← Back to blog

HIPAA Breach Notification Requirements: What to Do Now

August 14, 2026
HIPAA Breach Notification Requirements: What to Do Now

Under the HIPAA Breach Notification Rule (45 CFR §§164.400–414), covered entities must notify affected individuals, the HHS Secretary through the Office for Civil Rights (OCR), and — when a breach affects 500 or more residents of a single state — prominent media outlets serving that state. All notifications must occur without unreasonable delay and no later than 60 calendar days after the date of discovery. Business associates carry a parallel obligation: they must notify the covered entity without unreasonable delay and no later than 60 days from their own discovery date.

When a potential breach surfaces, your first moves matter as much as the notices themselves:

  • Preserve evidence. Secure logs, access records, and system snapshots before they are overwritten.
  • Identify affected individuals. Pull records to determine whose protected health information (PHI) was involved.
  • Estimate scope. Determine whether the incident crosses the 500-individual threshold at the state or national level.
  • Begin documentation immediately. Record who discovered the incident, when, and what steps were taken.
  • Prepare required notices. Draft individual notice, HHS submission, and media notice if the 500-resident threshold is met.

Key Takeaways

HIPAA breach notification requirements demand that covered entities notify individuals, HHS, and media (when applicable) without unreasonable delay and no later than 60 calendar days after discovery — with the burden of proof resting entirely on the covered entity to document compliance or justify non-notification.

PointDetails
60-day hard deadlineAll required notifications must be sent no later than 60 calendar days after the discovery date, with earlier action strongly preferred.
Discovery date riskPoor monitoring can move the constructive discovery date earlier; real-time log retention is your primary defense against this finding.
HHS reporting thresholdsBreaches affecting 500+ individuals require immediate HHS portal submission; breaches under 500 may be reported annually by 60 days after year-end.
Risk assessment burden of proofA documented, four-factor risk assessment is required to avoid notification; an undocumented "no breach" conclusion does not satisfy OCR.
CisoSafe breach readinessCisoSafe's vCISO services and compliance platform deliver the monitoring, templates, and documentation infrastructure that make HIPAA breach response provable.

Table of Contents

What counts as a reportable breach under HIPAA?

The Breach Notification Rule defines a breach as an impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises the security or privacy of that information. The default presumption is that any impermissible use or disclosure is a breach — unless the covered entity or business associate can demonstrate, through a documented risk assessment, that there is a low probability the PHI was actually compromised.

Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in HHS guidance. The most common safe harbor is encryption that meets the standards described in NIST Special Publication 800-111 for data at rest or FIPS 140-2 for data in transit. If the encryption standard matches HHS guidance, a lost or stolen device does not trigger notification obligations.

Reportable incidents include a lost laptop containing unencrypted patient records, unauthorized network access that exposed PHI, and a misdirected fax carrying identifiable health information. Non-reportable scenarios include a stolen laptop where the hard drive was encrypted to the applicable HHS standard, or an inadvertent internal disclosure between two authorized workforce members who had no reason to retain the information.

Pro Tip: When your risk assessment concludes that no breach occurred, document that conclusion in writing the same day — include the four regulatory factors you evaluated, the evidence reviewed, and the name of the person who made the determination. A verbal "we looked at it and it's fine" will not satisfy OCR.


Who must notify, and when does the 60-day clock start?

Covered entities — hospitals, physician practices, health plans, and healthcare clearinghouses — bear the primary legal responsibility to notify affected individuals and the HHS Secretary. Business associates do not notify individuals directly; they notify the covered entity, which then carries out individual and media notice.

How the discovery date is defined

Under 45 CFR §164.404, a breach is "discovered" on the first day it is known, or the first day it would have been known had the covered entity exercised reasonable diligence. That second clause is where organizations get into trouble. If your security logs showed anomalous access for three weeks before anyone reviewed them, OCR can treat the discovery date as the day those logs first showed the anomaly — not the day someone finally opened them. Poor monitoring does not reset the clock; it moves it backward.

