Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Breach Intelligence

HIPAA Breach Notification: Who to Tell, and When

Five separate notification duties with different deadlines and different recipients. When the clock starts, who gets told, and where the 60-day shorthand is wrong.

Patient ProtectPatient Protect Editorial Team·March 17, 2026·17 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
Timeline diagram showing HIPAA breach notification requirements from discovery through HHS reporting deadlines

HIPAA Breach Notification Guide: Requirements, Timeline & Reporting Steps (2026)

When a breach happens, most practices do not know what to do first. They know it is bad. They know they need to tell someone. But the specifics — who to notify, in what order, by when, and through which channel — are buried in a regulation most practice owners have never read end to end.

The HIPAA Breach Notification Rule (45 CFR §164.400–414) lays out specific requirements. There are two reporting tracks, hard deadlines, mandatory content for notification letters, and state-level requirements that can be stricter than the federal standard. Getting this wrong does not just delay recovery. It compounds the original violation with a second one.

This guide covers the full breach notification process for independent healthcare practices — from determining whether an incident qualifies as a breach to filing the final report with HHS.

What Counts as a Breach?

Under the Breach Notification Rule, a breach is an impermissible use or disclosure of protected health information (PHI) that compromises the security or privacy of the information. That definition is broad by design.

The critical default: any impermissible disclosure of PHI is presumed to be a breach unless your practice can demonstrate, through a documented risk assessment, that there is a low probability the PHI was actually compromised.

That risk assessment uses four factors:

  1. The nature and extent of the PHI involved. What types of identifiers were exposed? Did the disclosure include clinical information, Social Security numbers, or financial data? The more sensitive the data, the higher the risk.

  2. Who accessed or received the PHI. An unauthorized disclosure to another covered entity carries different risk than a disclosure to an unknown third party or a disclosure that was publicly accessible.

  3. Whether the PHI was actually acquired or viewed. A misdirected fax that was returned unopened carries lower risk than an email attachment that was opened and downloaded. If you can demonstrate the data was never accessed, the probability of compromise drops.

  4. The extent to which the risk has been mitigated. Did you retrieve the data? Did the recipient confirm destruction? Did you receive assurances that the information will not be used or further disclosed?

The assessment is how you rebut the presumption — it is not a step every incident requires. If one of the three §164.402 exclusions applies, there is no presumption to rebut and no breach to notify. A practice may also elect to notify without performing the assessment at all, which is sometimes the faster and cheaper answer for a small, obvious incident. Where you do rely on the assessment, document it. If the analysis concludes there is a low probability of compromise, you are not required to notify. But the documentation must exist. §164.414(b) puts the burden on you to show either that the required notifications were made or that the incident was not a breach. If OCR investigates and you cannot produce the written assessment, you have not carried that burden and the presumption stands — which is a bad position to be in, and a different thing from having failed to notify, which depends on what you actually did.

The Two Reporting Tracks

HIPAA separates breaches into two categories with different notification requirements. The dividing line is 500 affected individuals.

Large Breaches: 500 or More Individuals

These are the breaches that make the news. The requirements are:

Notify HHS contemporaneously with the individual notice. §164.408(b) ties the report to the notice you send individuals under §164.404(a), and HHS states the same standard for the report itself: without unreasonable delay and no later than 60 calendar days from discovery. Sixty days is the outer limit, not the schedule. Submit the report through the HHS breach reporting portal (ocrportal.hhs.gov). Once submitted, the breach is posted publicly on the HHS Breach Portal — commonly called the "Wall of Shame" — where it is visible to regulators, journalists, competitors, and patients indefinitely.

Notify affected individuals without unreasonable delay, and no later than 60 calendar days. Written notification by first-class mail to every individual whose PHI was compromised. If the individual previously consented to electronic communication, email is acceptable. The notification must contain specific content elements (covered below).

Notify prominent media outlets. If the breach affects more than 500 residents of a single state or jurisdiction, you must issue a press release or equivalent notice to prominent media outlets serving that state, on the same timing as the individual notice. Note the threshold is not the same as the one above: HHS reporting turns on 500 or more individuals in total, media notice on more than 500 residents of one state. This is not optional. It is a regulatory requirement that practices routinely overlook.

