If a HIPAA breach is confirmed, I have up to 60 calendar days to notify affected people, and some breaches also have to be reported to HHS and the media.
Here’s the short version:
- Who reports: Covered entities and business associates both have duties , often managed through third-party risk management programs, but covered entities usually handle notice to patients and HHS.
- What triggers notice: A breach of unsecured PHI. If PHI was encrypted or destroyed under HHS standards, the rule may not apply.
- When notice is due:
- Individuals: without unreasonable delay, no later than 60 calendar days after discovery
- HHS for 500+ people: no later than 60 days after discovery
- HHS for under 500 people: log the breach and file by March 1, 2027 for breaches found in 2026
- Media: if 500+ residents of one state or area are affected, notice is due within 60 calendar days
- What notices must include: what happened, what PHI was involved, what people should do, what the organization is doing, and how to contact the organization.
- What to keep on file: the discovery date, risk assessment, reportability decision, copies of notices, proof they were sent, and records for at least 6 years.
Put another way: the rule comes down to four things - confirm the breach, track the date of discovery, send the right notices, and keep the file. That matters because HHS reviews all breaches affecting 500 or more individuals, and late notice has led to enforcement cases, including a $475,000 settlement mentioned in the article.
If I were turning this into an action list, it would be:
- Record the date the incident was found
- Decide whether unsecured PHI was involved
- Complete and document the risk review
- Count how many people were affected
- Send notices before the 60-day outer limit
- Keep records ready in case OCR asks for them
This article explains those steps in plain terms so I can see who must act, who must be told, and what deadlines apply.
HIPAA Breach Notification: Step-by-Step Reporting Requirements
The HIPAA Breach Notification Rule Requirements
sbb-itb-535baee
Who Must Report and What Triggers Notification
The Breach Notification Rule applies to two groups: covered entities and business associates.[14] Knowing which group your organization fits into shapes what you must report and who needs to hear about it. It also sets who handles the issue inside the organization and who takes care of notices outside it.
Covered Entities and Business Associates
Covered entities include healthcare providers such as hospitals, clinics, and physicians; health plans such as insurance issuers, HMOs, and employer-sponsored plans; and health care clearinghouses that convert health information from one format to another. Business associates are the vendors, contractors, and service providers that create, receive, maintain, or transmit PHI for a covered entity. That can include IT vendors, billing services, cloud storage providers, and data analytics firms.[14]
In plain terms, covered entities usually handle the outside-facing notices. Business associates notify the covered entity so the covered entity can finish those outside notices.[14][9] The business associate has to provide enough detail for the covered entity to investigate the incident and send notice. That notice must go out without unreasonable delay and no later than 60 days after discovery.[8][15]
Before any notice duty kicks in, make sure the incident involved unsecured PHI.
Unsecured PHI and Breach Discovery
After an incident comes to light, the next step is simple: did it involve unsecured PHI? The Breach Notification Rule applies only to unsecured PHI - PHI that has not been made unusable, unreadable, or indecipherable through approved encryption or destruction.[4][12] So if PHI was secured under HHS guidance, something like a stolen laptop would not count as a reportable breach.
There’s another key point here. An impermissible use or disclosure is presumed to be a breach unless a documented risk assessment shows a low probability of compromise.[2][11][13]
Discovery is what starts the reporting clock. The clock begins on the first day the entity knew, or should have known, about the impermissible use or disclosure. Record that first awareness date in the incident log.[7][8][9][10]
Reporting Timelines and Required Notice Recipients
After a breach is discovered, two clocks start running: one for notice to individuals and one for notice to HHS. The key is to treat them as separate tracks, because HIPAA sets different reporting rules based on who must be notified and how many people were affected.
Affected Individuals, HHS, and Media Outlets

Notice to affected individuals is due without unreasonable delay and no later than 60 calendar days after discovery.[5][18]
HHS must also receive notice. If the breach affects 500 or more individuals, notice is due without unreasonable delay and no later than 60 days from discovery, using the HHS breach portal.[18]
If the breach affects fewer than 500 individuals, covered entities must keep a log of each breach and send HHS a consolidated annual notice no later than 60 days after the end of the calendar year in which the breaches were discovered. That means logging must continue throughout the year. Utilizing on-demand cyber risk management can help streamline this ongoing documentation process.[2][16][17] For breaches discovered in 2026, the annual HHS notice is due by March 1, 2027.[17]
Media notice can also come into play. If a breach affects 500 or more residents of a state or jurisdiction, notice must go to prominent media outlets serving that state or jurisdiction. The deadline is without unreasonable delay and no later than 60 calendar days after discovery.
Deadlines for Breaches Affecting 500 or More vs. Fewer Than 500 Individuals
For notice to individuals, the 60-day limit is based on calendar days, not business days. And that 60-day mark is the outside deadline, not the target. If notice can go out earlier, it should.
