HIPAA Breach Notification
The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected individuals, HHS, and in some cases the media, following a breach of unsecured PHI. Created by the HITECH Act in 2009 and tightened by the 2013 Omnibus Rule, it turns every security incident into a legal analysis with hard deadlines. Understanding it before an incident is essential, because the clock starts at discovery, not at your convenience.
Two framing points before the mechanics. First, breach notification is the primary way OCR learns about your organization — every large breach report opens an investigation, and investigators immediately ask for your risk analysis and policies. Second, the rule only applies to unsecured PHI, which makes encryption the most valuable control in this entire domain.
What Constitutes a Breach
A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. Since the Omnibus Rule, the presumption is against you: an impermissible use or disclosure is presumed to be a breach unless you can demonstrate — through a documented risk assessment — a low probability that PHI was compromised. "We don't think anyone saw it" is not a legal position; a written analysis is.
The Encryption Safe Harbor
Notification obligations apply only to unsecured PHI — PHI not rendered unusable, unreadable, or indecipherable through methods specified in HHS guidance: encryption meeting NIST standards (with keys not compromised) or proper destruction. A stolen laptop with full-disk encryption and an uncompromised key is not a reportable breach. A stolen unencrypted laptop is. This single distinction has separated non-events from seven-figure settlements, which is why encryption everywhere is the cheapest breach insurance available.
The Three Exceptions
The rule excludes three narrow situations from the breach definition:
- Unintentional access by a workforce member acting in good faith within their authority, with no further impermissible use — a nurse opens the wrong chart, realizes it, closes it.
- Inadvertent disclosure between two authorized persons at the same entity or arrangement, with no further use.
- Good-faith belief the recipient could not retain the information — a discharge sheet handed to the wrong patient and immediately retrieved.
These are genuinely narrow. Misdirected email to an external party, lost unencrypted media, and ransomware do not fit them.
The Four-Factor Risk Assessment
When an impermissible use or disclosure occurs, you must assess at minimum four factors to determine whether there is a low probability of compromise:
| Factor | Question | Lowers Probability | Raises Probability |
|---|---|---|---|
| 1. Nature and extent of PHI | How sensitive and identifiable is the data? | Limited demographics, no clinical or financial detail | SSNs, diagnoses, mental health, substance use, financial data |
| 2. Unauthorized recipient | Who received or accessed it? | Another HIPAA-regulated entity bound by obligations | Unknown attacker, public exposure, media |
| 3. Was PHI actually acquired or viewed? | Forensic evidence of access vs. mere opportunity | Logs show no access; device recovered with forensic proof of non-access | Confirmed exfiltration, ransomware with data theft |
| 4. Mitigation | Has risk been reduced? | Recipient attests to destruction and is credible; data remotely wiped before access | No mitigation possible; data on leak site |
All four factors must be considered together and the conclusion documented — the burden of proof is on you, and OCR can second-guess a thin analysis years later. If the assessment demonstrates low probability of compromise, the incident is not a reportable breach; keep the documentation for six years. If you cannot get to low probability, notify. Many organizations skip the assessment and notify by default for borderline cases; that is legally permitted and sometimes strategically simpler, but over-notifying has costs too (patient alarm, portal listing, investigation triggers), so a real assessment process is worth having.
Ransomware note: OCR guidance treats ransomware encryption of ePHI as an "acquisition" and therefore a presumed breach unless your forensics support a low-probability conclusion. Assume reportable until proven otherwise.
Notification Requirements
Individual notification must be provided without unreasonable delay and no later than 60 days after discovery. Discovery means the first day the breach is known — or would have been known exercising reasonable diligence — by anyone in your workforce other than the person who committed it. You cannot avoid the clock by not looking. Notice must be written, by first-class mail (or email if the individual agreed to electronic notice), and must include: a description of what happened and the dates of breach and discovery, the types of information involved, steps individuals should take to protect themselves, what you are doing to investigate, mitigate, and prevent recurrence, and contact procedures including a toll-free number for larger incidents. If contact information is insufficient for 10 or more individuals, substitute notice is required — a conspicuous website posting for 90 days or major media notice, plus a toll-free number active for 90 days.
HHS notification is required for all breaches, via OCR's online portal. For breaches affecting 500 or more individuals, notify HHS contemporaneously with individual notices (within 60 days of discovery); these breaches appear on OCR's public breach portal and reliably trigger an investigation. For breaches affecting fewer than 500, log each incident and submit them annually, within 60 days after the calendar year ends.
Media notification applies when a breach affects more than 500 residents of a single state or jurisdiction: notice to prominent media outlets serving that area, within the same 60-day window, typically via press release.
An important nuance: 60 days is the outer limit, not a grace period. "Without unreasonable delay" is the operative standard, and OCR has penalized entities that sat on completed investigations. Also remember that nearly every state has its own breach notification law — several with shorter deadlines, attorney general notice requirements, and credit monitoring mandates — so a multi-state breach is always a multi-regime notification project.
