Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The HIPAA Breach Notification Rule: What Counts as a Breach and What You Must Do

July 13, 2026

The HIPAA breach notification rule requires healthcare organizations and their vendors to alert patients, the federal government, and sometimes the media when unsecured health data is exposed. If your Chicagoland practice or business associate firm loses control of patient files, this rule dictates exactly who you must tell and how fast you must do it.

Understanding these breach notification rule requirements is critical because the clock starts ticking the moment an incident is discovered. Missing a deadline or failing to report an exposure can trigger severe HIPAA violations and penalties and intense regulatory scrutiny.

Federal civil penalties are tiered by culpability. Under the current inflation-adjusted penalty table, individual violations range from about $145 to roughly $73,011, with an annual cap of about $2.19 million per violation category.

Ignoring these deadlines is a massive financial risk. When a cyberattack or an operational mistake exposes data, you cannot simply fix the technical issue and move on in silence. You have to follow a strict legal playbook to investigate the incident, determine the scope of the damage, and notify the right people before time runs out.

What the HIPAA Breach Notification Rule Requires

At its core, the rule governs what must happen when unsecured protected health information is exposed to unauthorized people. It applies directly to covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates (vendors like IT providers, billing companies, EHR vendors, shredding services, and cloud services).

If you are wondering what is the purpose of the breach notification rule, it exists to ensure transparency and protect patients. When an organization experiences a data exposure, they are legally obligated to inform the affected people so those individuals can take steps to protect themselves from identity theft or medical fraud.

Three duties kick in the moment a breach is discovered. To comply with the rule, an organization must execute three primary duties when a breach occurs:

  • Notify affected individuals: You must send a written notice to every person whose data was involved.
  • Notify the government: You must report the incident to the HHS Office for Civil Rights.
  • Notify the media: If the breach affects a large enough group in a single state or jurisdiction, you must issue a press release to prominent media outlets.

Who enforces the rule. The HHS Office for Civil Rights (OCR) enforces this rule and has the authority to investigate complaints, conduct audits, and levy civil monetary penalties.

The breach notification letter has a required format. When you send a notification to an affected individual, you cannot just send a vague apology. The rule dictates the exact required content. Every letter must include:

  • A brief description of what happened, including the date of the breach and the date of discovery
  • The types of unsecured data that were involved
  • Steps the individuals should take to protect themselves
  • A description of what your organization is doing to investigate and mitigate the damage
  • Toll-free contact procedures so patients can ask questions

The rule also places direct liability on business associates. A vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity must report any breach back to that covered entity. The covered entity then typically handles notifying the patients and the government, though the exact responsibilities are defined in their Business Associate Agreement (BAA).

A missing or unsigned BAA is itself a violation of the HIPAA Privacy Rule, since a covered entity may only share PHI with a business associate under a documented written contract.

What Counts as a Breach of Unsecured PHI

Not every it glitch or lost device triggers a massive reporting event. The rule specifically applies to unsecured protected health information. To understand your covered entity breach obligations, you have to look at what the data is and how it was protected.

Protected health information (PHI) is individually identifiable health information held or transmitted in any form. Electronic protected health information (ePHI) is the digital subset of this data. It lives in your electronic health records, staff email accounts, server backups, and shared cloud drives.

The 18 identifiers that make data “protected.” The government recognizes 18 specific identifiers that make health data identifiable. These include names, addresses, dates, phone numbers, email addresses, Social Security numbers, medical record numbers, and biometric identifiers. If all 18 identifiers are removed, the data is officially de-identified and no longer falls under HIPAA.

Key distinction: A breach occurs when there is an impermissible use or disclosure under the HIPAA Privacy Rule that compromises the security or privacy of this identifiable data. The exact definition hinges on the word “unsecured.”

The Encryption Safe Harbor

This is where your it setup heavily influences your legal risk. Unsecured protected health information means data that is not rendered unusable, unreadable, or indecipherable to unauthorized people. If your data is properly encrypted and the decryption key was not compromised, the data is generally not considered unsecured — so its loss is usually not a reportable breach.

