HIPAA Breach Notification: Deadlines and Decisions Explained

No organization wants to think about a breach, but every covered entity should understand how the HIPAA Breach Notification Rule works before one happens. Deadlines begin to run quickly, decisions must be documented, and the people making them are often under stress. Knowing the framework in advance makes those decisions clearer.

This article gives a plain-English overview. It is not legal advice, and you should involve your compliance officer or counsel in any actual incident.

What Counts as a Breach

Under HIPAA, a breach is generally an impermissible use or disclosure of protected health information that compromises its security or privacy. The rule presumes an impermissible use or disclosure is a breach unless the covered entity demonstrates, through a documented risk assessment, that there is a low probability the information has been compromised.

The rule also contains exceptions, such as certain unintentional access by workforce members acting in good faith within the scope of their authority, or certain inadvertent disclosures between authorized people at the same organization, where information is not further misused.

Unsecured Versus Secured PHI

The notification requirements apply to unsecured PHI. HHS guidance describes PHI as secured when it has been rendered unusable, unreadable or indecipherable to unauthorized people, through encryption or destruction consistent with its guidance. If properly encrypted data is lost and the key is not compromised, notification generally is not required. This is one of the strongest practical reasons to encrypt devices and backups.

The Four-Factor Risk Assessment

When you cannot rule out a breach, you assess the probability that PHI has been compromised by considering at least these factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or to whom the disclosure was made

Whether the PHI was actually acquired or viewed

The extent to which the risk to the PHI has been mitigated

Document the analysis and the conclusion, whichever way it goes.

Who Must Be Notified

If a breach of unsecured PHI occurred, notification generally goes to:

Affected individuals, or their personal representatives, in writing

The Secretary of HHS, through the Office for Civil Rights breach reporting process

The media, when a breach affects more than 500 residents of a state or jurisdiction

Business associates must notify the covered entity of breaches they discover.

Timelines

Notice to individuals must be provided without unreasonable delay and no later than 60 calendar days after discovery of the breach. A breach is treated as discovered on the first day it is known, or reasonably should have been known, to the organization. That detail matters: the clock does not start when the investigation ends.

For breaches affecting 500 or more individuals, HHS must be notified at the same time as individuals, and media notice follows the same timeline. For breaches affecting fewer than 500, covered entities may log them and report to HHS within 60 days after the end of the calendar year in which they were discovered.

Sixty days is an outer limit. Delay without good reason can itself create problems.

What the Notice Must Contain

Individual notices are written in plain language and generally include:

A brief description of what happened, including the date of the breach and date of discovery, if known

The types of information involved

Steps individuals should take to protect themselves

What the organization is doing to investigate, mitigate harm and prevent recurrence

Contact procedures, including a toll-free number, email, website or postal address

Do Not Forget State Law and Contracts

Oklahoma, Texas and Arkansas each have breach notification statutes that may impose additional or different requirements, such as notice to the state attorney general or shorter timelines. Your contracts and cyber insurance policy may also require prompt notice. Counsel can help reconcile them.

Prepare Ahead

Keep a written breach response procedure naming who decides and who communicates

Maintain a template for the four-factor assessment

Keep a breach log, including incidents you determined were not reportable

Train staff to report suspected incidents immediately

Know your insurance carrier's notification requirements

Retain documentation for six years

How UnityCare IT Can Help

UnityCare IT helps healthcare organizations with the technical side of incidents: investigating what happened, preserving evidence and identifying which systems and data were affected. We work alongside your compliance officer and counsel, who make the legal determinations.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172