Discovering that protected health information may have been compromised is not a good day. What you do in the hours and days that follow has regulatory consequences — and the Breach Notification Rule (45 CFR §§164.400-414) is specific about what those obligations are and when they kick in.
What Triggers Notification
A breach under HIPAA is an acquisition, access, use, or disclosure of unsecured PHI that is not permitted by the Privacy Rule. The word "unsecured" is key.
"Unsecured PHI" means PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals. HHS specifies two methods that qualify:
- Encryption of data at rest and in transit, consistent with NIST guidance (NIST SP 800-111 for storage, NIST SP 800-52 for transmission)
- Destruction of physical media (paper shredded, electronic media destroyed per NIST 800-88)
If the compromised PHI was encrypted and the encryption keys were not also compromised, you do not have a breach requiring notification. This is the practical reason why encryption matters even as an "addressable" technical safeguard — it determines whether an incident becomes a reportable breach.
The Four-Factor Risk Assessment
When you discover a potential breach, you don't automatically have a reportable breach. The Breach Notification Rule creates a presumption that an impermissible use or disclosure is a breach — but you can rebut that presumption with a documented four-factor risk assessment:
-
The nature and extent of the PHI involved — what types of identifiers were exposed, whether clinical information was included, whether the combination of data could enable harm
-
Who used the PHI or to whom it was disclosed — an internal employee accessing records without authorization is different from an external attacker exfiltrating data
-
Whether the PHI was actually acquired or viewed — access logs can sometimes show that a system was compromised but no PHI was actually opened or exfiltrated
-
The extent to which the risk has been mitigated — for example, a laptop was stolen but was tracked and recovered before anyone could access it, and it was encrypted
If this assessment demonstrates a low probability that PHI was compromised, you can document that finding and decline to notify. You still must document the assessment — you can't just decide not to notify without the paperwork to support that decision.
Be conservative here. If the risk assessment is genuinely ambiguous, notification is the safer path. OCR doesn't penalize organizations for notifying when they weren't required to — they do investigate organizations that failed to notify when they should have.
Who You Must Notify and When
Affected Individuals
Written notice without unreasonable delay, and no later than 60 calendar days after you discover the breach.
Required content:
- A brief description of what happened, including the date of the breach and the date it was discovered (if known)
- The types of unsecured PHI involved (name, Social Security numbers, dates of birth, diagnosis, treatment information, financial account numbers — describe what was actually involved)
- Steps individuals should take to protect themselves from potential harm
- A brief description of what you're doing to investigate, mitigate harm, and prevent future breaches
- Contact information — a toll-free number, email address, or website where individuals can ask questions and get updates
Delivery: first-class mail to the individual's last known address. If the individual has agreed to electronic notification, email is acceptable. If you have insufficient address information for 10 or more individuals, you must post a notice on your website for 90 days and provide a toll-free number.
Media (for large breaches)
If the breach affects more than 500 residents of a state or jurisdiction, you must provide notice to prominent media outlets in that state or jurisdiction, within the same 60-day window.
This is the notification that makes the news. It's why large healthcare breaches become public knowledge quickly.
HHS/OCR
For breaches affecting fewer than 500 individuals: Log the breach in your breach log and submit the information to HHS through the OCR reporting portal within 60 days of the end of the calendar year in which the breach occurred. This means small breaches discovered in 2026 must be submitted by March 1, 2027 (the portal deadline for the prior year).
For breaches affecting 500 or more individuals: Notify HHS within 60 days of discovering the breach. HHS publishes these on the OCR Breach Reporting portal — this is what the media calls the "Wall of Shame" (hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html). Your organization's name, date of breach, approximate number of individuals affected, type of breach, and location of breached information all become public.
Business Associates
If you're a business associate and you discover a breach, you must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Critically: if you're acting as an agent of the covered entity, the CE's 60-day clock starts when you discover the breach — not when you notify them. If you wait 55 days, they have 5 days left. Whether you're an agent or independent contractor turns on how much control the CE exercises over your work; when in doubt, assume the clock runs from your discovery date and notify promptly.
What to Do in the First 72 Hours
The Breach Notification Rule doesn't establish a 72-hour requirement — that's the EU GDPR. But the first 72 hours are when you make decisions that either preserve your options or foreclose them.
Contain the incident: Cut off ongoing unauthorized access. This might mean revoking credentials, taking systems offline, or locking down an account. Don't let the breach continue while you investigate.
Preserve evidence: Do not wipe systems before forensic examination. The forensic record of what happened — what data was accessed, from where, when — is what you'll need for the risk assessment and potentially for OCR. Wiping evidence to "clean up" is worse than the breach.
Engage legal counsel early: Attorney-client privilege attaches to communications made for the purpose of obtaining legal advice. If you think this breach could involve litigation or regulatory investigation, having legal counsel engaged from the start protects more of your investigation communications than engaging them later.
Document everything: Breach response activities, timestamps, who was notified and when, what the four-factor risk assessment concluded. This documentation is your evidence that you responded appropriately.
Conduct the four-factor risk assessment: Get this done before you start notifying. If your analysis concludes that notification isn't required, you need that documented. If it concludes notification is required, you want to know as soon as possible — the clock is running.
Start the breach log entry: Even if notification isn't required, the incident should be documented. OCR can ask for your breach log during audits or investigations.
Don't Wait for Forensics to Complete
Forensic investigations of healthcare breaches can take weeks or months. The 60-day clock doesn't pause for them. If you're still investigating and the 60-day deadline is approaching, notify based on your best current understanding of what happened and what PHI was involved. You can note that the investigation is ongoing. Notify first; update later if necessary. Failing to notify within 60 days because you were waiting for a definitive forensic answer is not a defense OCR accepts.
SOURCES
- 45 CFR §§164.400-414 — Breach Notification for Unsecured PHI: ecfr.gov
- HHS, "Breach Notification Rule": hhs.gov/hipaa/for-professionals/breach-notification/index.html
- HHS HIPAA Breach Reporting Tool: hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html
- NIST SP 800-111, Guide to Storage Encryption Technologies for End User Devices: csrc.nist.gov/publications/detail/sp/800-111/final
- NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization: csrc.nist.gov/publications/detail/sp/800-88/rev-1/final
Experienced a potential breach or want a breach response plan in place before you need it? Schedule a consultation to talk through your incident response preparedness.