A concrete example shows why this matters. Consider a doctor who leaves a clinic laptop in a coffee shop in Woodstock. If the laptop has full-disk encryption and a strong password, the data remains secure. You lost hardware, but you did not suffer a HIPAA breach. If the laptop is unencrypted, however, anyone who finds it can read the patient files. That is a breach, and you must start notifying people.

Encryption is a safe harbor, not optional. LeadingIT operates the technical half of HIPAA for many Illinois practices, and encryption is a mandatory baseline. Encrypting ePHI at rest and in transit is a technical safeguard required by the HIPAA Security Rule. It acts as a safe harbor: if cybercriminals steal encrypted files but cannot access your encryption keys, you avoid the devastating fallout of a public breach notification.

Proper IT management focuses so heavily on device controls and secure access management precisely because encryption without access controls is meaningless.

Exceptions to the Rule

The regulation carves out a few narrow exceptions where an exposure does not count as a reportable breach. These generally involve situations where the data did not leave the controlled environment and further disclosure is highly unlikely.

  • Unintentional access by an employee: If a staff member accidentally opens the wrong patient record while doing their job in good faith, and they do not share that information further, it is not a breach.
  • Inadvertent disclosure between authorized personnel: If one authorized doctor accidentally sends a patient chart to another authorized nurse at the same facility, and the data stays within the facility, it is not a reportable breach.
  • Inability to retain the data: If you accidentally mail a patient statement to the wrong address, but the post office returns it unopened because the address does not exist, the unauthorized person never had a chance to view the data.

Unless you meet one of these strict exceptions, or you can prove through a formal risk assessment that there is a low probability the data was compromised, you must assume a breach occurred and begin the notification process.

The Clocks: Deadlines and Thresholds for Notification

When a breach happens, the HIPAA breach notification timeline is strict. The clock begins the moment the breach is discovered. Discovery means the first day anyone in your workforce (other than the person who caused the breach) knows about it, or reasonably should have known about it.

You cannot delay discovery by intentionally ignoring warning signs in your it network. If a hacker breaches your server on Monday, but your IT team does not check the alert logs until Friday, the government may argue that you reasonably should have known on Monday.

The 60-Day Maximum and “Without Unreasonable Delay”

The golden rule: notify affected individuals without unreasonable delay and no later than 60 days after discovery. Sixty days is the absolute maximum limit, not a grace period.

This 60 day breach notification requirement trips up many business owners. If your IT team and forensics investigators figure out exactly whose data was stolen early in the investigation, you cannot wait until day sixty to mail the letters. You must notify those patients immediately.

The only time law enforcement can pause this clock is if they provide a written statement that notifying patients would impede a criminal investigation or threaten national security.

During this window, your incident response plan is critical. Your IT provider must secure the network, review access logs, and determine exactly what data was touched. You need documented proof of what happened and how you responded.

A pattern shows up again and again in HIPAA enforcement: settlement after settlement traces back to one failure, no proper risk analysis.

This is where audit logging becomes your best defense. If you do not have detailed logs showing exactly which files a hacker accessed, you have to assume they accessed everything. You will be forced to report a massive breach. Proper logging allows your IT provider to prove exactly what was touched, potentially reducing a massive network incident down to a small, isolated exposure.

Small vs Large Breach Reporting Thresholds

The rule splits reporting requirements based on how many people are affected. The threshold number is 500, and every notification duty branches at that line:

RequirementFewer than 500 individuals500 or more individuals
Notify affected individualsWithout unreasonable delay, and within 60 days of discoveryWithout unreasonable delay, and within 60 days of discovery
Notify HHS Office for Civil RightsKeep a log and submit it annually, within 60 days after the end of the calendar year in which the breaches were discoveredWithout unreasonable delay, and within 60 days of discovery
Notify the mediaNot requiredPress release to prominent media outlets serving the state or jurisdiction where the affected individuals live
Public exposureNot applicablePosted on the HHS “Wall of Shame,” which often triggers an OCR investigation

The media notification HIPAA breach 500 requirement exists so the public learns of the risk even when you do not have current contact information for every single patient, and your HHS office for civil rights reporting is what lands a large breach on that public government website. The listing draws immediate public scrutiny.