Small Breaches: Fewer Than 500 Individuals

These are more common in independent practices. A misdirected fax, a misfiled record, an email sent to the wrong patient.

Notify affected individuals without unreasonable delay, and no later than 60 calendar days. Same standard, same content requirements as large breaches. The obligation to the individual does not change based on scale.

Log the breach internally. Maintain a breach log that records the details of every small breach — date of discovery, individuals affected, nature of the breach, and the outcome of the four-factor risk assessment.

Report to HHS after the year ends. §164.408(c) sets this at no later than 60 days after the end of the calendar year in which the breach was discovered — which lands on March 1 in most years and is usually quoted that way. Each breach is submitted as its own entry through the same portal; it is a log of individual reports, not one summary. Note the trigger is the year of discovery, not the year the breach happened, which matters for an incident found in January that began the previous autumn.

Business Associates: A Separate Duty

The scenario has enough moving parts to be worth its own walkthrough: what to do when a vendor is breached covers the sequence from the vendor's notice through your own filings.

If your vendor is the one who had the breach, the duty to see that your patients are notified stays with you. Under §164.410 the business associate notifies you, without unreasonable delay and no later than 60 calendar days from its own discovery. It must identify the affected individuals to the extent possible and give you the other information available to it that you need for your notices — at the time it notifies you, or promptly afterwards as it comes to hand. That last part matters in both directions: the vendor should not sit on its initial notice while it assembles a complete picture, and you should not expect the first notice to contain everything.

You remain ultimately responsible for making sure the required notifications happen. You may delegate the work of them: HHS permits a covered entity to have the business associate deliver the individual notices, and a business associate may submit the breach report to the Secretary on a covered entity's behalf. Which of you is better placed to do it depends on the circumstances — who holds the relationship with the patient, and what the vendor actually does for you. Delegating performance does not move the responsibility.

When your clock starts depends on the relationship, not on the calendar. If the business associate is your agent under the federal common law of agency, its discovery is imputed to you: your clock runs from the day the vendor discovered the breach, not the day it told you. If it is not your agent, your clock runs from the vendor's notice to you. Agency turns on how the relationship actually operates — the degree of control you have over the work — and not on the label used in the contract, so this is a question to put to counsel rather than to settle by reading the BAA's title. This is the arrangement practices are most often surprised by. The vendor's own duty is the same two-part standard — without unreasonable delay, and no later than 60 days — so a vendor that sits on a breach it could have reported in a week has not complied merely by landing inside the outer limit. What is true is that you may learn late through no fault of your own, and your own clock is not extended to compensate. It is worth checking what your BAAs actually say here, because many negotiate the vendor's window down to days rather than weeks, and that is the single most useful term in the agreement.

The Breach Notification Timeline

Here is how the process unfolds from the moment a breach is discovered. If you are in an incident right now rather than reading ahead of one, the breach response steps are the operational version of this — same obligations, ordered for someone who needs to act today.

Day 0 — Discovery. The 60-day clock starts when the breach is discovered — or when it reasonably should have been discovered. This is not when it is reported to management. It is not when the compliance officer learns about it. It is when any workforce member or agent of the practice — anyone other than the person who committed the breach — knew, or would have known by exercising reasonable diligence, that a breach had occurred. If a front desk employee noticed a misdirected fax on a Tuesday but did not tell anyone until the following Monday, the clock started on Tuesday. Which makes the workforce the part of this that is hardest to control by policy alone — the free breach notification training module is the version of this written for staff rather than for whoever owns compliance.

Containment and investigation, first. Stop the breach from continuing. Retrieve any disclosed PHI if possible. Identify which individuals were affected and what types of PHI were involved. Perform the four-factor risk assessment. Document every step.

Scope and preparation, next. Finalize the list of affected individuals. Draft notification letters that meet the content requirements below. Determine whether the breach crosses the 500-person threshold and triggers media notification. Consider engaging counsel if the breach is large, involves sensitive data, or has potential for litigation. The rule prescribes none of this internal sequencing — it is how we would run it, and the only federal clock is the one below.

Day 60 — the outer limit, not the target. §164.404(b) requires notice without unreasonable delay and in no case later than 60 days. Those are two tests, and the first one bites first: a practice that knew everything on day 5 and posted letters on day 58 has met the deadline and failed the standard. For large breaches the HHS report goes in contemporaneously with the individual notices, and media notice issues on the same footing.