For HHS reporting, the split is pretty simple:
- 500 or more individuals affected: report to HHS on the immediate timeline, no later than 60 days from discovery
- Fewer than 500 individuals affected: log each breach during the year, then file one consolidated notice after year-end
Quick-Reference Table: Recipient, Trigger, Timing, and Delivery
The table below lays out who gets notice, when, and how.
| Recipient | Trigger | Timing | Delivery Method |
|---|---|---|---|
| Affected individuals | Any breach of unsecured PHI | Without unreasonable delay and no later than 60 calendar days after discovery | Individual notice |
| HHS Secretary | Breach affecting 500 or more individuals | Without unreasonable delay and no later than 60 days from discovery | HHS breach portal |
| HHS Secretary | Breach affecting fewer than 500 individuals | No later than 60 days after the end of the calendar year | Consolidated annual notice through the HHS breach portal |
| Media outlets | Breach affecting 500 or more residents of a state or jurisdiction | Without unreasonable delay and no later than 60 calendar days after discovery | Notice to prominent media outlets serving the affected state or jurisdiction |
Once the deadlines are pinned down, the next step is making sure the notice itself includes all of HIPAA's required elements.
What the Notice Must Include and How to Send It
Once the timing is set, the next step is the notice itself: what it says and how you send it. This is where many organizations slip up. A notice may go out on time and still fall short if it leaves out required details.
Required Content for Individual Notices
Under 45 C.F.R. § 164.404, each individual breach notice must be written in plain language and include five core elements.[6][19][20][21][22]
- What happened: A short description of the incident, including the breach date and discovery date, if known.
- What information was involved: The categories of unsecured PHI involved, such as full name, Social Security number, date of birth, home address, account number, diagnosis, or disability code.[25]
- Steps individuals should take: Clear steps tied to the data exposed, such as placing a fraud alert, freezing credit, reviewing records, or watching for phishing.
- Actions the organization is taking: A short explanation of the investigation, mitigation steps, and security changes to address enterprise risks now in progress.
- How to get more information: At least one contact method, such as a toll-free phone number, email address, website, or mailing address, so people can ask questions or get more detail.
In practice, the items most often left out are the description of the PHI involved and the steps individuals should take.[23] If even one required item is missing, the notice is incomplete. That’s why a standard template with clear headings can save a lot of trouble.[24][3][27]
Written, Electronic, and Substitute Notice Methods
Written notice should go by first-class mail unless the individual has agreed to receive it electronically. If you use email, keep a documented opt-in record showing that the patient agreed to that method.[28][29]
If direct contact doesn’t work, HIPAA allows substitute notice. The method depends on how many affected people can’t be reached.[29]
- Fewer than 10 individuals: Use an alternate written notice, a phone call, or another method reasonably likely to reach the person.
- 10 or more individuals: Post the notice on the home page for at least 90 days, or place notice in major print or broadcast media serving the affected area. The substitute notice must also include a toll-free phone number active for at least 90 days so individuals can find out whether their PHI was involved.[29][26]
Documentation, Internal Response, and Summary
Breach Records, Escalation, and Audit Readiness
Once notice is on the table, documentation becomes the main job. Under HIPAA, covered entities and business associates must be able to show compliance, which means OCR can review the matter at any time.[36][1]
Each breach investigation should have its own file. That file should include the date and time of discovery, a description of what happened, which systems and PHI were involved, internal incident reports, investigation notes, timelines from discovery through final notice, the four-factor risk assessment, the reportability decision, copies of notices sent to individuals, HHS, and the media, proof of delivery, and any corrective actions taken.[5][38][31] That record is what OCR will look at when it reviews the case. OCR may also ask for proof of how the incident moved through the organization, including meeting notes, call logs, and internal emails, not just the formal notices.[37][33]
This is where many teams get into trouble. If internal escalation is weak, notice often goes out late. The Presence Health case is a clear example: OCR cited delayed notice after missing paper schedules exposed PHI for 836 people, which led to a $475,000 settlement and a corrective action plan.[34][32][35]
A defined Breach Response Team can help stop that kind of breakdown. This group should include the Privacy Officer, Security Officer, legal counsel, compliance, and executive leadership. Security handles the technical side. Privacy and legal interpret HIPAA rules. Compliance checks the documentation. Communications manages external messaging.[30][31] The key point is simple: write down escalation criteria before anything happens.
The last step on the operations side is keeping records audit-ready. Keep all breach records, including non-reportable incidents, for at least six years.[31] Non-breaches still matter. OCR can review those decisions during an audit and will expect to see the risk-assessment reasoning behind them.[5][38]
Key Reporting Requirements to Remember
Strong documentation, a defined escalation team, and steady recordkeeping form the operational backbone of HIPAA breach compliance. Treat the breach file as the main audit record, and keep it up to date from the moment the incident is discovered. Keep all breach records, including incidents found not reportable, for at least six years.[31]
FAQs
What counts as discovery under HIPAA?
Under HIPAA, discovery happens on the first day a breach is known to any workforce member or agent of the covered entity. It can also happen on the day the breach should have been known through reasonable diligence, whichever comes first.
That date starts the 60-day notification clock. Not the date the investigation ends.
When is a breach low risk?
Under HIPAA, any unauthorized acquisition, access, use, or disclosure of unsecured PHI is presumed to be a breach.
There’s only one narrow exception. It may count as low risk if a documented four-factor risk assessment shows there was a low chance the PHI was compromised.
That assessment looks at:
- the type of PHI involved
- who accessed it
- whether it was actually viewed or acquired
- how much the risk was reduced after the fact
Who sends notice if a business associate is involved?
If a business associate is involved in a breach, it must notify the covered entity.
The covered entity is still on the hook for making sure affected individuals, HHS, and the media get the required notices. A business associate can send those notices on the covered entity’s behalf, but accountability stays with the covered entity. That split of duties should be spelled out clearly in the Business Associate Agreement.