You have 60 days from today. If your practice discovered any breach affecting fewer than 500 individuals during calendar year 2025 — a misdirected fax, a portal message sent to the wrong patient, a laptop left in a car — the annual log covering those incidents is due to the Office for Civil Rights by March 1, 2026. Miss it and you have a reporting violation on top of whatever caused the breach.

The bigger incidents get different treatment. Anything touching 500 or more individuals goes on the public breach portal at HHS, the list the industry has called the HIPAA wall of shame since it went live. Your practice name, your state, the number of records, and the category of breach sit there where any patient, reporter, payer, or plaintiff's attorney can search them. This article covers what puts you on that list, the clocks that start the moment you discover an incident, and the documentation OCR will ask for afterward.

What the HIPAA Wall of Shame Actually Is

The HIPAA wall of shame is the public breach reporting portal that HHS maintains under Section 13402(e)(4) of the HITECH Act. The statute requires the Secretary to post a list of breaches of unsecured protected health information affecting 500 or more individuals. OCR does not use the nickname — the official name is the Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information.

Three things follow from that:

  • Listing is automatic and mandatory, not a penalty. You put yourself on it by filing the report the law requires you to file.
  • It only covers breaches of 500 or more individuals. Smaller incidents are reported annually and are not published individually.
  • Reporting is not an admission of a violation. OCR investigates every 500+ breach, and many close without a finding of noncompliance.

The point is that you cannot negotiate your way off the list. The only lever you control is whether the incident meets the definition of a reportable breach in the first place — and whether your record of that determination holds up.

The Two Clocks: 60 Days From Discovery, and March 1 for Everything Else

Both clocks start at discovery, which the rule defines as the first day the breach is known to your organization, or the first day it would have been known through the exercise of reasonable diligence. Knowledge by any workforce member or agent — other than the person who committed the breach — is knowledge by your practice. Your front-desk coordinator noticing a stack of after-visit summaries handed to the wrong patient starts the clock, whether or not she tells you that day.

500 or more individuals

You must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. You must notify OCR through the breach portal within that same 60-day window — contemporaneously with individual notice, not on the annual cycle. And if 500 or more residents of a single state or jurisdiction are affected, you must also notify prominent media outlets serving that state or jurisdiction within 60 days.

Sixty days is a ceiling, not a target. "Without unreasonable delay" is the operative standard, and OCR has treated multi-month delays as independent violations even where notice eventually went out.

Fewer than 500 individuals

Individual notice still runs on the same 60-day clock. The difference is the HHS notification: you log the incident and submit it through the portal within 60 days of the end of the calendar year in which the breach was discovered. For breaches discovered in 2025, that deadline is March 1, 2026.

Each small breach is submitted as a separate entry in the portal. Practices that batch a year's worth of incidents into one filing on February 28 routinely discover the form does not work that way. Build the log as incidents occur.

If you are a business associate

A business associate notifies the covered entity, not HHS and not the patients, no later than 60 days after discovery — unless the BAA sets a shorter window, which most well-drafted agreements do. A 10- or 15-day notice requirement in your BAA exists precisely so the covered entity has time left on its own 60-day clock.

What Gets Published Next to Your Practice's Name

The portal publishes a fixed set of fields. Know them before you file, because they shape how the incident reads to anyone who searches it later:

  • Name of covered entity
  • State
  • Covered entity type — healthcare provider, health plan, clearinghouse, or business associate
  • Individuals affected
  • Breach submission date
  • Type of breach — hacking/IT incident, unauthorized access/disclosure, theft, loss, or improper disposal
  • Location of breached information — network server, email, electronic medical record, paper/films, laptop, desktop computer, or other portable electronic device
  • Business associate present — yes or no

The distribution across those categories has shifted hard over the past decade. Theft of laptops and loss of paper records once dominated the list; today hacking and IT incidents involving network servers account for the large majority of reported breaches and an overwhelming share of affected individuals. Email is the second most common location, driven by business email compromise and phishing against clinical staff.

That shift matters for how you spend your security budget. If your last risk analysis still treats physical theft as your primary breach vector, it is describing the 2013 threat landscape.

The Presumption That Puts You on the List

Under 45 CFR 164.402, any acquisition, access, use, or disclosure of PHI not permitted by the Privacy Rule is presumed to be a breach. The burden is on you to demonstrate a low probability that the PHI was compromised. You do that with a documented four-factor risk assessment:

  1. The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or to whom the disclosure was made.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

All four. A one-line note saying "low risk, no notification required" is not a risk assessment; it is a conclusion with nothing under it. When OCR asks, they want to see the analysis, the date, who performed it, and what evidence supported each factor.

The three regulatory exceptions

Three situations are excluded from the definition of breach outright: an unintentional acquisition by a workforce member acting in good faith within the scope of authority; an inadvertent disclosure between two people authorized to access PHI at the same entity; and a disclosure where you have a good-faith belief the recipient could not reasonably have retained the information. Each still requires documentation showing why the exception applies.

