HIPAA Breach Notification: Who Must Be Told, and When

When a laptop goes missing, a staff member emails the wrong resident's records or ransomware encrypts a server, the first question is often, do we have to report this? The HIPAA Breach Notification Rule answers it, and the answer depends on a structured assessment rather than a gut feeling.

This explainer outlines how the rule works. It is general information, not legal advice, and any real incident should involve your privacy officer and qualified counsel.

What Counts as a Breach

Under the rule, a breach is an acquisition, access, use or disclosure of protected health information in a way not permitted by the Privacy Rule that compromises the security or privacy of the information. Importantly, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate a low probability that the information has been compromised.

That presumption is why documentation matters so much.

The Four-Factor Risk Assessment

To show a low probability of compromise, a covered entity weighs at least four factors.

The nature and extent of the information involved, including the types of identifiers and the likelihood that someone could be identified

The unauthorized person who used the information or to whom it was disclosed. For example, another covered entity bound by HIPAA is lower risk than an unknown outsider.

Whether the information was actually acquired or viewed. A lost device later recovered with forensic evidence that files were never opened is different from one that vanished.

The extent to which the risk has been mitigated, such as obtaining assurances that the recipient destroyed the information

Record the assessment in writing, including who performed it, the facts reviewed and the conclusion.

The Encryption Safe Harbor

The rule applies to unsecured protected health information. Information that has been encrypted according to HHS guidance, or destroyed properly, is considered secured, and its loss generally does not trigger notification. This is a major reason to encrypt laptops, phones and backups.

Notification Requirements

If the assessment concludes a breach occurred, notification duties follow.

Individuals

Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered. Notice is typically by first-class mail, or by email if the person has agreed to electronic notice. The notice must describe what happened, the types of information involved, steps individuals should take, what the entity is doing, and how to contact it.

HHS

For breaches affecting 500 or more individuals, the covered entity must notify HHS at the same time as individuals. For breaches affecting fewer than 500, entities must log them and report to HHS within 60 days after the end of the calendar year in which the breach was discovered.

The Media

Breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media outlets in that area.

Business Associates

A business associate must notify the covered entity of a breach without unreasonable delay and within 60 days of discovery, though contracts often require much faster notice.

When the Clock Starts

The 60-day period begins when the breach is discovered, or would have been discovered by exercising reasonable diligence. Waiting to investigate does not stop the clock, and 60 days is an outer limit, not a target.

State Laws May Add Requirements

Oklahoma, Texas and Arkansas each have their own data breach notification laws that may apply alongside HIPAA, sometimes with different triggers or deadlines. Counsel can help sort out which apply.

Practical Steps to Prepare

Name a privacy officer and a security officer, and publish how staff should report suspected incidents

Train staff to report mistakes quickly without fear of blame

Keep a template for the four-factor assessment

Maintain a log of all incidents, including those judged not to be reportable

Encrypt devices and backups

Know your cyber insurance and legal contacts before you need them

Support From UnityCare IT

Our team can help gather the technical facts for a risk assessment, such as device encryption status and access logs, and help you build reporting procedures so your staff know exactly what to do.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172