitigated — for example, whether the covered entity obtained satisfactory assurances from the recipient that the information will not be used or disclosed, and whether the recipient returned or destroyed the PHI.

This assessment must be documented. The Office for Civil Rights (OCR) may review it in an investigation. An undocumented risk assessment is treated as if it was not conducted.

Who must be notified, and when

Individual notification

Under 45 CFR § 164.404, covered entities must notify each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach.4

Timeline: Without unreasonable delay, and no later than 60 calendar days after discovery.

Discovery date: The date the covered entity knew, or reasonably should have known, about the breach. A covered entity is deemed to have discovered a breach when a workforce member or agent (other than the individual committing the breach) first knows of the incident with reasonable diligence.

Method: Written notification by first-class mail, or by email if the individual has agreed to receive electronic notices. When contact information is insufficient for 10 or more individuals, the covered entity must post a prominent notice on its website for 90 days or notify through major print or broadcast media.

Content required (45 CFR § 164.404(c)):

  • A brief description of the breach
  • The types of information involved
  • Steps individuals should take to protect themselves
  • A brief description of what the covered entity is doing to investigate, mitigate harm, and prevent future occurrences
  • Contact information for questions

HHS notification

Breaches affecting 500 or more individuals: The covered entity must notify HHS contemporaneously with the individual notifications — meaning within the same 60-calendar-day window from discovery.5 Notification is submitted electronically through the HHS breach reporting portal at hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting.

Breaches affecting fewer than 500 individuals: The covered entity must maintain a log and report to HHS within 60 days after the end of the calendar year in which the breach was discovered. In practice, breaches discovered in any month of 2026 must be reported to HHS by March 1, 2027. There is no minimum number — even a breach affecting one individual must be logged and reported.

Media notification

Under 45 CFR § 164.406, for breaches affecting 500 or more individuals in a single state or jurisdiction, the covered entity must also provide notice to prominent media outlets serving the affected state or jurisdiction, within 60 days of discovery.6

Business associate obligations

When a business associate (BA) discovers a breach of unsecured PHI, the BA must notify the covered entity without unreasonable delay, and no later than 60 days following discovery.7

Whether the covered entity’s own 60-day clock runs from the BA’s discovery date or from the date the covered entity is notified depends on the relationship. Discovery is imputed to the covered entity when the breach is known to any workforce member or agent of the covered entity, and whether a BA is an agent is determined under the federal common law of agency.8 If the BA is acting as an agent of the covered entity, the BA’s discovery is imputed and the covered entity’s clock runs from that earlier date. If the BA is not an agent — the typical independent-contractor arrangement — the covered entity is generally treated as discovering the breach when the BA notifies it. Either way, a BA that delays its report compresses the time the covered entity has left, so the BAA should require prompt notification and the covered entity should not assume it holds a full 60 days from the day it hears of the incident.

Under 45 CFR § 164.410, BAs must include in their breach report: the identification of each individual whose PHI was involved (or where not possible, the best available information for use by the covered entity), and any other available information the covered entity needs to make its notifications.

BA notification obligations must be reflected in the business associate agreement (BAA).

What the Security Rule NPRM does not change

The Security Rule Notice of Proposed Rulemaking (NPRM) (90 Fed. Reg. 898, January 6, 2025) does not modify the Breach Notification Rule. The HHS reporting deadlines in this guide remain the operative requirements.

The NPRM proposes separate Security Rule obligations with their own timelines — a 72-hour disaster-recovery SLA for restoring critical relevant electronic information systems after an incident, 24-hour notice when a business associate activates its contingency plan, and 24-hour notice to other regulated entities when a workforce member’s access to ePHI changes or terminates. None of those are HHS breach notifications.9

This proposal has not been finalized as of July 2026.

Common mistakes in breach response

Not documenting the risk assessment. If a covered entity concludes that a low probability of PHI compromise exists and notification is not required, that conclusion must be supported by a documented four-factor assessment. An informal judgment that “nothing bad probably happened” is not defensible.

Missing the discovery clock. The 60-day clock runs from discovery — the date a workforce member knew or should have known. Practices that delay internal reporting create compounding liability: the notification deadline may expire before the covered entity even begins its response.

Confusing the fewer-than-500 HHS reporting deadline. Small-practice breaches affecting fewer than 500 individuals do not require immediate HHS reporting. But they must be logged, and the annual report must be submitted. A common error is treating the lack of an immediate deadline as permission to not report at all.

No breach response plan. A covered entity with no written incident response procedures — required under 45 CFR § 164.308(a)(6) — has no framework for conducting the four-factor analysis, preserving evidence, or meeting notification deadlines under pressure.

What to prepare before an incident

  • A written security incident and breach response policy
  • An internal escalation chain (who is notified first, in what order, within what time frame)
  • A four-factor risk assessment template
  • A breach log, maintained even for incidents that did not require external notification
  • Contact information for the HHS breach reporting portal
  • A template individual notification letter
  • Your BAA language confirming business associates’ reporting obligations

Sources

Footnotes

  1. 45 CFR § 164.402 (definitions of “breach” and “unsecured protected health information”; the three breach exceptions and the four-factor test). https://www.ecfr.gov/current/title-45/section-164.402

  2. HHS, Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals (encryption per NIST SP 800-111 for data at rest and SP 800-52/800-77/800-113 in transit; destruction per NIST SP 800-88). https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html

  3. 45 CFR § 164.402(2) (rebutting the breach presumption through a documented four-factor risk assessment). https://www.ecfr.gov/current/title-45/section-164.402

  4. 45 CFR § 164.404 (notification to individuals — timeliness, methods, and required content). https://www.ecfr.gov/current/title-45/section-164.404

  5. 45 CFR § 164.408 (notification to the Secretary of HHS — 500-or-more vs. fewer-than-500 timing). https://www.ecfr.gov/current/title-45/section-164.408

  6. 45 CFR § 164.406 (notification to the media for breaches affecting 500 or more residents of a state or jurisdiction). https://www.ecfr.gov/current/title-45/section-164.406

  7. 45 CFR § 164.410 (business associate breach notification to the covered entity). https://www.ecfr.gov/current/title-45/section-164.410

  8. 45 CFR § 164.404(a)(2) (a breach is “treated as discovered” when known to a workforce member or agent of the covered entity, agency determined under the federal common law of agency). https://www.ecfr.gov/current/title-45/section-164.404

  9. HIPAA Security Rule NPRM, 90 Fed. Reg. 898 (January 6, 2025). Proposed; not finalized as of July 2026. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information