Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA Training

Module 04 · Free · 7:56

HIPAA Breach Notification Rule

The definition of a breach and the three exceptions to it, what unsecured PHI is, the individual/media/HHS notification timelines, business associate notification, and the administrative documentation the rule requires.

The Breach Notification Rule governs what a practice must do when patient information is compromised. This module covers the definition of a breach, the three specific exceptions to that definition, what "unsecured PHI" actually means, the notification methods and 60-day timelines for individuals / HHS / media, business associate notification, and the administrative documentation the rule requires the practice to maintain.

Regulatory anchors

  • 45 CFR §164.402
  • 45 CFR §164.404
  • 45 CFR §164.406
  • 45 CFR §164.408
  • 45 CFR §164.410
  • 45 CFR §164.414

Hosted on the Patient Protect YouTube channel

HIPAA Breach Notification Rule: What Your Practice Must Do

Learning objectives

What the workforce should be able to do after this module.

  • Understand the purpose of the Breach Notification Rule
  • Define what constitutes a breach and identify the three exceptions
  • Learn breach notification requirements, methods, and timelines
  • Understand documentation and compliance responsibilities

Assessment: 5 knowledge-check questions per module, 80% passing standard.

Module outline

Section-by-section walkthrough.

  1. 01

    Purpose of the Breach Notification Rule

    The rule ensures that patients, regulatory authorities, and — in some cases — the public are informed when patient information has been compromised. It promotes transparency, accountability, and timely response, and reinforces the HHS requirements for privacy and security.

  2. 02

    Definition of a breach

    A breach is the unauthorized access, use, or disclosure of PHI or ePHI that compromises the security or privacy of that information. Not all incidents are breaches — three specific exceptions apply.

  3. 03

    The three exceptions to breach

    Exception 1: unintentional acquisition, access, or use of PHI by a workforce member, Business Associate, or someone acting under the authority of a Covered Entity — done in good faith, within the scope of their role. Exception 2: communication of PHI between authorized covered entities or business associates (provider to provider, provider to health plan), as long as not disclosed beyond what the Privacy Rule permits. Exception 3: good-faith belief that the unauthorized individual who accessed the PHI could not retain the information — the information was immediately destroyed, not understood, or could not be copied or shared.

  4. 04

    Unsecured PHI — the trigger for notification

    Unsecured PHI is patient information that has not been encrypted or has not been properly disposed of per HHS standards. HHS states that breach notification is only required when the breach involves unsecured PHI. Encryption and proper disposal remain the strongest protection against triggering notification obligations.

  5. 05

    Individual notification — first-class mail or email, 60 days

    Affected individuals must be notified without unreasonable delay and no later than 60 days after the breach is discovered. Notification should be sent by first-class mail, or by email if the patient has agreed to receive communications electronically. If contact information is outdated for 10 or more individuals, the practice must post a notice on its website or a major media platform for at least 90 days. For fewer than 10 individuals, alternative methods (phone or written notice) may be used.

  6. 06

    Media notification — 500+ individuals in a state

    If a breach affects more than 500 individuals within a specific state or jurisdiction, the practice must notify prominent media outlets within that area within 60 days.

  7. 07

    Secretary (HHS) notification — timeline depends on scale

    Breaches affecting 500 or more individuals must be reported to HHS within 60 days via the electronic breach reporting form. Breaches affecting fewer than 500 individuals must be reported annually — within 60 days of the end of the calendar year.

  8. 08

    Business Associate notification

    If a breach occurs through a Business Associate, the BA must notify the covered entity within 60 days of discovery. Either the BA or the covered entity may notify affected individuals — the responsibility must be clearly outlined and mutually agreed upon.

  9. 09

    Administrative documentation

    The practice must maintain proof of all breach notifications provided, document the date of the breach and the number of individuals affected, keep copies of all reports submitted to HHS, document any incidents that did not qualify as a breach (with the reasoning — typically a documented risk assessment), maintain written breach-notification policies, train staff on those policies, and have disciplinary policies in place for employees who do not follow HIPAA procedures.

Sample knowledge check

A representative question from this module.

Sample question · 5 per module in the live series

A workforce member accidentally opens a chart for the wrong patient in the EHR, immediately realizes the mistake, and closes it without viewing further or using the information. Under the Breach Notification Rule as this module describes it, does this fall under an exception to the definition of a breach?

  1. A.No — any unauthorized access is automatically a breach.
  2. B.Yes — this fits Exception 1: unintentional acquisition, access, or use of PHI by a workforce member in good faith, within the scope of their role.
  3. C.Yes — but only if the workforce member reports it in writing within 24 hours.
  4. D.No — the three exceptions apply only to Business Associates, not to workforce members.
Show explanation

Correct answer: B. Exception 1 to the definition of a breach covers unintentional acquisition, access, or use of PHI by a workforce member, Business Associate, or someone acting under a covered entity — in good faith, within the scope of their role. The practice should still document the incident and its determination.

Module 04 of the HIPAA Foundations series

Every learner. Every module. One office price.

When you are ready to train the whole practice, the complete 19-module HIPAA Foundations series unlocks for up to 25 personnel at $39/office/month — with per-learner assessment scores, verifiable Certificates of Completion, and workforce-wide tracking.

Free tools stay free — no account needed. The 14-day platform trial asks for a card for identity verification; no charge before day 14, cancel any time.