HIPAA Breach Notification Rule: Deadlines and Evidence
You have until March 1, 2026 to file every breach you discovered in 2025 that affected fewer than 500 people. That deadline is 60 days after the close of the calendar year, and it is one of the few dates in the HIPAA breach notification rule that does not move for anyone. If your practice logged a misdirected fax in February, a lost thumb drive in June, and a portal message sent to the wrong patient in October, each of those is a separate submission to the HHS breach portal — and if you have not been keeping a running log, you are about to reconstruct ten months of incidents from memory.
This article is for the person who owns that log. It covers what triggers the rule, who must notify whom, how fast, and what the file looks like when OCR asks to see it.
What the HIPAA Breach Notification Rule Requires, in Plain Terms
The HIPAA breach notification rule (45 CFR §§ 164.400–414) requires covered entities to notify affected individuals, HHS, and — in larger incidents — the media, after an impermissible use or disclosure of unsecured protected health information. Business associates must notify the covered entity.
The core deadlines:
- Individuals: without unreasonable delay, no later than 60 calendar days from discovery.
- HHS, breaches affecting 500 or more: contemporaneously with individual notice, no later than 60 days from discovery.
- HHS, breaches affecting fewer than 500: annually, no later than 60 days after the end of the calendar year in which the breach was discovered.
- Media, 500+ residents of a single state or jurisdiction: prominent media outlets serving that area, no later than 60 days from discovery.
- Business associate to covered entity: no later than 60 days from discovery, unless your BAA sets a shorter window.
An impermissible use or disclosure is presumed to be a breach. You carry the burden of proving otherwise through a documented four-factor risk assessment, or by showing the PHI was secured under HHS encryption and destruction guidance.
"Discovery" Starts Earlier Than Most Practices Think
The clock starts on the first day the breach is known — or reasonably should have been known — to any workforce member other than the person who caused it. Not the day it reaches your desk. Not the day your attorney finishes reviewing.
That distinction has real consequences. If a medical assistant notices on November 3 that a discharge packet went to the wrong address and mentions it to a supervisor, your 60 days began November 3, even if the incident report reached the privacy officer on November 20. You just spent 17 of your 60 days on internal routing.
Two operational fixes address this. First, define discovery in your incident response policy and train every workforce member that any suspected impermissible disclosure goes to the privacy officer the same business day. Second, timestamp intake. Your incident log needs a "date first known to workforce" field separate from "date reported to privacy officer," because OCR will ask about the gap.
The Law Enforcement Delay Is Narrow
Under § 164.412, if a law enforcement official states that notification would impede a criminal investigation, you may delay. A written statement specifying a time period lets you delay for that period. An oral statement buys you 30 days, and you must document the officer's identity. Anything beyond that requires the written version. Do not treat a detective's verbal "hold off for now" as an open-ended extension.
The Four-Factor Risk Assessment That Decides Whether You Notify
You may skip notification only if you determine there is a low probability that the PHI has been compromised. That determination requires all four factors in § 164.402, documented in writing:
- The nature and extent of the PHI involved, including types of identifiers and the likelihood of re-identification. A first name and appointment date is not the same as a name, SSN, and diagnosis code.
- The unauthorized person who used the PHI or to whom the disclosure was made. Another HIPAA-covered provider bound by the same obligations weighs differently than an unknown recipient of a misdirected email.
- Whether the PHI was actually acquired or viewed. Forensic evidence matters here. A laptop recovered with an unbroken chain of custody and no evidence of file access supports a lower probability than one that vanished.
- The extent to which the risk has been mitigated. A written, signed attestation of destruction from the recipient is mitigation. A phone call where someone said they threw it away is weaker.
Write the assessment as a short memo — one page is often enough — with the incident facts, each factor addressed by name, the conclusion, and the signature and date of whoever made the call. A conclusion without the four factors walked through individually is the single most common documentation failure I see in practices that self-report.
Three Situations That Are Not Breaches
The rule carves out three exceptions, and you should know them cold because they resolve a meaningful share of front-desk incidents:
- Unintentional acquisition or access by a workforce member acting in good faith within the scope of authority, with no further impermissible use. A biller opens the wrong chart, closes it, reports it.
- Inadvertent disclosure between authorized persons at the same covered entity, business associate, or organized health care arrangement, again with no further impermissible use.
- Good-faith belief the recipient could not reasonably have retained the information. A patient hands back a summary sheet after a glance at the wrong name.
Each exception still requires a documented determination. "Not a breach, exception 1" in your log, with two sentences of facts, is enough — and it is far better than an unexplained blank.
What Goes in the Notice, and How You Send It
Individual notices must be written in plain language and contain five elements: a brief description of what happened including dates, the types of PHI involved, the steps individuals should take to protect themselves, what your practice is doing to investigate and mitigate, and contact procedures including a toll-free number, email, website, or postal address.
Delivery is first-class mail to the last known address, or email if the individual has agreed to electronic notice. If you have insufficient or out-of-date contact information for 10 or more individuals, you must provide substitute notice: a conspicuous posting on your website home page for 90 days, or notice in major print or broadcast media serving the area, plus a toll-free number active for at least 90 days. For fewer than 10, an alternative form — telephone, written, or other means — is acceptable.
