HIPAA Breach Notification: Deadlines and Steps Explained

Few moments test a care organization like discovering that resident information may have been exposed. A misdirected fax, a stolen laptop, a compromised email account or a ransomware attack all raise the same question: what are we required to do, and how quickly? The HIPAA Breach Notification Rule answers that question, but the details are easy to forget under pressure.

This post gives a plain-English overview. It is educational, not legal advice, and any real incident should involve your compliance officer and legal counsel.

What counts as a breach

Under the rule, a breach is an impermissible use or disclosure of unsecured protected health information that compromises its security or privacy. Unsecured generally means not encrypted or destroyed in a way that meets HHS guidance.

Not every incident is reportable. The rule starts from a presumption that an impermissible use or disclosure is a breach unless you can demonstrate a low probability that the information was compromised. There are also limited exceptions, such as certain unintentional, good-faith access by a workforce member acting within their authority.

The four-factor risk assessment

To decide whether there is a low probability of compromise, you must assess at least these factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.

The unauthorized person who used the information or to whom it was disclosed.

Whether the PHI was actually acquired or viewed.

The extent to which the risk has been mitigated.

Document your analysis carefully. If you cannot show a low probability of compromise, you must treat the incident as a reportable breach.

Who must be notified and when

Affected individuals

You must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovering the breach. The 60 days is an outer limit, not a goal. A breach is treated as discovered on the first day it is known, or would reasonably have been known, to the organization.

Notice is generally sent by first-class mail, or by email if the individual has agreed to electronic notice. It must be written in plain language and typically includes:

A description of what happened and the date of the breach and discovery, if known.

The types of information involved.

Steps individuals should take to protect themselves.

What the organization is doing to investigate, reduce harm and prevent a recurrence.

Contact information for questions.

The Secretary of HHS

Breaches affecting 500 or more individuals must be reported to HHS contemporaneously with individual notice, and no later than 60 days after discovery. Breaches affecting fewer than 500 individuals may be logged and reported to HHS within 60 days after the end of the calendar year in which they were discovered.

The media

For breaches involving more than 500 residents of a state or jurisdiction, covered entities must also notify prominent media outlets serving that area, within the same 60-day limit.

State requirements

Many states have their own breach notification laws with different definitions and timelines. Oklahoma, Texas and Arkansas each have statutes that may apply in addition to HIPAA, so your counsel should review both.

Business associates

If a vendor discovers a breach involving your PHI, it must notify you, and your business associate agreement should set a faster timeline for doing so. Your own 60-day clock may begin when the business associate's discovery is imputed to you, so quick communication is essential.

Practical steps when an incident occurs

Contain it: stop the exposure, disable accounts, retrieve the misdirected materials.

Start a written log with dates, times and actions.

Notify your privacy officer, administrator, IT provider and, if applicable, your insurer.

Preserve evidence, such as logs and affected devices.

Complete the risk assessment and record your conclusion.

Decide on notifications and prepare letters and reports.

Fix the root cause and update your risk analysis and training.

Keep records

HIPAA requires you to retain breach documentation for six years, including your risk assessments, even when you determine no notification is required.

Prepare in advance

Having templates for notification letters, a contact list and a short incident checklist saves time. Practice a scenario with leadership so roles are clear.

How UnityCare IT can help

UnityCare IT helps healthcare and senior-living organizations investigate incidents, preserve technical evidence and document findings that feed breach decisions. If you would like to build an incident checklist before you need it, we can help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034