HIPAA Breach Notification Timelines Explained for Providers

No organization plans to have a breach, but every organization that handles protected health information should know what the rules require if one occurs. The HIPAA Breach Notification Rule sets out who must be told, how and by when. Understanding the timelines in advance can prevent mistakes made under pressure.

This article provides a general explanation and is not legal advice. Consult counsel for decisions about a specific incident, and remember that state laws and contracts may impose additional requirements.

What counts as a breach

Under HIPAA, a breach is generally an impermissible use or disclosure of PHI that compromises its security or privacy. The rule presumes that such an event is a breach unless the covered entity can demonstrate a low probability that the PHI has been compromised, based on a documented risk assessment.

Examples include a lost unencrypted laptop, a ransomware attack, an email sent to the wrong person, an employee looking at records without a work reason and a vendor incident that exposes your residents' information.

The four-factor risk assessment

The rule lists factors that must be considered when deciding whether there is a low probability of compromise:

The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.

The unauthorized person who used the PHI or to whom the disclosure was made.

Whether the PHI was actually acquired or viewed.

The extent to which the risk has been mitigated.

Document the assessment and the conclusion. If you cannot show a low probability of compromise, treat the event as a reportable breach.

There is a safe harbor for PHI that was properly encrypted according to HHS guidance, since it is considered unsecured only when it is not encrypted or destroyed in the approved ways.

Notice to individuals

Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The 60 days is an outer limit, not a target, and waiting until day 59 without a good reason can itself be a violation.

A breach is treated as discovered on the first day it is known, or would reasonably have been known, to the organization or to any workforce member or agent other than the person committing it. This means the clock can start when a staff member notices, not only when leadership is informed. Train staff to report immediately.

Notice must generally be sent by first-class mail, or by email if the individual has agreed to electronic notice. It should be written in plain language and include a description of what happened, the types of information involved, steps individuals should take, what the organization is doing and contact information.

Notice to HHS

500 or more individuals: notify HHS at the same time as individual notice, within the 60-day limit.

Fewer than 500 individuals: you may keep a log and report to HHS within 60 days after the end of the calendar year in which the breaches were discovered.

Notice to the media

If a breach affects more than 500 residents of a single state or jurisdiction, the covered entity must also notify prominent media outlets serving that area, within the same 60-day limit.

Business associates

A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days. Your agreement may require a much shorter period, which is why contract terms matter. The covered entity generally remains responsible for notifying individuals unless the agreement delegates that task.

Law enforcement delay

If a law enforcement official states that notice would impede a criminal investigation, the notification may be delayed for the period specified.

State laws

Oklahoma, Texas and Arkansas each have their own breach notification statutes, and they may have different triggers, deadlines and requirements to notify state officials. Ask counsel to review them.

Be ready

Keep an incident response plan and contact list.

Maintain a breach log and documentation of assessments.

Practice the process in a tabletop exercise.

Make sure vendors know how to reach you.

How UnityCare IT can help

UnityCare IT supports incident response and the technical investigation that informs breach assessments. If you want to put a plan and contact list in place before you need one, we can help.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034