A misdirected billing file goes to the wrong clearinghouse. Your practice manager counts the rows: 612 unique patients. That number just changed everything about your next 60 days. Cross the 500 record breach threshold and you owe HHS a filing within 60 calendar days of discovery, a media notification in some cases, and a permanent listing on OCR's public breach portal. Stay under it and you log the incident and file it by March 1 of the following year.

This article is for the person who has to make that call — the privacy officer, practice owner, or compliance lead. It covers how to count, which clock starts when, and what evidence you keep.

What Is the 500 Record Breach Threshold Under HIPAA?

The 500 record breach threshold is the dividing line in the HIPAA Breach Notification Rule (45 CFR 164.400–414) that determines when you report a breach of unsecured protected health information to the Secretary of HHS.

  • 500 or more individuals affected: Notify HHS without unreasonable delay and no later than 60 calendar days after discovery, contemporaneously with individual notices. The breach is posted to OCR's public portal.
  • Fewer than 500 individuals affected: Log the breach and submit it to HHS no later than 60 days after the end of the calendar year in which it was discovered.
  • Individual notice is unchanged either way: Affected patients get written notice within 60 days of discovery, regardless of headcount.

The threshold changes the reporting deadline and the publicity. It does not change your duty to notify patients, investigate, mitigate, or document.

The Threshold Counts People, Not Records

The phrase "500 record breach threshold" is how most administrators say it, but the regulation counts individuals. One patient with 40 encounter notes, three imaging studies, and a decade of claims is one person for threshold purposes.

This cuts both ways. A stolen laptop holding 12,000 documents that belong to 380 patients is a sub-500 breach. A single spreadsheet with one row per patient and 503 rows is a 500-plus breach with a public listing.

So the first operational task after any suspected breach is de-duplication. Have someone pull unique patient identifiers — MRN, not row count, not file count, not message count. Document how you de-duplicated. If your number lands between 450 and 550, expect OCR to ask how you arrived at it.

Separate Incidents Do Not Aggregate

Three unrelated incidents of 200 patients each across a year are three sub-500 breaches. They do not combine into a 600-patient reportable event. But if your investigation reveals that a single unauthorized access session touched 200 charts on Monday and 400 on Thursday through the same compromised credential, that is one incident affecting 600 individuals. The distinguishing question is whether the incidents share a root cause and a timeframe.

Two Clocks: 60 Days From Discovery vs. March 1

For breaches discovered in calendar year 2025 that affected fewer than 500 individuals, your submission deadline is March 1, 2026 — 60 days after December 31, 2025. Each breach is submitted as a separate entry through the same OCR breach portal form. There is no consolidated upload.

If you are reading this on December 30, 2025, you have roughly nine weeks to reconcile your incident log against what you are actually going to file. Pull the log now. Every incident you classified as a breach in 2025 needs a portal entry.

When "Discovery" Starts the Clock

A breach is treated as discovered on the first day it is known to your organization — or the first day it would have been known through the exercise of reasonable diligence — by any workforce member or agent other than the person who committed the breach.

That definition matters more than most practices realize. If a front-desk employee noticed a stack of misprinted statements on October 3 and told nobody until November 20, your clock arguably started October 3. "Reasonable diligence" also means that if your access logs would have flagged anomalous record views had anyone reviewed them, OCR may treat the date the logs were generated as the discovery date.

Practical control: put a standing item on your monthly compliance meeting agenda to review access-log alerts, and document that the review happened. Signed, dated review records are the cheapest defense against a constructive-discovery argument.

The Media Notice Trap: "500 or More" vs. "More Than 500"

These are two different thresholds and people conflate them constantly.

  • HHS notice: triggered at 500 or more individuals, counted across the entire breach.
  • Media notice: triggered when more than 500 residents of a single State or jurisdiction are affected. You notify prominent media outlets serving that State or jurisdiction, within the same 60-day window.

So a breach affecting exactly 500 people in one state requires HHS notice and no media notice. A breach affecting 501 people in one state requires both.

A Worked Example: 640 Patients, Two States, One Laptop

An unencrypted laptop is stolen from a clinician's car on February 10. Forensics confirms it held a local export covering 640 unique patients: 400 with Ohio addresses, 240 with Kentucky addresses.

  • HHS filing: Required. 640 ≥ 500. Due no later than April 11 (60 days from discovery), submitted contemporaneously with patient notices.
  • Individual notices: Required for all 640, by first-class mail to last known address, due by the same date.
  • Media notice: Not required. Neither state exceeds 500 residents.
  • Portal listing: Yes. The incident appears publicly with your entity name, state, covered entity type, individuals affected, and breach type.

Change the mix to 520 Ohio and 120 Kentucky and you now add media notification in Ohio. Same total, different obligation. Always break your affected-individual count down by state before you decide.

Who Does What in the First 72 Hours

Assign these roles in your incident response policy by name and title, not by committee.

