Chat with us
Breach Notification Rule

HIPAA Breach Notification
Timelines & Requirements

When a breach of unsecured PHI occurs, HIPAA requires notification to affected individuals, HHS, and potentially the media. Learn the 60-day timeline and notification requirements.

What Constitutes a Breach?

Breach Definition

An impermissible use or disclosure of PHI that compromises the security or privacy of the PHI. There is a presumption that any impermissible use or disclosure is a breach.

Exceptions to Breach

  • • Unintentional access by workforce member acting in good faith
  • • Inadvertent disclosure between authorized persons
  • • Good faith belief that unauthorized person could not retain PHI

Breach Response Timeline

1

Discovery

Day 0

Breach discovered or should have been discovered through reasonable diligence

2

Risk Assessment

Days 1-7

Conduct 4-factor risk assessment to determine if notification is required

3

Individual Notice

Within 60 days

Written notice to affected individuals via first-class mail

4

Media Notice

Within 60 days

If 500+ individuals affected in a state, notify prominent media

5

HHS Notice

Within 60 days

Notify HHS via online portal (immediate if 500+, annual if <500)

4-Factor Risk Assessment

To determine if an impermissible disclosure compromised PHI, evaluate these factors:

1

Nature of PHI

Types of identifiers and likelihood of re-identification

2

Unauthorized Person

Who received or accessed the PHI (employee, external party, etc.)

3

PHI Acquired/Viewed

Whether PHI was actually acquired or viewed

4

Risk Mitigation

Extent to which risk has been mitigated (e.g., data returned, destroyed)

What Must Be Included in Breach Notice

Description of breach
Types of information involved
Steps individuals should take
What entity is doing to investigate
Contact information
Toll-free number (if 10+ individuals)

Need Help with Breach Response?

Our experts can help you develop incident response procedures and navigate breach notification requirements.