The 60-day rule in practice

The regulation sets two simultaneous standards: act without unreasonable delay and act no later than 60 calendar days after discovery. These are not the same thing. Sixty days is the outer limit, not the target.

A law-enforcement exception exists: if a law-enforcement official requests a delay in notification because it would impede a criminal investigation, the covered entity may delay for the period specified by the official, up to 30 days (extendable in writing).

Notification milestones from discovery:

  1. Day 0 (Discovery): Contain the incident, preserve forensic evidence, and open an investigation file.
  2. Days 1–5: Identify affected individuals, classify PHI types involved, and assess whether the 500-individual threshold is crossed.
  3. Days 5–15: Complete or substantially advance the risk assessment; draft individual notices.
  4. Days 15–30: Send individual notices if the risk assessment confirms a breach; submit to HHS if ≥500 individuals are affected.
  5. No later than Day 60: All required notifications must be sent and documented, regardless of whether the investigation is fully complete.

What must individual notices contain and how must they be delivered?

Every individual notice must meet the content and delivery standards set out in 45 CFR §164.404. Plain language is a regulatory requirement, not a stylistic preference. Notices written in dense legal prose that an average patient cannot understand fail the standard.

Required notice elements

Required ElementGuidance on Wording
Brief description of the breachState what happened and the approximate date the breach occurred and was discovered.
Types of PHI involvedList specific categories: name, Social Security number, diagnosis codes, financial account numbers, etc.
Steps individuals should takeRecommend concrete protective actions: credit monitoring, fraud alerts, contacting their insurer.
What the entity is doingDescribe investigation steps, mitigation actions, and any corrective measures already implemented.
Contact proceduresProvide a dedicated toll-free number, mailing address, email address, or website for follow-up questions.

Delivery methods and substitute notice rules

First-class mail to the individual's last known address is the standard delivery method. Email is permitted when the individual has agreed to receive electronic communications. When contact information is insufficient or out of date:

  • Fewer than 10 individuals: Provide an alternative form of written notice, telephone contact, or other means.
  • 10 or more individuals: Post a conspicuous notice on the covered entity's website for at least 90 days, or publish in major print or broadcast media in the geographic area where the affected individuals likely reside. The notice must include a toll-free number active for at least 90 days.

When a breach affects 500 or more residents of a single state or jurisdiction, the covered entity must also notify prominent media outlets serving that state — typically through a press release to major newspapers or broadcast stations — without unreasonable delay and no later than 60 days from discovery.

Common drafting pitfalls to avoid:

  • Using passive constructions that obscure what actually happened ("data may have been accessed" instead of "an unauthorized person accessed records containing your name and diagnosis")
  • Omitting the specific PHI categories involved
  • Failing to include a working toll-free number at the time the notice is mailed
  • Sending notices before the toll-free line is staffed and ready to respond

How do you report a breach to HHS and OCR?

All breach reports to the HHS Secretary are submitted through the HHS OCR Breach Reporting Portal. The portal is also where OCR publishes breach reports and where investigators access filed submissions. The timing and method differ based on how many individuals were affected.

Step-by-step HHS reporting process

  1. Estimate the number of affected individuals. You do not need a final count to submit; an estimate is acceptable for the initial filing.
  2. Gather incident details. Collect the date of discovery, the date of the breach (if known), the type of breach (hacking, unauthorized access, loss, theft, etc.), the location of breached information (laptop, network server, paper records), and the PHI categories involved.
  3. Log in to the OCR Breach Portal at ocrportal.hhs.gov and complete the online submission form.
  4. Submit the initial report. For breaches affecting 500 or more individuals, submit without unreasonable delay and no later than 60 days after discovery.
  5. Update the submission if the scope changes after the initial filing. OCR accepts amended reports.

Timing by breach size

  • 500 or more individuals: Report to HHS without unreasonable delay and no later than 60 calendar days after discovery. OCR will investigate these breaches and post them publicly.
  • Fewer than 500 individuals: Log the breach internally and submit to HHS annually. The annual submission deadline is 60 days after the end of the calendar year in which the breaches occurred. Earlier reporting is permitted and often advisable.