The encryption safe harbor

The rule only covers unsecured PHI. If the data was encrypted consistent with HHS guidance — which points to NIST SP 800-111 for data at rest and NIST-validated processes for data in transit — the incident is not a reportable breach. This is the single highest-leverage control you can implement. Full-disk encryption on every laptop and workstation converts an entire category of potential wall-of-shame listings into a non-event, provided you can produce evidence the device was encrypted and the key was not compromised.

Keep encryption attestations per device, with dates. "We think everything is encrypted" is worth nothing when the laptop is already gone.

The "Business Associate Present" Column

Roughly a third of entries on the HIPAA wall of shame in recent years involve a business associate — a billing company, a transcription service, an IT managed service provider, a cloud backup vendor. When the breach originates with a vendor, the covered entity is still the one whose name appears on the portal in most cases, because the covered entity holds the notification obligation to its own patients.

That is the practical reason your vendor paperwork matters. A signed BAA does not prevent a breach, but it establishes the vendor's notification timeline, its obligation to cooperate with your investigation, its subcontractor flow-down duties, and who bears notification costs. Without it, you have an independent HIPAA violation sitting alongside the breach, and OCR has repeatedly settled cases where the missing agreement was the finding — not the incident itself.

If your vendor list has gaps — and most do, especially for the small SaaS tools clinical staff adopted without telling anyone — close them before you need them. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which makes it practical to paper the entire vendor list in an afternoon rather than one contract at a time.

How Long Your Entry Stays Up

Breaches under investigation stay on the main portal list. Once OCR closes the investigation, the entry moves to the portal's archive, which remains publicly searchable indefinitely. Entries do not expire off the internet after two years, and they do not come down because you fixed the problem.

Plan communications accordingly. Patients who search your practice name years later will find the archive entry with no context about remediation unless you have published your own account somewhere they will also find.

A 72-Hour Playbook for the Day You Discover an Incident

Assign these roles now, in writing, before you need them.

Hour 0–4 — Contain. Your IT lead isolates affected systems, disables compromised credentials, and preserves logs. Nobody wipes or reimages anything. Your privacy officer records the discovery date and time and who reported it. That timestamp is the anchor for every deadline that follows.

Hour 4–24 — Scope. Determine what PHI was involved, whose, and how many individuals. If a vendor is implicated, invoke the notification and cooperation clauses in the BAA in writing the same day. If the number could plausibly reach 500, notify counsel now rather than on day 45.

Day 2–5 — Assess. Complete and sign the four-factor risk assessment. Reach a documented conclusion: reportable, or not reportable with stated reasoning. If reportable, start drafting individual notices immediately — content requirements under 164.404(c) include a description of what happened, the types of information involved, steps individuals should take, what you are doing, and contact procedures including a toll-free number.

Day 5–60 — Notify. Send written notice by first-class mail to last known addresses, or by email where the individual has agreed to electronic notice. If you have insufficient or out-of-date contact information for 10 or more individuals, substitute notice applies: a conspicuous posting on your website home page for 90 days, or notice in major print or broadcast media, plus a toll-free number active for at least 90 days. File the report through the HHS breach reporting portal.

The Evidence File OCR Will Ask For

Every 500+ breach triggers an OCR investigation. The data request that follows is predictable, and the practices that come through it cleanly are the ones that had these documents before the incident, not after:

  • Your current security risk analysis, dated, covering all systems that create, receive, maintain, or transmit ePHI — including the one that got breached.
  • The risk management plan showing what you did about the findings.
  • Written policies and procedures for breach notification, sanctions, access management, and audit controls.
  • Workforce training records with names and dates.
  • Executed BAAs for every vendor with PHI access, including subcontractor flow-downs.
  • The four-factor risk assessment for the incident.
  • Copies of the notices sent and proof of mailing dates.

Retain all of it for six years from creation or last effective date, per 45 CFR 164.530(j). OCR's enforcement pattern over the past several years has centered heavily on the risk analysis requirement — incomplete or entirely absent risk analyses show up as a finding in resolution agreement after resolution agreement. HHS also issued a proposed Security Rule update in January 2025 that would tighten many of these expectations, including asset inventories and mandatory encryption; it remains proposed, but it signals where enforcement attention sits.

Review the full requirements on the HHS Breach Notification Rule page, and read a dozen entries on the portal for practices your size. The pattern is instructive.

What to Do This Week

Pull your 2025 incident log and confirm every small breach has a completed risk assessment attached. Submit the ones that qualify before March 1, 2026. Then check two things: whether every vendor touching PHI has a signed, current agreement, and whether your risk analysis was updated in the last twelve months.

If either is stale, fix the paperwork now. Build the missing business associate agreements in one sitting, and use automated risk analysis and policy generation to close the documentation gap that OCR asks about first. Neither prevents an incident — but both determine whether the investigation that follows a listing on the HIPAA wall of shame ends in a closure letter or a corrective action plan.