Breach Notification Timelines Explained in Plain English

When something goes wrong with resident information, the first questions are usually "Is this a breach?" and "How long do we have?" The HIPAA Breach Notification Rule answers both, but the language can feel dense. This post puts the main points in plain English. It is general information, not legal advice, and state laws may add their own requirements, so involve counsel early.

What Counts as a Breach

A breach is an impermissible use or disclosure of unsecured protected health information (PHI) that compromises its security or privacy. Examples include:

A laptop with unencrypted resident records is stolen

A fax or email goes to the wrong recipient

An employee looks at records of a neighbor with no job reason

Ransomware encrypts files containing PHI

A vendor mailbox is hacked and contains resident data

"Unsecured" generally means not encrypted or destroyed in a way HHS guidance recognizes. That is one reason encryption matters: properly encrypted data lost along with a device may fall outside the notification requirement.

The Presumption and the Risk Assessment

An impermissible use or disclosure is presumed to be a breach unless you can show a low probability that the PHI was compromised. That conclusion rests on a documented assessment of at least four factors:

The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or received it

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated

Document this assessment every time, even when you conclude no notification is needed.

Exceptions

Certain situations are not breaches, including some unintentional, good-faith access by workforce members acting within their authority, and some inadvertent disclosures between authorized people within the same organization, as long as the information is not further misused. Have counsel confirm any exception.

The Key Deadlines

Notice to individuals

Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a goal. Delay without good reason can itself be a violation.

A breach is treated as discovered on the first day it is known, or would have been known with reasonable diligence, to anyone in the organization other than the person who committed it.

Notice to HHS

500 or more individuals: notify HHS at the same time as individuals, no later than 60 days after discovery, through the OCR breach portal.

Fewer than 500 individuals: keep a log and report to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.

Notice to the media

If a breach involves more than 500 residents of a single state or jurisdiction, you must also notify prominent media outlets serving that area, within the same 60-day limit.

Business associates

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Your agreements may require much shorter timelines, which is wise.

What the Notice to Individuals Must Contain

Written in plain language, sent by first-class mail or email if the person agreed to electronic notice, and including:

What happened and when, including dates of the breach and discovery

The types of information involved

Steps individuals should take to protect themselves

What you are doing to investigate, mitigate harm and prevent recurrence

How to contact you, including a toll-free number, email, website or postal address

For residents who lack capacity, notice goes to the personal representative. If contact information is outdated for ten or more people, substitute notice such as a website posting or major media notice is required.

Law Enforcement Delays

If a law enforcement official states that notification would impede a criminal investigation, you may delay notification for the time specified, with proper documentation.

State Laws

Oklahoma, Texas, Arkansas and other states have their own breach notification statutes with different definitions and timing. Some set shorter deadlines or require notice to the state attorney general. Compare requirements early.

Build a Simple Response Rhythm

Contain the issue and preserve evidence.

Notify your privacy officer and counsel right away.

Start the four-factor assessment.

Calendar the 60-day limit from the discovery date.

Prepare notice letters and call-center scripts in advance.

Document everything, including why a breach was or was not reportable.

How UnityCare IT Can Help

UnityCare IT supports healthcare organizations with the technical side of incident investigation, including determining what systems and data were affected, which informs the breach assessment. If you want to practice, we can run a tabletop exercise with your team.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172