  1. Hour 0–4 — Containment (IT lead or managed service provider). Disable credentials, revoke the share link, recall the message, isolate the device. Preserve logs before anything is wiped.
  2. Hour 0–8 — Notification to the privacy officer (any workforce member). Your workforce needs one phone number and one email address for this. Train it annually and post it.
  3. Hour 4–48 — Scoping (privacy officer + IT). Produce the de-duplicated unique-patient count and the state-by-state breakdown. This is the number that decides your threshold.
  4. Hour 24–72 — Four-factor risk assessment (privacy officer). Document nature and extent of the PHI, who received or accessed it, whether it was actually acquired or viewed, and the extent of mitigation. Unauthorized acquisition, access, use, or disclosure is presumed to be a breach unless you demonstrate a low probability of compromise.
  5. Day 3–10 — Decision and drafting (privacy officer + counsel). Breach or no breach. If breach, draft notices, prepare the portal submission, check state attorney general and state-specific deadlines, which are often shorter than 60 days.
  6. Day 10–60 — Execution (practice administrator). Mail notices, stand up the toll-free line if substitute notice applies, file with HHS, notify media if the state threshold is exceeded.

If you cannot produce this sequence on paper today, your incident response plan is not operational. Practices that build the plan and the supporting policy set from scratch usually stall on the documentation layer — you can generate a risk analysis report and the full HIPAA policy set, including breach notification procedures, and then adapt the role assignments to your actual staff.

Substitute Notice: The 10-Person Rule

If you have insufficient or out-of-date contact information for 10 or more affected individuals, you must provide substitute notice: a conspicuous posting on the home page of your website for 90 days, or notice in major print or broadcast media in the geographic areas where affected individuals likely reside — plus a toll-free number active for at least 90 days.

For fewer than 10 individuals with bad contact information, substitute notice can be by an alternative written form, telephone, or other means.

Budget for this. A 90-day toll-free line staffed to answer questions is a real cost, and it applies to sub-500 breaches too.

Business Associates and the Threshold You Don't Control

Most 500-plus breaches in a small practice originate with a vendor, not the front desk. Your business associate must notify you without unreasonable delay and no later than 60 days after its discovery. If that vendor burns 55 days before telling you, you have five days left on the same 60-day clock — unless the vendor is your agent under federal common law of agency, in which case its discovery is imputed to you from day one.

Fix this contractually. Your BAA should require notification to you within a defined short window — 5 to 10 calendar days is common — and require the vendor to deliver the de-duplicated affected-individual count with a state breakdown. If your agreements are inherited templates that only restate the regulatory minimum, replace them; a signature-ready Business Associate Agreement built through a guided wizard is faster than redlining a decade-old PDF.

Also settle in writing who files. The covered entity is ultimately responsible for the HHS submission and patient notices, but a large vendor may offer to send them on your behalf. Either arrangement works; ambiguity does not.

What Never Reaches the Threshold

Three exceptions and one safe harbor keep incidents off your log entirely.

The encryption safe harbor. The rule applies only to unsecured PHI. PHI encrypted consistent with HHS guidance — which points to NIST-validated methods — or destroyed per that guidance is not unsecured, and its loss is not a reportable breach. A stolen laptop with full-disk encryption and a key that was not compromised produces no notification obligation. Review the HHS guidance on securing protected health information and confirm your device encryption actually meets it.

The three regulatory exceptions. Unintentional acquisition or use by a workforce member acting in good faith within the scope of authority; inadvertent disclosure between two people authorized to access PHI at the same entity or organized health care arrangement; and disclosure where you have a good faith belief the unauthorized recipient could not reasonably have retained the information. Each still requires documentation showing why the exception applies.

The Evidence File OCR Expects

Whether you cross the 500 record breach threshold or not, keep these for six years from creation:

  • Incident intake record with discovery date and the name of the person who discovered it
  • The de-duplicated affected-individual count with methodology and state breakdown
  • The written four-factor risk assessment and the breach/no-breach conclusion
  • Copies of the individual notice template and a mailing list or mail-house confirmation
  • Screenshot or confirmation number from the HHS portal submission
  • Media notice copy and outlet list, if applicable
  • Mitigation and corrective action steps, with completion dates and owners
  • Sanction record if a workforce member's conduct contributed

Look at the OCR breach portal before you file. Reading how comparable practices described their incidents will sharpen your own submission narrative, and it is a useful reality check for leadership on what public listing actually looks like. The Breach Notification Rule text and HHS instructions govern the form fields.

One more thing to check this week: your state. Many states impose attorney general notification at counts far below 500, sometimes within 30 days. HIPAA sets a floor, not a ceiling.

Start With the Documents That Make the Decision Defensible

The practices that handle a 500-plus breach cleanly are not the ones with the best luck. They are the ones that already had a current risk analysis, a written incident response procedure with named owners, and BAAs that force vendors to report fast.

If your risk analysis predates your last EHR migration or your policy binder has never been updated, build the current set now — automated HIPAA risk analysis reports, policies, and the supporting document set get you to a defensible baseline in an afternoon rather than a quarter. Then run one tabletop exercise against the 640-patient laptop scenario above and see where your process breaks.