There is one real extension, and it is narrow. Under §164.412, if a law enforcement official states that notification would impede a criminal investigation or damage national security, notice is delayed — for the period specified if the statement is written, or up to 30 days if it is oral and documented. Absent that, late notice is a separate violation OCR evaluates on its own.

Within 60 days of the year end — Small breach annual report. If the breach affected fewer than 500 individuals, the HHS report is due no later than 60 days after the close of the calendar year in which it was discovered — March 1 in most years, but the rule is the 60 days, not the date. Every small breach from the prior calendar year must be included.

What Individual Notification Must Include

The Breach Notification Rule specifies five content elements that every notification letter must contain. Omitting any of them makes the notification deficient:

  1. A description of the breach — what happened, in plain language, including the date of the breach and the date of discovery.

  2. The types of PHI involved — names, Social Security numbers, dates of birth, diagnoses, treatment information, financial data, or whatever specific identifiers were compromised.

  3. Steps individuals should take to protect themselves — such as monitoring credit reports, placing fraud alerts, or changing passwords. Tailor this to the type of PHI exposed.

  4. What the practice is doing in response — investigation steps, remediation measures, and steps taken to prevent recurrence.

  5. Contact information — a toll-free phone number, email address, or mailing address where affected individuals can ask questions. It should be genuinely monitored; the specific 90-day requirement belongs to substitute notice, covered below, not to every notice you send.

Notifications must be sent by first-class mail. Email is permitted only if the individual has previously agreed to receive electronic communications from the practice. If you cannot reach 10 or more individuals by mail, substitute notice is required — a conspicuous posting on your website home page for 90 days or notice in major print or broadcast media where they likely live, together with a toll-free number active for at least 90 days.

When you cannot reach someone

If contact information is out of date or insufficient for ten or more individuals, §164.404(d)(2) requires substitute notice: a conspicuous posting on your website home page for 90 days, or notice in major print or broadcast media where the affected people likely live, plus a toll-free number active for those 90 days. For fewer than ten, a substitute by any reasonable means — phone, alternative address — is enough. This is the origin of the "90 days" figure that circulates in breach discussions, and it is about unreachable individuals, not about a general contact window.

State Notification Requirements

HIPAA sets the federal floor, not the ceiling. Many states have their own breach notification laws — and some impose shorter timelines than HIPAA's 60 days.

Examples vary widely. Some states require notification within 30 days. Others require notification to the state attorney general in addition to affected individuals. Several states have expanded the definition of personal information beyond what HIPAA covers, which can trigger notification obligations even when the federal rule might not.

Your practice must comply with both federal and state requirements. When they conflict, the stricter standard applies. Check your state attorney general's website for current breach notification requirements. If your practice operates in multiple states — or treats patients from other states — you may need to comply with the laws of each.

This is an area where legal counsel adds value. A five-minute conversation with a healthcare attorney before you send notifications can prevent a state-level compliance failure.

Common Breach Notification Mistakes

One scenario sits behind a large share of these and has its own analysis: unauthorized access by a workforce member, where the question is usually whether a permitted purpose covered the access at all.

These are the errors that turn a manageable incident into a compounded regulatory problem.

Not recognizing a breach as a breach. The most dangerous mistake. A staff member sends records to the wrong patient and retrieves them the same day. The practice decides it was "not really a breach" and does nothing. But unless you perform and document the four-factor risk assessment, the presumption stands. An undocumented incident that you decided was not a breach looks exactly like a breach you tried to hide.

Starting the clock from the wrong date. The 60-day timeline runs from discovery by any workforce member — not from when it was escalated to the compliance officer, not from when it was discussed at a staff meeting, not from when leadership decided to act. Practices that delay internal reporting effectively shorten their own response window.

Not documenting the four-factor risk assessment. Even when the analysis legitimately supports a low-probability conclusion, the absence of documentation negates the analysis. OCR does not accept verbal recollections. If it is not written down, it did not happen.

Skipping media notification for large breaches. Practices that report to HHS and notify individuals sometimes forget the media notification requirement for breaches affecting more than 500 residents of a single state. This is a distinct obligation. Missing it is a distinct violation.

