Start Free Assessment

HIPAA Annual Breach Reporting: HHS Submission Guide

HIPAA requires notification of data breaches affecting 500+ individuals to HHS and the media. Learn the requirements and annual reporting procedures.

This guide covers breach notification timelines, what to include in breach reports, how to submit to HHS, and best practices for documenting breaches.

What is a Breach Under HIPAA?

A breach is unauthorized acquisition, access, use, or disclosure of protected health information that compromises the security or privacy of the information. Not all unauthorized access constitutes a breach. A breach occurs when there is a reasonable risk of financial, reputational, or other harm to affected individuals.

Breach Notification Timeline

Notification Deadlines

  • Without unreasonable delay: Notify affected individuals (typically within 30-60 days)
  • Concurrent notification: Notify media if 500+ individuals affected in same jurisdiction
  • Within 60 days: Notify HHS of breaches affecting 500+ individuals
  • Without unreasonable delay: Notify business associates if their PHI affected
  • Document: Keep detailed records of all notifications and investigation

Individual Notification Requirements

What to Include in Breach Notification to Individuals

Description of the breach and date it occurred/was discovered
Types of information involved in the breach
Steps individuals should take to protect themselves
What you're doing to address the breach
Contact information for further questions
Notification method (mail, email, phone)

HHS Breach Report Submission

When to Report to HHS

Report to HHS Office for Civil Rights when:

  • Breach affects 500 or more individuals
  • No low-risk assessment was made
  • You initially failed to notify and must correct

Reporting Website: https://ocrportal.hhs.gov/ocr/breach/wizard.jsf

Information Required in HHS Report

Covered entity or business associate information
Breach date and discovery date
Type of breach and unauthorized person involved
Number of individuals affected
Types of PHI involved
Description of the breach and circumstances
Steps taken to mitigate the breach
Law enforcement involvement

Annual Breach Report Compilation

Year-End Breach Reporting Checklist

Compile all breaches discovered during the year
Verify all individual notifications were sent
Document all breaches in your breach log
Verify HHS reporting completed for breaches 500+
Analyze breach patterns and causes
Identify remediation actions taken
Create annual breach summary report
File report with compliance documentation

Breach Investigation Procedures

Steps for Investigating a Breach

  • Identify: Detect and confirm the breach occurred
  • Investigate: Determine cause, scope, and affected individuals
  • Assess Risk: Evaluate likelihood of harm from the breach
  • Contain: Stop unauthorized access and secure systems
  • Notify: Inform affected individuals, media (if needed), and HHS
  • Document: Record all findings and notifications
  • Remediate: Fix vulnerabilities to prevent recurrence

Prepare Your Breach Response Plan

Get breach notification templates, investigation procedures, and HHS reporting tools.

Get Breach Response Resources