The HIPAA Breach Notification Rule: Who to Tell and When

A misdirected fax, a stolen laptop, a phishing email that exposed a mailbox, a ransomware attack. Any of these might be a breach under HIPAA, and each can start a clock for notifications. Knowing the basics before an incident helps leaders make calm, correct decisions. This article is a general explainer, not legal advice. Involve your attorney or compliance officer for real incidents.

What Counts as a Breach?

Under the HIPAA Breach Notification Rule, a breach is generally an impermissible use or disclosure of unsecured protected health information that compromises its security or privacy. The rule presumes that an impermissible use or disclosure is a breach unless you can demonstrate a low probability that the PHI has been compromised, based on a documented risk assessment.

"Unsecured PHI" generally means information that has not been rendered unusable, unreadable or indecipherable to unauthorized people through methods specified by HHS, such as proper encryption or destruction. This is a major reason encryption of laptops, phones and backups matters: if a properly encrypted device is lost, the incident may not be a reportable breach.

The Four-Factor Risk Assessment

To decide whether there is a low probability of compromise, consider at least these factors:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification

The unauthorized person who used the PHI or to whom it was disclosed. A disclosure to another covered entity bound by HIPAA is different from one to an unknown party.

Whether the PHI was actually acquired or viewed

The extent to which the risk has been mitigated, such as obtaining satisfactory assurance that the recipient destroyed the information

Document the analysis and the conclusion, whether or not you decide notification is required.

There are also limited exceptions, such as certain unintentional good-faith access by workforce members acting within their authority, and certain inadvertent disclosures between authorized people at the same organization, that do not constitute breaches if conditions are met.

Who Must Be Notified?

1. Affected individuals

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. Notice is usually by first-class mail, or by email if the individual has agreed to electronic notice. It must be written in plain language and include a description of what happened, the types of information involved, steps individuals should take, what the entity is doing, and contact information. If contact information is out of date for 10 or more people, substitute notice such as a website posting or media notice may be required.

The 60 days is an outer limit. Waiting until day 59 when you knew the facts on day 10 is not compliant.

2. HHS

Breaches affecting 500 or more individuals: notify HHS at the same time as individual notice, within the 60-day window. HHS posts these on its public breach portal.

Breaches affecting fewer than 500: keep a log and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.

3. The media

For breaches involving more than 500 residents of a state or jurisdiction, covered entities must notify prominent media outlets serving that area, also within 60 days.

4. Law enforcement may request a delay

If a law enforcement official states that notification would impede an investigation or damage national security, the timing can be delayed as the rule provides.

Business Associates

If the incident happens at a vendor, the business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery, and your contract may require faster. The covered entity generally remains responsible for notifying individuals, though the parties can delegate tasks by agreement. This is why your BAAs should specify timelines.

State Law and Other Obligations

Oklahoma, Texas, Arkansas and other states have their own breach notification laws and may require notice to state attorneys general or other regulators, sometimes with different deadlines or definitions. Insurance policies often require prompt notice to the carrier. Review these with counsel.

What to Do in the First Days

Contain the incident and preserve evidence.

Record the date and time of discovery, since that starts the clock.

Notify your privacy officer, leadership, counsel and insurer.

Determine what information and which individuals are affected.

Complete and document the risk assessment.

Prepare notification letters and a call-center or contact plan.

Keep a log of all steps taken.

Prevention Is Cheaper

Encryption, access controls, training and good backups reduce both the likelihood of incidents and the chance that they become reportable.

How UnityCare IT Helps

UnityCare IT supports healthcare clients with the technical side of incident response, including determining what systems and data were affected, and with safeguards that lower breach risk. For legal determinations, consult your counsel.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034