Missing the small-breach annual deadline. Small breaches can feel insignificant — a single misdirected fax, a single misfiled record. But they accumulate in the breach log, and the entire log must be reported to HHS no later than 60 days after the calendar year in which they were discovered. Missing the annual filing deadline draws regulatory attention to incidents that might otherwise have been unremarkable.

How Patient Protect Helps

Patient Protect provides the operational infrastructure that breach notification requires — before, during, and after an incident.

Security incident logging. Incidents your practice records are timestamped and tracked from entry through resolution, with the disposition someone wrote at the time attached to them. Patient Protect does not detect incidents in your systems — the record starts when a person enters it — and that record is what a later investigation asks for.

A place for the four-factor assessment to live. The assessment is your practice's determination and stays that way — §164.402 puts it on the covered entity, and no product discharges it. What the platform does is structure the questions, hold what you concluded, and retain it with a date on it, which is the part that is impossible to reconstruct later.

Breach intelligence dashboard. The breach dashboard tracks HHS OCR breach data, refreshed daily — every reported breach affecting 500 or more individuals, searchable by entity, state, breach type, and date. Monitor whether your business associates appear in the data before OCR contacts you.

Resolved and Reported are separate fields. Closing an incident internally and discharging a notification duty are different acts, and an event record that conflates them is how a practice comes to believe it reported something it did not. Time Occurred and Time of Action are also held separately, because the notification clock runs from discovery and that is a date you have to be able to name.

Basic starts at $39/month with no long-term contract. None of it decides whether you had a breach or writes your notices — it keeps the record that a later investigation will ask you for, which is the thing practices reliably do not have.

Frequently Asked Questions

What is the HIPAA breach notification deadline?

Sixty days from the date of discovery. Discovery occurs when any workforce member knew or reasonably should have known about the breach — not when management was informed. For large breaches (500 or more individuals), the HHS report goes in contemporaneously with the individual notice — without unreasonable delay, and no later than 60 calendar days from discovery. For small breaches (under 500), the HHS report is due no later than 60 days after the end of the calendar year in which the breach was discovered — and you may file sooner.

Do I have to report a small breach to HHS?

Yes. Every breach, regardless of size, must be reported to HHS. The difference is timing. Breaches affecting fewer than 500 individuals are reported through the HHS breach reporting portal no later than 60 days after the calendar year in which they were discovered, and may be reported as soon as they are discovered. They are not exempt from reporting — just on a different schedule.

What if I am not sure whether it was a breach?

First check whether one of the three §164.402 exclusions applies — if one does, there is no breach. Otherwise the Rule presumes that any impermissible use or disclosure is a breach, and the four-factor risk assessment is how you rebut that presumption: perform it and document it. You can also skip the assessment and simply notify, which is often the proportionate answer to a small incident. What you cannot do is skip it and stay silent — then the presumption stands, and you are working to the individual-notice clock: without unreasonable delay, and no later than 60 calendar days from discovery.

Can I be fined for a late breach notification?

Yes. Failure to provide timely breach notification is a separate HIPAA violation, independent of the underlying breach. Penalties follow the standard HIPAA penalty tiers, which are adjusted for inflation and set by culpability — see HIPAA violation penalties for the current figures. OCR evaluates the notification timeline separately from the breach itself.

What is the HHS breach reporting portal?

The portal at ocrportal.hhs.gov is the official mechanism for submitting breach reports to the Office for Civil Rights. Both large and small breach reports are filed through this portal. Large breach reports (500+ individuals) are posted publicly. Small breach annual reports are submitted but not individually published.

Does sending PHI to the wrong patient count as a breach?

It is an impermissible disclosure under the Privacy Rule, and it is presumed to be a breach — unless one of the three §164.402 exclusions applies, or you rebut the presumption with the four-factor risk assessment by demonstrating a low probability of compromise — for example, if the recipient confirmed they did not open the communication and the PHI was retrieved. Even then, the assessment must be documented. This is one of the most common breach scenarios for independent practices.


The breach notification process is not optional and it is not flexible. The deadlines are fixed, the content requirements are specific, and the consequences of noncompliance are independent of the original breach. The practices that handle it well are the ones that built the documentation infrastructure before the incident occurred.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

How exposed is your practice right now?

Take the free self-assessment — see your compliance gaps with prioritized next steps.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA