On Monday, November 3, a medical assistant at a four-provider orthopedic practice emailed a surgery scheduling spreadsheet to a referring office. Wrong address. 214 patients, names and dates of birth and procedure codes. She told the office manager the same afternoon. The office manager mentioned it to the privacy officer eleven days later, during a staff meeting.

Under the HIPAA breach reporting timeline, that practice's 60-day deadline started on November 3 — not November 14. Day 60 landed on January 2. Nobody in that building knew the clock had been running for a week and a half.

This article maps every deadline in the Breach Notification Rule, who owns each one, and what the evidence file has to contain when the Office for Civil Rights asks you to prove you met them. If you are the person who would be answering that question, keep reading.

The HIPAA Breach Reporting Timeline in Plain Numbers

Four deadlines govern almost every incident:

  • Individuals: notify without unreasonable delay, and no later than 60 calendar days after discovery of the breach.
  • Breaches affecting 500+ individuals: notify HHS contemporaneously with individual notice — no later than 60 calendar days after discovery — and notify prominent media outlets serving the affected state or jurisdiction within the same 60 days.
  • Breaches affecting fewer than 500 individuals: log them and submit to HHS no later than 60 days after the end of the calendar year in which they were discovered. For anything discovered in 2025, that deadline is March 1, 2026.
  • Business associates: notify the covered entity without unreasonable delay and no later than 60 calendar days after the business associate discovers the breach — unless your Business Associate Agreement requires faster, which it should.

All of these live in 45 CFR §§ 164.400–414. The 60 days is a ceiling, not a target. "Without unreasonable delay" is the operative standard, and OCR has treated a slow 55-day notification as a violation when nothing justified the pace.

Discovery Starts the Clock — and Discovery Is Broader Than You Think

A breach is "discovered" on the first day it is known to your organization, or by exercising reasonable diligence would have been known. Critically, knowledge is imputed to you if any workforce member or agent knows — other than the person who committed the breach.

Go back to the orthopedic practice. The medical assistant knew on November 3. She is a workforce member. Her knowledge is the practice's knowledge. The eleven days the office manager sat on it were eleven days of the 60 already burned, and eleven days the practice will have to explain.

The reasonable diligence trap

"Would have been known" catches practices that do not look. If your EHR generates audit logs that nobody reviews, and a login anomaly sat in those logs for four months, OCR can argue discovery occurred when a reasonably diligent practice would have caught it — not when you finally opened the report.

The operational fix is unglamorous. Assign a named person to review access logs on a fixed cadence, document each review with a date and initials, and keep those records. That documentation is the only thing standing between you and a discovery date you did not choose.

Build a one-way reporting channel

Front-desk and clinical staff should report suspected incidents to the privacy officer directly — not up through a supervisor who filters. Give them an email alias, a phone extension, and a paper form. Train that reporting the same day is a job requirement, not a courtesy. Then log the intake timestamp, because that timestamp becomes your documented discovery date.

The Four-Factor Risk Assessment That Decides Whether You Notify

An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you demonstrate a low probability that the PHI has been compromised. You carry the burden. The assessment weighs at least four factors:

  1. The nature and extent of the PHI, including the types of identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or to whom it was disclosed.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

Run this in writing, every time, even when the answer is obvious. A two-page memo signed by the privacy officer with the date of discovery, the facts, each factor addressed, and the conclusion is exactly what an investigator wants to see. Retain it six years.

The clock does not pause while you assess. Discovery already happened. Your risk assessment is one activity inside the 60 days, not a preliminary step before the 60 days begin.

The three exceptions worth memorizing

Certain events are excluded from the definition of breach outright:

  • Unintentional acquisition, access, or use by a workforce member acting in good faith within the scope of authority, with no further impermissible use or disclosure.
  • Inadvertent disclosure between two people both authorized to access PHI at the same covered entity, business associate, or organized health care arrangement — again, with no further impermissible use.
  • A good-faith belief that the unauthorized recipient would not reasonably have been able to retain the information.

Document the exception the same way you would document a risk assessment. "We decided it was fine" is not a record.

500 or More Individuals: One Deadline, Three Audiences

Cross 500 affected individuals in a single state or jurisdiction and the incident becomes public. Within the same 60 days you owe:

  • Individual notice by first-class mail to the last known address, or by email if the individual previously agreed to electronic notice.
  • Media notice to prominent outlets serving the state or jurisdiction — typically a press release, and it must contain the same content elements as the individual notice.
  • HHS notice through the OCR breach portal, filed contemporaneously with individual notice.

Submissions land on the public portal that practice administrators know as the wall of shame. You can review current and historical filings at the OCR breach reporting portal, which is also where the electronic submission form lives.

If you have insufficient or out-of-date contact information for 10 or more individuals, substitute notice kicks in: a conspicuous posting on your website home page for 90 days, or notice in major print or broadcast media in the affected area, plus a toll-free number active for at least 90 days. For fewer than 10, an alternative written form, telephone, or other means will do.

Fewer Than 500: The March 1 Filing Most Practices Forget

Small breaches still require individual notice within 60 days of discovery. What changes is the HHS reporting deadline — those roll into an annual submission due within 60 days after the calendar year ends.

