HIPAA Breach Notification Deadlines: A Step-by-Step Timeline

Few things are more stressful for an administrator than discovering that protected health information may have been exposed. A laptop is missing. A fax went to the wrong number. An employee looked at records they had no reason to see. Within hours, questions arise: is this a reportable breach, who do we tell, and how long do we have?

The HIPAA Breach Notification Rule gives clear answers, though the details matter. This is general information, not legal advice, and you should involve counsel and your compliance officer for any real incident.

What counts as a breach

Under the rule, a breach is the acquisition, access, use or disclosure of unsecured protected health information in a manner not permitted by the Privacy Rule that compromises its security or privacy. Unsecured means not encrypted or destroyed according to HHS guidance.

Any such impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the information was compromised, based on a documented risk assessment.

The four-factor risk assessment

To rebut the presumption, evaluate at least:

The nature and extent of the information involved, including identifiers and how likely it is to identify people.

The unauthorized person who used the information or to whom it was disclosed.

Whether the information was actually acquired or viewed.

The extent to which the risk has been mitigated, for example through a signed assurance that the recipient destroyed the data.

Document your reasoning. If you cannot show a low probability of compromise, treat it as a reportable breach.

The timeline

Day 0: Discovery

A breach is treated as discovered on the first day it is known to your organization, or would have been known with reasonable diligence. Any workforce member, other than the person who committed the breach, knowing about it can start the clock, so staff must know to report immediately.

Days 0 to 3: Contain and investigate

Stop the exposure, whether that means recovering a document, disabling an account or locking a device.

Notify your privacy officer and security officer.

Preserve evidence and begin documenting.

Call your insurer if cyber coverage may apply, since policies often have prompt-notice conditions.

Within 60 days: Notify affected individuals

You must notify each affected individual without unreasonable delay, and no later than 60 calendar days after discovery. The 60 days is an outer limit, not a target. Notice is generally sent by first-class mail, or by email if the individual agreed to electronic notice, and must include:

A description of what happened and when, including the date of discovery.

The types of information involved.

Steps individuals should take to protect themselves.

What you are doing to investigate, mitigate harm and prevent a recurrence.

Contact information for questions.

Where contact information is out of date for ten or more people, substitute notice through a website posting or major media may be required.

Media notice for larger breaches

If a breach affects more than 500 residents of a state or jurisdiction, you must also notify prominent media outlets in that area within the same 60-day limit.

Notice to HHS

500 or more individuals: notify the HHS Secretary at the same time as individual notice, without unreasonable delay and within 60 days, through the OCR breach portal.

Fewer than 500: log the breach and report to HHS within 60 days after the end of the calendar year in which it was discovered.

Business associate breaches

If a vendor is breached, they must notify you without unreasonable delay and within 60 days of discovery, though your contract may require sooner. The clock for your obligations can depend on whether the vendor acts as your agent, so ask counsel and read the agreement.

Do not forget state law

Many states, including Oklahoma, Texas and Arkansas, have their own breach notification statutes with different definitions, deadlines and attorney general reporting requirements. A breach may trigger both federal and state obligations, and the shorter deadline governs in practice.

Law enforcement delay

If law enforcement states that notification would impede a criminal investigation, you may delay as directed. Document the request.

Prepare in advance

Write a breach response procedure naming who decides, who drafts notices and who calls counsel.

Train staff to report suspected incidents immediately.

Keep a breach log with risk assessments, even for incidents you decide are not reportable.

Encrypt laptops, phones and backups. Properly encrypted data is generally exempt from notification.

Where we fit

UnityCare IT helps with the technical side of incidents, including scoping what was accessed, preserving logs and strengthening controls afterward. If your breach procedure is not written yet, we can help you build one before you need it.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172