Breach Notification Timelines Under HIPAA, Step by Step

When a security incident exposes protected health information, administrators quickly face a stressful question: what do we have to report, to whom and by when? The HIPAA Breach Notification Rule sets out requirements for covered entities and business associates. This article summarizes the main timelines in plain language. It is general information, not legal advice, and state laws may add requirements, so involve counsel early.

Step one: Is it a breach

The Rule defines a breach as an impermissible use or disclosure of protected health information that compromises the security or privacy of the information. An impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the PHI has been compromised, based on a documented risk assessment of at least four factors:

The nature and extent of the PHI involved, including the types of identifiers and likelihood of re-identification

The unauthorized person who used the PHI or to whom the disclosure was made

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated

The Rule also lists exceptions, such as unintentional access by a workforce member acting in good faith within the scope of their authority, and inadvertent disclosures between authorized persons at the same organization, provided the information is not further misused.

Another important concept is unsecured PHI. The notification requirements apply to PHI that is not rendered unusable, unreadable or indecipherable to unauthorized persons through methods specified by HHS, such as appropriate encryption. Properly encrypted data on a lost laptop, for instance, may fall outside notification requirements.

Step two: Know when the clock starts

A breach is treated as discovered on the first day it is known to the organization, or would have been known by exercising reasonable diligence. Waiting to investigate does not delay the clock. This is why prompt internal reporting and incident logging matter.

Step three: Notify affected individuals

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery. Sixty days is an outer limit, not a target. Notice should go out as soon as you have the information needed, and it should be written in plain language. Content generally includes:

A brief description of what happened, including dates of the breach and discovery

The types of information involved

Steps individuals should take to protect themselves

What your organization is doing to investigate, mitigate harm and prevent recurrence

Contact procedures, including a toll-free number, email address, website or postal address

Notice is typically by first-class mail, or by email if the individual has agreed to electronic notice. If contact information is out of date for ten or more individuals, substitute notice through a conspicuous website posting or major media is required, with a toll-free number active for at least 90 days. Urgent situations may warrant telephone notice in addition.

For residents who cannot manage their own affairs, notice generally goes to a personal representative.

Step four: Notify HHS

Breaches affecting 500 or more individuals: notify HHS at the same time as individual notices, meaning within 60 days of discovery, through the OCR breach portal.

Breaches affecting fewer than 500 individuals: keep a log and report to HHS no later than 60 days after the end of the calendar year in which the breaches were discovered.

Step five: Notify the media when required

If a breach involves more than 500 residents of a single state or jurisdiction, you must also notify prominent media outlets serving that area, within the same 60-day limit.

Business associates

A business associate must notify the covered entity following discovery of a breach, without unreasonable delay and no later than 60 days. Your business associate agreement can and often should require faster notice, so you have time to meet your own obligations. The covered entity's clock may start when the business associate is acting as its agent, so counsel should review the facts.

Law enforcement delay

If a law enforcement official states that notification would impede a criminal investigation, you may delay notification for the period specified, following the rule's procedures for written or oral statements.

State laws and other duties

Oklahoma, Texas and Arkansas each have their own breach notification statutes, which may have different timing, content or regulator-notice requirements. Your cyber insurer may also require prompt notice, and contracts with payers or partners may impose additional duties.

Practical preparation

Include breach assessment steps in your incident response plan

Pre-draft notification letter templates for counsel to review

Know where to find current contact information for residents and representatives

Keep a breach log, even for incidents judged not reportable

Rehearse the process in a tabletop exercise

UnityCare IT supports healthcare organizations with the technical investigation behind a breach assessment, including logs, scope and evidence preservation, and can help you prepare a response plan before you need one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172