Get HIPAA Audit →

HIPAA Breach Notification Requirements: Complete Guide

Quick Answer

When unsecured protected health information (PHI) is acquired by unauthorized individuals, you must notify affected individuals, the Department of Health and Human Services (HHS), and potentially the media—all within 60 days of discovering the breach. The notification must include specific information about the breach and steps individuals should take. Failure to comply with breach notification requirements can result in penalties of $100-$1,500,000 per breach.

What Constitutes a HIPAA Breach?

HIPAA defines a breach as unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Not every unauthorized access is a breach—the rule includes a "low probability of compromise" exception that's crucial to understand.

A breach occurs when:

However, if you can demonstrate through a risk assessment that there is a low probability the information was actually compromised, you may not need to treat it as a reportable breach. For example, if a locked hard drive containing encrypted patient data is stolen but you have evidence that the encryption keys were never compromised and the thief had no way to access the data, you might document a low probability of compromise.

Examples of Breaches

Examples of NOT Breaches (Low Probability of Compromise)

The 60-Day Breach Notification Timeline

HIPAA's Breach Notification Rule requires you to notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.

Day 1-3: Breach Discovery

Your organization discovers or is notified of unauthorized acquisition, access, use, or disclosure of PHI. This triggers the 60-day clock. The discovery date is when you knew or should have known about the breach, not when it occurred.

Day 1-5: Preliminary Investigation

Begin immediate investigation to determine scope of breach, number of individuals affected, what information was compromised, and whether low probability of compromise can be documented.

Day 10-30: Risk Assessment

Conduct thorough risk assessment to determine probability of compromise. Consider nature and extent of PHI, whether it was actually acquired, security measures in place, and whether there's evidence of misuse.

Day 30-45: Notification Preparation

Prepare notification letters to affected individuals, notification to HHS, and determine if media notification is required (generally required if more than 500 residents of a single state affected).

Day 45-60: Send Notifications

Mail notification letters to affected individuals, notify HHS via breach reporting portal, notify affected media outlets, notify business associates if they're involved in the breach.

Notification to Affected Individuals

Notification letters sent to affected individuals must include specific elements defined in HIPAA regulations. The notification should be in plain language understandable to the average person and include:

Required Content Elements

The notification method should be by first-class mail. If you don't have reliable mailing addresses for some individuals, you must provide notice by email if available, telephone, or substitute notice through media and prominent website posting. The key is ensuring affected individuals are informed in a timely manner.

Avoid language that's overly technical or frightening. Clearly explain what happened, why they're receiving the notice, and what steps they should take—such as monitoring their accounts for fraud or placing fraud alerts with credit agencies.

HHS Notification

You must notify the Department of Health and Human Services via the online Breach Notification Portal at www.hhs.gov/ocr/privacy/hipaa/breachnotificationcenter/index.html. This notification is required for all breaches affecting 10 or more individuals.

For breaches of fewer than 10 individuals, you can aggregate the notification and report annually, though many organizations report all breaches as they occur for completeness.

The HHS notification should include:

Media Notification

You must notify prominent media outlets if a breach affects more than 500 residents of a state or jurisdiction. This notification should be made without unreasonable delay and no later than 60 days from discovery.

Breaching the personal information of more than 500 people in a state typically qualifies as newsworthy, and the state's major news outlets (newspapers, television stations, wire services) should receive notification. The notification provides factual information about the breach without minimizing its seriousness.

Media notification is a significant event—it's public acknowledgment of the breach and often generates news coverage. This is why thorough investigation and documentation of what happened is critical before notifying media.

Risk Assessment and Low Probability of Compromise

One of the most important aspects of breach notification is the risk assessment that determines whether a breach notification is actually required. HIPAA allows you to refrain from notification if you can demonstrate through a risk assessment that there is a low probability that the information has been compromised.

Risk Assessment Factors

The assessment should evaluate:

Documentation is Critical

Document your risk assessment thoroughly and retain it. When the Office for Civil Rights audits your organization and asks about breaches, they'll want to see how you evaluated each incident. Thorough documentation showing reasonable analysis of risk factors demonstrates good faith compliance even if your judgment is questioned.

Business Associate Breach Notification

When your business associates discover or suspect a breach, they must notify you immediately. You are then responsible for conducting the risk assessment and making the notification decisions. If HHS or media notification is required, you notify—not the business associate.

However, your Business Associate Agreement should specify that the business associate will cooperate with your investigation and provide all information necessary for you to conduct the risk assessment and issue appropriate notifications.

Documentation and Retention Requirements

You must maintain documentation of:

Retain this documentation for at least 6 years, as the Office for Civil Rights may conduct investigations that reference breaches from years prior. Comprehensive documentation is your best defense if an investigation occurs.

Frequently Asked Questions

What if I can't notify individuals within 60 days?
HIPAA requires notification without unreasonable delay and no later than 60 calendar days. There are no extensions. If you cannot meet this deadline, you should begin notifications immediately and communicate progress to HHS, explaining any delays. Severe delays will be viewed negatively in regulatory investigations.
Do I need to notify patients if it's a business associate's breach?
Yes, you are responsible for notification even if a business associate discovered or caused the breach. Your BAA should require rapid notification from the business associate, but you make the final notification decisions and bear responsibility for compliance.
Can I disclose the breach to legal counsel before notifying patients?
Yes. Consulting with legal counsel is appropriate and doesn't delay the 60-day clock. However, you should initiate your investigation and notification process immediately upon discovery while working with counsel.
What if the breach was caused by an employee violation, not a system failure?
The cause doesn't affect your notification obligation. Whether the breach resulted from malicious intent, negligence, or accident, if it meets the definition of a breach affecting PHI, you must notify affected individuals unless low probability of compromise is documented.
Do I need to notify individuals if their data was encrypted?
If the data was properly encrypted and the encryption keys were not compromised, you may be able to document low probability of compromise and avoid notification. However, this requires demonstrating that decryption was not possible for the unauthorized person.
What if I don't know the exact number of individuals affected?
Begin notification immediately to all potentially affected individuals based on your best estimate. Continue your investigation to determine the precise scope. If your initial estimate was higher than the actual number, you still must notify those you contacted—you cannot retract notifications.
Can I notify individuals by email instead of mail?
Primary notification should be by first-class mail. Email is an acceptable alternative if you don't have reliable mailing addresses. Many organizations use both methods to ensure individuals receive notice.
What's the difference between individual, HHS, and media notification?
Individual notification informs patients of the breach and steps they should take. HHS notification is regulatory reporting to the Office for Civil Rights. Media notification is required for large breaches affecting 500+ people in a state, providing public notice of the incident.

Prepare Your Breach Notification Plan

Every healthcare organization should have a documented breach response plan that specifies roles, responsibilities, decision-making processes, and notification templates. Medcurity helps organizations develop and test breach response procedures to ensure they can meet HIPAA's strict 60-day timeline.

Get Breach Response Template →