The HHS Breach Notification Rule guidance page lays out the full requirements and links directly to the submission form. Bookmark it in your incident response binder.
A Worked Timeline: 340 Records, Discovered on a Tuesday
Your billing manager opens a vendor email on Tuesday, January 13 reporting that a subcontractor's misconfigured storage bucket exposed a claims file containing 340 patient names, dates of service, and CPT codes. Here is how the calendar runs.
- Day 0 (Jan 13): Discovery. Log it. Open the incident file. Preserve the vendor's email and any logs they will share.
- Days 1–5: Scope confirmation. Get the exact patient list from the business associate. Confirm whether the data was encrypted at rest in a manner consistent with HHS guidance — if it was, and the keys were not exposed, this may not be an unsecured PHI breach at all.
- Days 5–14: Four-factor assessment, written and signed. Request access logs showing whether the bucket was actually crawled or downloaded.
- Days 14–25: Draft notice letters, verify addresses against your patient management system, stand up the toll-free line if substitute notice will be needed.
- By Day 45: Letters mailed. Do not run to Day 60 — mail delays and address returns eat the margin.
- By March 1 of the following year: Because 340 is under 500, this goes on the annual HHS filing, not an immediate one. But you still notified individuals within 60 days.
- Six years: Retain the entire file — assessment, letter template, mailing list, vendor correspondence, board or leadership notification.
Note what did not happen: no media notice, because the count is under 500. And no waiting until year-end to tell patients. Practices confuse the annual HHS filing with the individual notice deadline more often than any other part of the HIPAA breach notification rule.
Your Business Associates Are Half the Exposure
Scan the OCR breach portal and the pattern is consistent: hacking and IT incidents at vendors, clearinghouses, and billing companies account for a large share of the reported records. Your practice's own network may be sound while your exposure sits inside someone else's.
The regulatory default gives a business associate 60 days from discovery to notify you — which, if they use all of it, leaves you zero days to notify patients. That is why the notification clause is the most important paragraph in your BAA. Negotiate for notice within 5 to 10 business days of discovery, require the BA to supply the affected individual list and the facts you need for your own four-factor assessment, and specify who pays for notification.
If your agreements are inconsistent or missing, a signature-ready Business Associate Agreement builder will get standardized terms in place across your vendor list faster than routing redlines one at a time.
Track Which Vendors Touch PHI
Maintain a vendor inventory with, at minimum: legal entity name, service description, category of PHI accessed, BAA execution date, notification window from the contract, and a security contact. When an incident hits, that table tells you in 30 seconds who to call and what you contracted for.
The Documentation OCR Asks For First
Breach investigations rarely start with the breach. They start with a data request: your Security Rule risk analysis, your policies and procedures, your workforce training records, your BAAs, and your breach log. Practices that cannot produce a current, documented risk analysis under § 164.308(a)(1)(ii)(A) find that a single misdirected email becomes a broader compliance review.
HHS published a proposed rule in January 2025 to strengthen Security Rule requirements — including tighter expectations around asset inventories, network mapping, and encryption. As of December 2025 it is not final, but the direction is clear: documentation-light compliance programs are getting harder to defend.
If your risk analysis is a spreadsheet someone updated three years ago, or your policy set does not actually name your systems, close that gap before you need it. Tools that generate a documented HIPAA risk analysis and the supporting policy set get you to a defensible baseline in hours rather than the months an outside consulting engagement takes.
State Laws and the FTC Rule Stack on Top
HIPAA sets a floor. Nearly every state has its own breach notification statute, and many run shorter clocks — 30 or 45 days — or require notice to the attorney general at thresholds well below 500. Check your state's requirements and any state where your patients reside.
Separately, if your practice operates a consumer-facing health app or a service that falls outside HIPAA, the FTC Health Breach Notification Rule may apply to that product line, with its own notification obligations. Two rules can govern one company.
Assign These Four Roles Before January
- Intake owner: receives every suspected incident, same business day, and timestamps it. Usually the privacy officer, with a named backup.
- Assessor: conducts and signs the four-factor analysis. Should not be the person who caused the incident.
- Notifier: owns letter production, address verification, mailing, and the toll-free line.
- Filer: submits to the HHS portal — immediately for 500+, and by March 1 for the prior year's small breaches.
Write those names into your incident response policy. "The Privacy Officer or designee" is not an assignment; it is a gap waiting for a vacation week.
Your Next 30 Days
Pull your 2025 incident log. Confirm every entry has a discovery date, a documented determination, and — where notification was required — proof of mailing. Reconcile it against your submissions and calendar the March 1 filing now.
Then look at whether the underlying documentation would hold up if the portal filing turned into a records request. If your risk analysis, policies, and BAAs are not current, build the full compliance document set before the next incident forces the issue. The HIPAA breach notification rule is procedural, and procedure is winnable — but only if the paperwork exists on day zero, not day sixty.