The 2024 Change Healthcare hack exposed the health data of 192.7 million people, becoming the largest healthcare data breach in US history.

While most incidents are far smaller, any breach hitting the 500-person mark requires immediate, large-scale action. These small vs large breach reporting thresholds give minor incidents slightly more breathing room on the government-reporting side.

The patient-notification duty remains the same regardless of size. If an employee loses a paper file containing the records of a few patients, you still must notify those specific patients within the same 60-day window. You simply skip the media outreach and roll the incident into the annual log you submit to HHS.

Business Associate Breach Notification Timelines

If you are a vendor handling ePHI, your business associate breach notification duties are slightly different. You do not notify the patients or the media directly. Instead, you must notify the covered entity.

The notification handoff follows a clear three-stage chain, with each link carrying its own deadline:

StageWho actsWhat they must doDeadline
1. DiscoveryBusiness AssociateDiscovers breach, gathers affected-individual names, description of incident, types of PHI involved, and mitigation steps takenReport to Covered Entity without unreasonable delay, no later than 60 days
2. ReceiptCovered EntityReceives BA report; its own 60-day patient-notification clock starts from this receiptSame 60-day maximum to notify patients, HHS, and media (if 500+)
3. DownstreamCovered EntitySends all notifications to patients, HHS Office for Civil Rights, and prominent media outlets (if 500+ affected)Within 60 days of BA report receipt

The BAA often tightens the timeline. The law requires business associates to notify the covered entity without unreasonable delay and no later than 60 days after discovering the breach.

In practice, a well-written Business Associate Agreement almost always shortens this window. Most covered entities require their vendors to report incidents within a few days. If a vendor waits 60 days to tell a clinic about a breach, the clinic will have no time left to investigate and notify their patients before their own 60-day clock expires.

When a vendor reports an incident, they must provide the covered entity with all available details. This includes the names of the affected individuals, a description of what happened, the types of unsecured protected health information involved, and the steps the vendor is taking to mitigate the damage.

The practical takeaway: Understanding these deadlines is why proactive IT management is non-negotiable. If you do not have active monitoring in place, you will spend your entire 60-day window just trying to figure out if a hacker accessed your systems. By the time you realize what happened, the deadline will have passed.

The Four-Factor Risk Assessment When Something Goes Wrong

When an incident occurs, you do not automatically have to send a breach notification letter. The law presumes that any impermissible use or disclosure of unsecured protected health information is a breach, but you can overcome this presumption. To do so, you must conduct a formal risk assessment to prove there is a low probability that the data was actually compromised.

This is not a gut feeling or a quick guess by your IT team. The government requires you to evaluate the incident using a strict four-factor risk assessment. You must document your findings for every incident, even if you decide not to report it.

Use this decision matrix to work through the four factors in order:

FactorWhat to checkLow-risk outcomeHigh-risk outcome
1. Nature and extent of PHI involvedWas it a name and appointment time, or SSNs and detailed treatment plans? Can the data be easily linked to specific individuals?Routine data with low re-identification riskFinancial or clinical data with high identity-theft risk
2. Identity of unauthorized recipientIs the recipient another HIPAA-covered provider who knows how to handle data, or a cybercriminal or random commercial party?Recipient is bound by HIPAA and will likely destroy the dataRecipient has no HIPAA obligation; probable misuse
3. Was data actually acquired or viewed?Do audit logs prove nobody opened the files? Did forensics show a stolen laptop was never powered on?Data was not viewed; low probability of compromiseCannot prove data was untouched; must assume it was viewed
4. Extent to which risk was mitigatedDid you obtain a sworn statement the recipient deleted the unopened email? Was the lost phone remote-wiped before unlock?Risk effectively mitigated; low probability of harmNo mitigation possible; data is out of your control

If you evaluate these four factors and cannot confidently demonstrate a low probability of compromise, you must proceed with HIPAA breach reporting. Looking at common HIPAA breach examples, organizations often fail this assessment simply because they lack the technical monitoring required to prove what happened.