Checklist of fields commonly required on the HHS submission form:

  • Covered entity name, address, and contact information
  • Type of covered entity (health plan, provider, clearinghouse)
  • Date the breach was discovered
  • Date the breach occurred (or approximate date range)
  • Type of breach (hacking/IT incident, unauthorized access/disclosure, theft, loss, improper disposal, other)
  • Location of breached information (electronic, paper/film, other)
  • Type of PHI involved
  • Number of individuals affected (estimate acceptable)
  • Description of what happened
  • Safeguards in place at the time of the breach
  • Actions taken in response

Pro Tip: Submit an initial estimate as soon as you have a reasonable basis for the count. HHS guidance confirms that early submissions with estimates — updated later — demonstrate proactive compliance and reduce enforcement exposure compared to waiting for a precise final count.


What are business associates required to do after a breach?

Business associates (BAs) occupy a distinct position in the notification chain. They do not send notices to affected individuals; that responsibility stays with the covered entity. But BAs must notify the covered entity without unreasonable delay and no later than 60 calendar days after the BA's own discovery of the breach.

The notice a BA provides to the covered entity must include, to the extent possible, the identity of each individual whose PHI was involved, along with all other information the covered entity needs to make its own required notifications. That means the BA should deliver a structured identification file containing names, last known addresses, and the specific PHI categories affected for each individual.

Business associate agreements (BAAs) often allocate notification responsibilities further. Some BAAs require the BA to notify individuals directly on the covered entity's behalf; others require the BA to provide the covered entity with a complete notification package within a shorter window than the regulatory 60-day maximum. Review your BAAs now, before an incident occurs, to understand your contractual obligations and whether they are more stringent than the regulatory floor.

Operational steps for business associates after discovery:

  • Preserve all relevant logs, access records, and system artifacts immediately.
  • Prepare a forensic summary documenting the timeline, systems involved, and data accessed.
  • Compile an identification file (name, contact information, PHI types) for every affected individual you can identify.
  • Deliver the complete package to the covered entity as soon as the information is available, without waiting for the 60-day limit.

When is notification not required? The risk assessment exception explained

Not every impermissible disclosure triggers notification. The Breach Notification Rule provides two pathways to avoid notification obligations: the encryption safe harbor and the low-probability-of-compromise risk assessment.

Encryption safe harbor

When PHI is encrypted to the standard specified in HHS guidance — NIST SP 800-111 for data at rest, FIPS 140-2 for data in transit — and the encryption key was not also compromised, the information is considered "secured" and no notification is required. This is the cleanest exception: if the device or media is properly encrypted and the key is intact, the incident is not a reportable breach regardless of who accessed the hardware.

Hands installing encrypted data drive

The low-probability risk assessment

When PHI is not encrypted, a covered entity or business associate may still avoid notification by conducting a documented risk assessment that demonstrates a low probability the PHI was actually compromised. The assessment must address four specific factors:

  1. Nature and extent of PHI involved — including the types of identifiers and the likelihood of re-identification.
  2. Who accessed or could have accessed the PHI — whether the recipient was an unauthorized person who would be likely to misuse the information.
  3. Whether PHI was actually acquired or viewed — forensic evidence that the data was not opened, copied, or transmitted.
  4. Extent to which risk has been mitigated — steps taken to recover the information or obtain reliable assurances that it was not further used or disclosed.

"The covered entity or business associate, as applicable, has the burden of demonstrating that all required notifications have been made or, alternatively, that the use or disclosure did not constitute a breach." — Breach Notification Rule | HHS.gov

A defensible "no breach" determination requires a formal, written risk assessment that addresses all four factors with supporting evidence. Lacking this documentation can itself trigger enforcement action even when actual harm was unlikely.

Pro Tip: Timestamp every step of your risk assessment process. OCR expects to see who conducted the assessment, what evidence was reviewed, when each decision was made, and who approved the final determination. A PDF with a creation date of Day 58 after discovery raises immediate questions about whether the assessment was contemporaneous.


