When a security incident involves protected health information, administrators quickly face a set of questions with deadlines attached. Was it a reportable breach? Who needs to be told? How long do we have? The HIPAA Breach Notification Rule provides the framework, though state laws, contracts and insurance policies can add their own requirements. This article summarizes the federal timelines in plain language. It is general information, not legal advice, so involve your counsel and compliance officer in real decisions.
Under the rule, a breach is an impermissible use or disclosure of unsecured PHI that compromises the security or privacy of the information. An impermissible use or disclosure is presumed to be a breach unless the covered entity demonstrates a low probability that the PHI has been compromised, based on a documented risk assessment.
Unsecured PHI means information that has not been rendered unusable, unreadable or indecipherable to unauthorized persons through methods specified by HHS, such as proper encryption. Lost encrypted devices often do not trigger notification for this reason.
There are also limited exceptions, such as unintentional access by a workforce member acting in good faith within the scope of their authority, certain inadvertent disclosures between authorized persons, and situations where the recipient could not reasonably have retained the information.
To decide whether there is a low probability of compromise, the rule requires considering at least these factors.
The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
The unauthorized person who used the PHI or to whom it was disclosed
Whether the PHI was actually acquired or viewed
The extent to which the risk has been mitigated
Document this assessment carefully, whatever the conclusion.
A breach is treated as discovered on the first day it is known to the covered entity, or by exercising reasonable diligence would have been known. Knowledge of any workforce member or agent, other than the person who committed the breach, is generally attributed to the organization. This is why prompt internal reporting matters. Delay in escalating an incident can shorten the time you have.
Deadline: without unreasonable delay and no later than 60 calendar days after discovery. The 60 days is an outer limit, not a target. If you have the information needed earlier, you should not wait.
Method: written notice by first-class mail to the last known address, or by email if the individual has agreed to electronic notice. Special rules apply for urgent situations, outdated contact information and deceased individuals, including next of kin or personal representatives.
Content: a brief description of what happened, including dates of the breach and discovery; the types of information involved; steps individuals should take to protect themselves; what the organization is doing to investigate, mitigate harm and prevent recurrence; and contact procedures, which must include a toll-free number, email address, website or postal address.
Substitute notice: if contact information is insufficient for ten or more individuals, a conspicuous website posting for 90 days or notice in major media, with a toll-free number. For fewer than ten, alternative written, telephone or other means can be used.
500 or more individuals: notify the HHS Secretary at the same time as individual notice, without unreasonable delay and within 60 days of discovery, through the HHS breach reporting portal.
Fewer than 500 individuals: maintain a log and report to HHS no later than 60 days after the end of the calendar year in which the breaches were discovered.
HHS makes breaches affecting 500 or more individuals publicly visible.
If a breach involves more than 500 residents of a single state or jurisdiction, the covered entity must also notify prominent media outlets serving that area, within the same 60-day outer limit. This is typically done through a press release.
If a business associate discovers a breach, it must notify the covered entity without unreasonable delay and no later than 60 days after discovery. Contracts often require much faster notice, which is why your business associate agreements should specify short reporting windows. The covered entity then handles the notifications to individuals and regulators unless the agreement delegates it.
Maintain an incident response plan with named roles and contact details
Create template notification letters reviewed by counsel
Keep a breach log
Train staff to report suspected incidents immediately
Know where the HHS portal is and who is authorized to use it
UnityCare IT helps healthcare organizations with the technical side of incident response, including determining which systems and records were affected, preserving evidence and restoring operations. If you do not yet have a documented incident response plan, we can help you draft one that works alongside your compliance program.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172