Why a Written Incident-Response Plan Decides How This Goes

When a data exposure happens, chaos is your biggest liability. You only have a maximum of 60 days to investigate, stop the leak, perform the four-factor risk assessment, identify every affected patient, draft the notification letters, and contact the government. You cannot figure out how to do this on the fly.

The Security Rule requires three safeguard categories to protect your systems. These are administrative, physical, and technical safeguards. Your incident response plan falls squarely under administrative safeguards.

Safeguard categoryWhat it coversExamples for a medical practice
AdministrativePolicies, procedures, and designated accountable personnelRisk analysis, incident response plan, Security Officer designation, workforce training, BAA management
PhysicalPhysical barriers and controls protecting hardware and facilitiesDoor locks, workstation security, device disposal procedures, facility access controls
TechnicalTechnology-based controls protecting data and systemsEncryption (at rest and in transit), access controls (MFA, role-based), audit logging, network monitoring, automatic logoff

The Security Officer and Privacy Officer are named accountable owners. HIPAA requires formally designating a Privacy Officer and a Security Officer. These individuals are the accountable owners of your compliance program. When an incident occurs, your response plan dictates exactly what these officers must do, who they must call, and how your IT provider fits into the response.

A documented, current risk analysis is the foundation of this plan and the single most-requested document in an investigation. If you want to know how to build this foundation, reviewing the risk assessment guide is your first step.

OCR investigations are typically triggered by a complaint, a reported breach, or selection under the OCR audit program. Any breach affecting 500 or more individuals draws heightened OCR scrutiny. When the government investigates, the process is mostly a documentation request. Investigators will ask for:

  • Your risk analysis
  • Your policies
  • Training records
  • Access logs
  • Incident records
  • Business Associate Agreements

If your incident response plan is just a template you downloaded and never customized, you will fail the audit. Your plan must detail how your specific practice works with your managed IT provider to isolate infected servers, preserve forensic evidence, and pull the audit logs necessary to determine the scope of the breach. If you cannot produce this documentation, you will face severe HIPAA breach notification penalties.

See Where You Stand

Free 2-minute HIPAA Risk-Check: 8 plain-English questions, your audit-readiness level and the gaps to fix. No sign-up to see your result. free HIPAA compliance checklist

Frequently Asked Questions

How many days to notify a HIPAA breach?

You must notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach. This 60-day window is a strict maximum limit, not a grace period.

How soon after a breach must notification be given?

Notification must be given as quickly as possible once the facts are known. The law requires action without unreasonable delay, meaning you should send notifications immediately after identifying the affected individuals, provided it is within the 60-day limit.

What is considered a breach under the breach notification rule?

A breach is an impermissible use or disclosure of unsecured protected health information that compromises the security or privacy of the data. This assumes a breach occurred unless a risk assessment proves there is a low probability the data was actually compromised.

Does HIPAA have a breach notification rule?

Yes. The Breach Notification Rule is one of the primary components of HIPAA. It legally mandates how covered entities and business associates must respond when unsecured health data is exposed.

Is the breach notification rule a HIPAA rule?

Yes. It sits alongside the Privacy Rule and the Security Rule to form the core regulatory framework of HIPAA compliance. It is enforced by the HHS Office for Civil Rights.

Protect Your Practice with Proactive it

There is no official “HIPAA certified” status for a business or an IT vendor. Compliance is an ongoing state you maintain and can evidence, not a certificate you buy. LeadingIT helps you become and stay compliant by managing the technical safeguards and documentation required to protect your patient data.

Leading it has helped Illinois practices meet HIPAA since 2010. If you need help securing your network or managing your vendor agreements, explore Leading it’s HIPAA compliance services. You can also book a call directly, contact us online, or call us at 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.