How do state breach-notification laws affect your obligations?

HIPAA sets a federal floor, not a ceiling. Every state has its own breach-notification statute, and many impose requirements that are stricter than the federal rule. When state law is more protective of individuals than HIPAA, you must follow the stricter standard.

The axes where state laws most commonly diverge from federal requirements:

  • Notification trigger: Some states require notification for breaches of information that HIPAA does not cover, or apply a lower probability-of-harm threshold.
  • Timing: Several states require notification within 30, 45, or 72 hours of discovery — well inside HIPAA's 60-day outer limit.
  • Substitute notice: State rules on when and how substitute notice may be used often differ from the federal rules.
  • Media notice: Some states require media notification at lower thresholds than the 500-resident federal trigger.
  • Regulatory recipients: Certain states require simultaneous notice to a state attorney general or consumer protection agency.
Compliance AxisFederal (HIPAA) StandardTypical State Variation
Notification triggerUnsecured PHI, low-probability risk assessmentMay include broader data categories; some states use a harm threshold
TimingNo later than 60 calendar days30–72 hours in several states
Substitute noticeSpecific rules for <10 and ≥10 individualsState rules vary; some require AG notification
Media notice threshold500+ residents of a stateSome states set lower thresholds

Practical action items for multi-state incidents:

  • Inventory every state where affected individuals reside, not just where your organization is headquartered.
  • Check each state's breach-notification statute for timing, content, and recipient requirements.
  • Involve state counsel before finalizing substitute notice decisions or media statements.
  • Document which state standard you applied and why, for each state where individuals reside.

State law compliance is not optional when it is stricter than HIPAA. Treating the 60-day federal deadline as your only obligation in a state that requires 72-hour notification is a compliance failure — and a separate enforcement exposure.


What are the penalties for HIPAA breach-notification violations?

OCR's enforcement posture has sharpened considerably over the past decade. Investigations are triggered by breach reports, complaints, and OCR's own audit program. For breaches affecting 500 or more individuals, an investigation is effectively automatic — OCR receives the report and opens a review.

Factors that increase enforcement severity:

  • No contemporaneous risk assessment when one was required
  • Evidence that audit logs were available but ignored, moving the constructive discovery date earlier
  • Delayed notification when the organization had sufficient information to act sooner
  • Repeated incidents suggesting systemic failure rather than an isolated event
  • Failure to cooperate with OCR during an investigation

Mitigation actions that reduce enforcement exposure:

  • Prompt notification, even with estimated figures that are later refined
  • Full cooperation with OCR investigators, including timely production of documentation
  • A comprehensive corrective action plan that addresses the root cause
  • Evidence of prior compliance investment: policies, training records, and risk assessments predating the incident
  • Voluntary self-disclosure before OCR becomes aware of the breach through other means

The penalty structure under HIPAA distinguishes between violations due to reasonable cause, violations due to willful neglect that are corrected, and violations due to willful neglect that are not corrected. The last category carries the highest penalty exposure. Documentation of your investigation, risk assessment, and notification process is your primary defense against a willful-neglect finding.


Your 24–72 hour breach-response checklist and OCR documentation package

The first three days after discovery determine whether your organization can demonstrate reasonable diligence to OCR. Speed and documentation are equally important.

24–72 hour operational checklist

  • Contain the incident. Isolate affected systems, revoke compromised credentials, and block unauthorized access paths.
  • Preserve forensic evidence. Capture logs, screenshots, and system states before any remediation that could overwrite data.
  • Identify the scope. Determine which systems, records, and individuals were affected; flag whether the count is likely to exceed 500.
  • Establish secure communications. Use out-of-band channels for incident response discussions to avoid tipping off a threat actor still in the environment.
  • Open the investigation file. Record the date and time of discovery, who discovered it, and the initial facts known.
  • Notify leadership and legal counsel. Brief your privacy officer, general counsel, and executive leadership immediately.
  • Assess HHS reporting timing. If the incident clearly involves 500 or more individuals, begin preparing the HHS submission in parallel with the investigation.

