HIPAA Breach Notification Requirements: Complete Guide
Quick Answer
When unsecured protected health information (PHI) is acquired by unauthorized individuals, you must notify affected individuals, the Department of Health and Human Services (HHS), and potentially the media—all within 60 days of discovering the breach. The notification must include specific information about the breach and steps individuals should take. Failure to comply with breach notification requirements can result in penalties of $100-$1,500,000 per breach.
What Constitutes a HIPAA Breach?
HIPAA defines a breach as unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Not every unauthorized access is a breach—the rule includes a "low probability of compromise" exception that's crucial to understand.
A breach occurs when:
- Unsecured PHI is accessed by an unauthorized person
- The access or acquisition was not intentional (though intent doesn't matter for liability)
- The unauthorized person had ability to acquire the information
- There is no credible evidence the information was not actually acquired
However, if you can demonstrate through a risk assessment that there is a low probability the information was actually compromised, you may not need to treat it as a reportable breach. For example, if a locked hard drive containing encrypted patient data is stolen but you have evidence that the encryption keys were never compromised and the thief had no way to access the data, you might document a low probability of compromise.
Examples of Breaches
- A healthcare worker emails patient records to a personal email account by mistake
- A laptop containing unencrypted patient data is stolen from an employee's car
- A vendor maliciously copies PHI from your system without authorization
- A database of patient records is exposed due to a security misconfiguration
- A hacker gains access to your EHR system and copies patient information
- A paper file with medical records is left in a public location where unauthorized people access it
Examples of NOT Breaches (Low Probability of Compromise)
- An encrypted hard drive is lost—the data cannot be accessed without the encryption key
- An employee temporarily accesses another employee's record by mistake but no copy is made
- A document with patient name is misfiled but the actual medical information is not exposed
- An employee briefly views a record outside their job duties but takes no action with the data
The 60-Day Breach Notification Timeline
HIPAA's Breach Notification Rule requires you to notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.
Your organization discovers or is notified of unauthorized acquisition, access, use, or disclosure of PHI. This triggers the 60-day clock. The discovery date is when you knew or should have known about the breach, not when it occurred.
Begin immediate investigation to determine scope of breach, number of individuals affected, what information was compromised, and whether low probability of compromise can be documented.
Conduct thorough risk assessment to determine probability of compromise. Consider nature and extent of PHI, whether it was actually acquired, security measures in place, and whether there's evidence of misuse.
Prepare notification letters to affected individuals, notification to HHS, and determine if media notification is required (generally required if more than 500 residents of a single state affected).
Mail notification letters to affected individuals, notify HHS via breach reporting portal, notify affected media outlets, notify business associates if they're involved in the breach.
Notification to Affected Individuals
Notification letters sent to affected individuals must include specific elements defined in HIPAA regulations. The notification should be in plain language understandable to the average person and include:
Required Content Elements
- Description of what happened (what types of information were compromised)
- Description of steps individuals should take to protect themselves
- Description of what your organization is doing to investigate the breach, mitigate the impact, and prevent future breaches
- Contact information including phone number and email for questions
The notification method should be by first-class mail. If you don't have reliable mailing addresses for some individuals, you must provide notice by email if available, telephone, or substitute notice through media and prominent website posting. The key is ensuring affected individuals are informed in a timely manner.
Avoid language that's overly technical or frightening. Clearly explain what happened, why they're receiving the notice, and what steps they should take—such as monitoring their accounts for fraud or placing fraud alerts with credit agencies.
HHS Notification
You must notify the Department of Health and Human Services via the online Breach Notification Portal at www.hhs.gov/ocr/privacy/hipaa/breachnotificationcenter/index.html. This notification is required for all breaches affecting 10 or more individuals.
For breaches of fewer than 10 individuals, you can aggregate the notification and report annually, though many organizations report all breaches as they occur for completeness.
The HHS notification should include:
- Name of covered entity
- Contact information (address, phone, email)
- Description of the breach
- Description of the types of information compromised
- Steps being taken to mitigate harm and prevent recurrence
- Information about discovery date, notification date, and number of individuals affected
Media Notification
You must notify prominent media outlets if a breach affects more than 500 residents of a state or jurisdiction. This notification should be made without unreasonable delay and no later than 60 days from discovery.
Breaching the personal information of more than 500 people in a state typically qualifies as newsworthy, and the state's major news outlets (newspapers, television stations, wire services) should receive notification. The notification provides factual information about the breach without minimizing its seriousness.
Media notification is a significant event—it's public acknowledgment of the breach and often generates news coverage. This is why thorough investigation and documentation of what happened is critical before notifying media.
Risk Assessment and Low Probability of Compromise
One of the most important aspects of breach notification is the risk assessment that determines whether a breach notification is actually required. HIPAA allows you to refrain from notification if you can demonstrate through a risk assessment that there is a low probability that the information has been compromised.
Risk Assessment Factors
The assessment should evaluate:
- Nature and extent of PHI involved: What specific information was accessed? Demographics, diagnoses, financial data? More sensitive information increases risk.
- Whether the PHI was actually acquired: Do you have evidence the unauthorized person actually accessed the data? Finding an unlocked office with files present doesn't prove they were accessed.
- Extent of actual access: Did the person view the entire database or just one record? The more limited the access, the lower the risk.
- Identity of unauthorized person and likelihood they accessed PHI: Did a random person find a document, or did someone with technical skills intentionally breach your system?
- Whether PHI was actually acquired or used: Has there been any evidence of misuse, such as fraudulent charges or identity theft?
- Security measures that limit accessibility: Was the data encrypted? Behind a firewall? In a locked cabinet? Were access credentials required?
Documentation is Critical
Document your risk assessment thoroughly and retain it. When the Office for Civil Rights audits your organization and asks about breaches, they'll want to see how you evaluated each incident. Thorough documentation showing reasonable analysis of risk factors demonstrates good faith compliance even if your judgment is questioned.
Business Associate Breach Notification
When your business associates discover or suspect a breach, they must notify you immediately. You are then responsible for conducting the risk assessment and making the notification decisions. If HHS or media notification is required, you notify—not the business associate.
However, your Business Associate Agreement should specify that the business associate will cooperate with your investigation and provide all information necessary for you to conduct the risk assessment and issue appropriate notifications.
Documentation and Retention Requirements
You must maintain documentation of:
- Date of breach discovery
- Risk assessment conducted (factors considered, conclusion reached)
- Individuals notified and notification method/date
- HHS notification information
- Media notification if applicable
- Corrective actions taken to prevent recurrence
- Investigation summary and findings
Retain this documentation for at least 6 years, as the Office for Civil Rights may conduct investigations that reference breaches from years prior. Comprehensive documentation is your best defense if an investigation occurs.
Frequently Asked Questions
Prepare Your Breach Notification Plan
Every healthcare organization should have a documented breach response plan that specifies roles, responsibilities, decision-making processes, and notification templates. Medcurity helps organizations develop and test breach response procedures to ensure they can meet HIPAA's strict 60-day timeline.
Get Breach Response Template →