HIPAA Breach Notification Requirements
HIPAA breaches require notification to affected individuals, HHS, and sometimes media. Here is what counts as a breach, the timing rules, and how to handle the notification process.
What Counts as a HIPAA Breach
The HIPAA Breach Notification Rule (45 CFR Sections 164.400-414) defines a breach as the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises the security or privacy of the PHI.
Two key concepts:
- Unsecured PHI: PHI that is not encrypted using HHS-approved methods (FIPS 140-2 validated for at-rest, TLS for in-transit). Encrypted data, properly secured, is not subject to breach notification.
- Compromise: Probability that PHI has been compromised based on a four-factor risk assessment
The four-factor risk assessment:
- Nature and extent of PHI involved
- The unauthorized person who used the PHI or to whom disclosure was made
- Whether PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
If the assessment concludes there is a low probability of compromise, notification may not be required. Document the analysis carefully.
Cross-reference the HIPAA framework reference for complete rule definitions.
Three Exceptions to Breach Definition
Three specific scenarios are excluded from the breach definition:
- Unintentional access by workforce or person acting under authority: An authorized user accidentally accesses PHI they were not supposed to see, in good faith, and does not further use or disclose it.
- Inadvertent disclosure between authorized persons at the same covered entity or business associate: One authorized person discloses PHI to another authorized person at the same organization, and PHI is not further disclosed.
- Disclosure where the recipient could not reasonably retain the PHI: For example, a file briefly displayed to someone who could not memorize or copy it.
These exceptions are narrow. Most incidents that look like "low risk" do not actually meet exception criteria. When in doubt, treat the incident as a breach and document the analysis.
The four-factor risk assessment is your tool for borderline cases. A documented, defensible analysis showing low probability of compromise can support a no-breach determination.
Individual Notification Requirements
If a breach is determined, affected individuals must be notified:
- Timing: Without unreasonable delay and no later than 60 days after discovery
- Method: First-class mail to last known address, or email if individual previously agreed to electronic notice
- Substitute notice: If contact information is insufficient, alternative notice via website posting or major media
- Content requirements: Brief description of breach, types of PHI involved, steps individuals should take, what the entity is doing, contact procedures
The 60-day clock starts on the date the breach is discovered, defined as the date the breach is known or, by exercising reasonable diligence, would have been known. Do not delay discovery to delay notification.
For breaches affecting more than 500 individuals in a single state or jurisdiction, prominent media notice is also required: notification to prominent media outlets in the affected geographic area.
HHS Notification (the 500 Threshold)
HHS notification is required for all breaches but with different timing based on size:
- Breaches affecting fewer than 500 individuals: Annual notification by 60 days after the end of the calendar year. Logged on HHS portal.
- Breaches affecting 500 or more individuals: Notification without unreasonable delay and within 60 days of discovery. Goes onto the HHS "Wall of Shame" public breach portal.
The 500-individual threshold has significant business implications:
- Public listing on HHS portal creates reputational impact
- Major breaches trigger formal OCR investigation
- State attorneys general often pursue parallel investigations
- Media attention typically follows public listing
The HHS portal lists every breach over 500 individuals with the entity name, breach date, individuals affected, and breach type. The list is searchable and is monitored by media, plaintiff attorneys, and competitors. Plan communications strategy for any breach approaching the 500 threshold.
Business Associate Obligations
Business associates have parallel breach notification obligations:
- Notify covered entity: BA must notify the covered entity without unreasonable delay and within 60 days of discovery
- Provide details: Identification of affected individuals, description of breach, types of PHI involved
- Cooperate with covered entity notification: BA may handle individual notifications under BAA terms, or may provide information for covered entity to notify
For SaaS startups operating as business associates:
- Build incident response procedures that can identify breach scope quickly (often within hours, given the 60-day clock)
- Maintain customer breach contact information
- Have BAA-aligned notification templates ready
- Document breaches even if exception criteria are met
Treat every potential breach as if you will need to notify, then back off only when the four-factor analysis genuinely supports it. The cost of unnecessary notification is reputational. The cost of failed notification when required is regulatory: OCR fines, state AG action, and potential class action litigation.
Frequently Asked Questions
Related Articles
HIPAA Risk Analysis Guide
HIPAA Security Rule requires a documented risk analysis. Missing or inadequate risk analysis is the single most-cited HIPAA violation. Here is how to do one that holds up.
HIPAA Security Rule Requirements
The HIPAA Security Rule defines the safeguards covered entities and business associates must implement to protect electronic PHI. Here is what each safeguard requires and how to operationalize it.
HIPAA Compliance for Startups
Healthcare startups face HIPAA from day one if they handle PHI. Here is a practical roadmap from initial scoping to audit readiness without enterprise-scale overhead.