Pro Tip: Automated, timestamped log collection is your strongest proof of a reasonable-diligence discovery date. If your SIEM or endpoint detection platform captured the anomaly at a specific time, that timestamp becomes your official discovery anchor — and it protects you from OCR arguing the clock started earlier. Organizations without real-time monitoring lose this protection entirely.

Documentation package OCR expects

The documentation you assemble during and after an incident is what OCR reviews when it investigates. Every item below should be preserved and organized:

DocumentWhat It Must Show
Incident timelineChronological log of events from first anomaly to final notification, with timestamps
Discovery recordWho discovered the breach, when, and how — with supporting log evidence
Forensic reportSystems accessed, data involved, attack vector, and evidence of what was or was not exfiltrated
Risk assessmentWritten evaluation of the four regulatory factors with supporting evidence and a signed conclusion
Notification drafts and delivery receiptsFinal text of individual notices, mailing or email records, and confirmation of delivery
Media notice recordsCopy of press release, outlets contacted, and dates of publication
Substitute notice recordsWebsite posting screenshots with dates, or documentation of alternative contact methods used
HHS submission confirmationPortal confirmation number and date of submission
Law enforcement correspondenceAny written requests for notification delay and the covered entity's response

For an incident response plan template aligned to NIST standards that maps directly to these documentation requirements, CisoSafe provides a ready-to-use framework your team can adapt immediately. Downloadable security templates for breach-notification policies and risk-assessment documentation are also available to accelerate your compliance program.


Why documentation and real-time monitoring define breach readiness

The most consistent gap CisoSafe observes across regulated organizations is not a failure to understand the notification rules — it is a failure to build the operational infrastructure that makes compliance provable. Compliance officers often know the 60-day deadline. What they underestimate is how much the discovery date, the risk assessment, and the notification log matter when OCR is sitting across the table reviewing their response.

Technician managing network cables in server room

The organizations that navigate OCR investigations with the least friction share three characteristics. First, they have real-time monitoring in place that produces timestamped, tamper-evident logs. Second, they maintain documented risk assessment templates that their teams can execute within 48 hours of an incident, not 48 days. Third, they have pre-drafted notification templates reviewed by legal counsel, so the drafting process under pressure does not introduce errors or delays.

The conventional wisdom in compliance circles is that breach response is primarily a legal and communications problem. That framing is incomplete. The technical infrastructure — log retention, endpoint detection, automated evidence capture — is what determines whether your legal team has anything defensible to work with. A well-written notice sent on Day 58 with no supporting documentation is a far weaker position than an imperfect notice sent on Day 20 with a complete, timestamped investigation file behind it.

Waiting for a breach to test your readiness is the most expensive way to find out what your program is missing.


CisoSafe reduces your breach-notification risk before an incident occurs

Regulated organizations that lack a structured breach-response program face a predictable problem: when an incident occurs, they are building the process and executing it simultaneously, under regulatory time pressure. CisoSafe eliminates that problem by delivering the infrastructure, templates, and expert guidance before the clock starts.

CisoSafe

CisoSafe's vCISO services and AI-powered compliance platform give your organization the operational readiness that OCR expects to see during an investigation. The platform supports real-time threat monitoring with automated, timestamped evidence capture — the exact documentation that establishes a defensible discovery date. CisoSafe's vCISO team delivers pre-built risk-assessment templates aligned to the four regulatory factors, individual and HHS notification templates reviewed for plain-language compliance, and incident response planning that maps to the 24–72 hour checklist above.

Relevant services for breach-notification readiness include:

  • Incident response planning and tabletop exercises
  • Real-time monitoring and automated log retention
  • HIPAA risk assessments and compliance gap analysis
  • Notification template development and legal review coordination
  • Evidence retention and audit-ready documentation packages
  • Third-party risk management and BAA review support

Schedule an incident readiness review with CisoSafe's vCISO team at Cisosafe to assess your current breach-response posture and close the gaps before they become enforcement findings.


Sources

These are the primary federal sources you will need during an incident response and reporting process:

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.