Business Associate Obligations
A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery, identifying (to the extent known) each affected individual and providing the information the covered entity needs for its own notices. The covered entity then owns individual, HHS, and media notification — its 60-day clock runs from the business associate's discovery in agency situations, and practically from when it is told.
This is why BAAs almost never leave the timeline at 60 days. Covered entities routinely negotiate business associate notice within 5 to 15 days (sometimes 72 hours) of discovery, so they retain enough runway to investigate and notify. If you are a vendor, know exactly what your BAAs promise — your contractual deadline is probably far shorter than the regulatory one, and missing it is a breach of contract even if you beat the rule. Subcontractor business associates owe the same duty up the chain to the business associate above them.
Building an Effective Breach Response Process
A HIPAA-ready incident response process layers legal workflow onto standard security response:
- Detect and contain — standard IR: isolate systems, preserve evidence, stop ongoing exposure.
- Preserve and investigate — forensic imaging and log preservation matter doubly here, because factor 3 of the risk assessment (was PHI actually viewed or acquired?) is answered with logs.
- Engage counsel early — for significant incidents, privileged direction of the investigation protects the analysis and coordinates state law obligations.
- Run the breach risk assessment — a standing four-factor template, completed and signed for every impermissible use or disclosure, however small.
- Notify on the timeline — individuals, HHS, media, states, and (for business associates) upstream customers per BAA terms.
- Mitigate and remediate — credit monitoring where financial data is involved, control fixes, and a corrective action record; OCR weighs post-incident conduct heavily.
- Document everything for six years — assessments, notification copies, dates, and the small-breach log for annual HHS submission.
Breach Readiness Checklist
- Incident response plan includes HIPAA-specific steps and the four-factor assessment template
- Encryption verified across endpoints, databases, backups, and media — your safe harbor evidence
- Logging sufficient to prove whether data was accessed or exfiltrated
- Discovery obligations understood: monitoring in place so you cannot "reasonably fail to know"
- BAA notification deadlines inventoried (yours to customers, vendors' to you)
- Notification letter templates drafted with all required content elements
- Substitute notice mechanics ready (website banner process, toll-free number vendor)
- HHS portal submission process documented; annual small-breach log maintained
- State breach law matrix maintained for states where your individuals reside
- Breach counsel and forensics firm identified before you need them
- Cyber insurance notification requirements integrated into the runbook
- Workforce trained to report suspected incidents immediately, with a no-blame reporting channel
- Tabletop exercise run in the last 12 months, including a ransomware scenario
Frequently Asked Questions
Is every security incident a reportable breach?
No. An incident becomes a reportable breach only if it involves an impermissible use or disclosure of unsecured PHI that fails the low-probability risk assessment and no exception applies. A blocked phishing attempt, a compromised system containing no PHI, or a lost encrypted device typically is not reportable — but the analysis and its documentation are still required.
When does the 60-day clock actually start?
At discovery: the first day anyone in your workforce (other than the wrongdoer) knows of the breach or would have known with reasonable diligence. If your logs showed exfiltration in March and nobody looked until June, expect regulators to argue the clock started in March. Detection capability is a notification-compliance control, not just a security one.
An employee emailed PHI to the wrong recipient. Breach?
Presumptively yes, unless an exception applies or the four-factor assessment supports low probability. Helpful facts: the recipient is another HIPAA-regulated entity, promptly confirmed deletion, and the data was limited. Hurtful facts: an unknown personal address, sensitive diagnoses, no response to recall attempts. Do the assessment, document it, and decide — do not just recall the message and move on.
Do we have to offer credit monitoring?
HIPAA does not require it, but several state laws do when Social Security numbers are involved, and OCR views it favorably as mitigation. Practically, breaches exposing SSNs or financial data almost always include 12 to 24 months of monitoring — for law, litigation posture, and customer trust alike.
What happens after we report a 500+ breach to HHS?
Your entry appears on OCR's public breach portal, and OCR opens a compliance review. Expect a data request covering your risk analysis, policies, training records, BAAs, and the incident file. Outcomes range from closure with technical assistance to a resolution agreement with a monetary settlement and multi-year corrective action plan — largely determined by how strong your pre-breach program looks on paper.
As a business associate, do we ever notify individuals directly?
Only if the BAA delegates it, which sometimes happens when the business associate holds the contact information (for example, a patient-facing app). By default the covered entity notifies. Never notify a covered entity's patients unilaterally — coordinate, because the covered entity owns the regulatory relationship.
In the next lesson, we will cover business associate requirements.
Breach readiness depends on evidence you can produce fast — encryption status, logs, policies, training records. AuditXYZ helps you compare compliance automation platforms and auditors so that proof is always a query away, not a scramble.