HIPAA Breach Notification: Timelines and Who to Tell

A laptop is stolen from a car. A staff member emails a spreadsheet to the wrong person. A ransomware attack encrypts a file server. Each of these may be a breach of protected health information, and each triggers questions about what you must do, how quickly and for whom.

The HIPAA Breach Notification Rule answers many of those questions. This overview is intended for administrators and compliance leads and is general information, not legal advice. Always consult qualified counsel for a specific situation.

What Counts as a Breach?

Under the rule, a breach is generally an impermissible use or disclosure of protected health information that compromises its security or privacy. Importantly, such an event is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the information was compromised, based on a documented risk assessment.

There are also a few exceptions, such as certain unintentional access by a workforce member acting in good faith, or inadvertent disclosures between authorized people within the same organization, as long as the information is not further misused.

The Four-Factor Risk Assessment

To decide whether notification is required, evaluate at least these factors:

The nature and extent of the information involved, including how sensitive it is and the likelihood it could identify someone

The unauthorized person who used or received the information

Whether the information was actually acquired or viewed

The extent to which the risk has been mitigated, for example through assurances that data was destroyed

Document the analysis and your conclusion. If you cannot show a low probability of compromise, notification is generally required.

Unsecured vs. Secured Information

The notification requirement applies to unsecured protected health information, meaning information that has not been rendered unusable, unreadable or indecipherable to unauthorized people. Properly encrypted data, or data that has been destroyed according to federal guidance, generally falls outside the notification requirement. This is one strong reason to encrypt laptops, tablets and backups.

Who Must Be Notified and When

Affected Individuals

Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. A breach is treated as discovered on the first day it is known, or would reasonably have been known with reasonable diligence. Notices are generally sent by first-class mail, or by email if the individual has agreed to electronic notice. The notice should include, in plain language:

What happened, including the dates of the breach and discovery

The types of information involved

Steps individuals should take to protect themselves

What the organization is doing to investigate and prevent recurrence

Contact information for questions

Sending notices to a resident's personal representative or next of kin may be necessary in a care setting.

The Department of Health and Human Services

Breaches affecting 500 or more individuals: notify HHS without unreasonable delay and no later than 60 days after discovery.

Breaches affecting fewer than 500 individuals: log them and submit the information to HHS annually, within 60 days after the end of the calendar year in which the breaches were discovered.

The Media

For breaches involving more than 500 residents of a state or jurisdiction, covered entities must also notify prominent media outlets serving that area, within the same 60-day outer limit.

Business Associates

A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days. Your contract may require sooner notice, which is why breach reporting terms in your agreements matter.

State Laws and Other Obligations

HIPAA is not the only rule. Oklahoma, Texas and Arkansas each have their own breach notification laws with their own requirements, and some involve notifying a state attorney general. Contracts with payers, insurers and corporate partners may add more. Your cyber insurance policy may require immediate notice to the carrier. Legal counsel can help sort through the overlapping rules.

Practical Steps

Write a breach response procedure and name the people responsible

Train staff to report incidents immediately, since the clock can start when anyone in the organization knows

Keep a breach log and documentation for six years

Keep template notification letters ready for review by counsel

Know how to quickly identify affected residents

Prevention Is Easier

Most breach notifications start with preventable events. UnityCare IT can help you strengthen safeguards such as encryption and access controls, and can support investigation and documentation when something goes wrong.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172