Every small breach your practice discovered during 2025 must be filed with HHS by March 1, 2026. Each one is a separate submission through the portal, not a single combined report.

Two failure modes recur. First, practices maintain no running breach log, so January arrives and nobody can reconstruct the year. Second, practices report the breach date instead of the discovery date, which quietly misstates the record. Keep a live spreadsheet with columns for discovery date, breach date, individuals affected, PHI elements, notification date, and portal confirmation number. Update it the day an incident closes.

HHS maintains the full rule text and notification instructions on its Breach Notification Rule page. Print it and keep it in the incident binder.

Your Business Associates Report to You — If Your Contract Says So

Business associates do not notify patients or file with HHS on their own behalf for your patients. They notify you, and you carry the downstream obligations. The regulatory default gives them the full 60 days, which would leave you with zero days to investigate, draft, print, and mail.

That is why the notification clause in your BAA is not boilerplate. A workable agreement requires the business associate to report a suspected breach within a defined short window — many practices use 5 or 10 calendar days from discovery — to provide the identity of affected individuals and the PHI elements involved, and to cooperate with your investigation at their cost.

Pull your vendor list and check the notification clause in each agreement. Billing company, transcription service, IT managed service provider, shredding vendor, cloud backup, answering service, email platform. If any of those contracts is silent on timing or simply mirrors the 60-day default, you have a gap that will surface at the worst possible moment. When you need to replace one, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, so you are not signing up for a platform to fix three contracts.

State Breach Laws and the FTC Rule Can Beat the Federal Clock

HIPAA sets a floor. Many state breach notification statutes require notice in 30 or 45 days, apply lower thresholds for attorney general notification, or cover data elements HIPAA does not. Where state law is more protective, you follow state law.

Separately, if your practice offers a consumer-facing health app or personal health record product that falls outside HIPAA, the FTC's Health Breach Notification Rule may apply with its own timing and content requirements. Know which regime governs before an incident, not during one.

A Worked Timeline You Can Copy

Take the orthopedic practice, and assume the privacy officer had learned of the misdirected email on November 3 instead of November 14.

  • Day 0 (Nov 3): Intake form completed and timestamped. Discovery date recorded. Privacy officer opens an incident file.
  • Day 1–2: Contain. Contact the recipient practice, request deletion, obtain written attestation of deletion. Pull the sent item and confirm the exact attachment and recipient list.
  • Day 3–7: Scope. Generate the exact list of 214 individuals and the PHI elements. Run and sign the four-factor risk assessment.
  • Day 8–15: Decide and draft. Because the recipient was another provider under obligations of confidentiality and attested to deletion, the practice may reach a low-probability conclusion — but the memo has to show the reasoning, not the conclusion alone.
  • Day 15–30: If notice is required, print and mail. Notices must state what happened, the breach date and discovery date, the types of PHI involved, steps individuals should take, what you are doing to investigate and mitigate, and contact procedures including a toll-free number, email, website, or postal address.
  • Day 60 (Jan 2): Absolute outer limit. If you are still working on Day 55, something in your process broke.
  • By March 1, 2026: File the small-breach report with HHS through the portal. Save the confirmation.

You Can Delay Only for Law Enforcement

Under 45 CFR § 164.412, if a law enforcement official states that notification would impede a criminal investigation or damage national security, you may delay. A written statement specifying the required delay period lets you delay for that period. An oral statement lets you delay up to 30 days unless a written statement follows.

Document the officer's name, agency, badge number, date, and the exact statement. "The detective asked us to hold off" without a record is not a defense.

The Evidence File That Proves You Met the Timeline

Section 164.414 puts the burden of proof on you — to show either that notifications were made as required, or that the use or disclosure was not a breach. Your incident file should contain, for six years:

  • The intake record with the discovery timestamp and who reported it.
  • The signed four-factor risk assessment or exception memo.
  • The affected individual list and PHI elements.
  • A copy of the notification letter, the mailing date, the mailing method, and the returned-mail handling record.
  • Media notice and substitute notice documentation, if applicable.
  • The HHS portal confirmation.
  • Mitigation and sanction records — retraining, policy change, workforce discipline applied under your sanction policy.

OCR has resolved cases built specifically on late notification, including a 2017 settlement with a Chicago-area health system that paid $475,000 after failing to notify individuals, media, and HHS within the required window. The underlying breach was not the violation OCR charged. The delay was.

For the framework behind incident detection and response controls, NIST's SP 800-66 Revision 2 maps Security Rule requirements to practical safeguards and is a defensible reference to cite in your own policies.

What to Do This Week

Pull your 2025 breach log and confirm every small breach is ready to file before March 1, 2026. Then check three things: whether your staff know who to call the same day, whether someone is actually reviewing audit logs on a schedule, and whether your vendor agreements require notice fast enough to leave you room to act.

If that review turns up contracts with weak or missing notification clauses, build replacement Business Associate Agreements with the timing language you need and get them signed before the next incident. And if your broader documentation set — risk analysis, policies, incident response procedures — has not been touched in a year, automating the compliance document set is a faster path than starting from a blank page in March.