The HIPAA Breach Notification Rule sets who must be told after protected health information is exposed, and how quickly.
The short answer
After a breach of unsecured PHI, a covered entity must notify affected individuals without unreasonable delay and within 60 days, notify HHS, and notify prominent media if 500 or more residents of a state are affected. Business associates must notify the covered entity. An impermissible use or disclosure is presumed to be a breach unless a documented four-factor risk assessment shows a low probability that PHI was compromised.
Note the word unsecured. Properly encrypted data rendered unreadable is generally outside the rule, which is the strongest practical argument for encrypting everything.
On this page
What counts as a breach
An acquisition, access, use or disclosure of PHI not permitted by the Privacy Rule, which compromises its security or privacy. Three exceptions sit outside the definition.
| Exception | Example |
|---|---|
| Unintentional access by workforce, in good faith and within scope | A nurse opens the wrong chart, closes it, shares nothing |
| Inadvertent disclosure between authorised people at the same entity | An internal email reaches the wrong colleague who is also authorised |
| Good-faith belief the recipient could not retain the information | Discharge papers handed to the wrong patient and immediately returned |
Encryption is the safe harbour
If PHI was encrypted to the standard HHS specifies, and the key was not compromised, it is not unsecured PHI and notification is generally not triggered. A stolen laptop becomes a property loss rather than a reportable breach.
The four-factor assessment
Who to notify, and when
| Recipient | Timing | Method |
|---|---|---|
| Affected individuals | Without unreasonable delay, no later than 60 days from discovery | Written notice by first-class mail, or email if agreed |
| HHS, 500 or more affected | Within 60 days of discovery | Electronic submission to the HHS portal |
| HHS, fewer than 500 | Within 60 days of the end of the calendar year | Annual log submitted to the portal |
| Media | Within 60 days, if 500 or more residents of one state or jurisdiction | Prominent outlets serving that area |
| Covered entity, by a business associate | Without unreasonable delay, within 60 days unless the BAA is stricter | As specified in the BAA |
The clock starts on discovery, and you are treated as having discovered a breach when any workforce member knew or reasonably should have known. Delaying investigation does not delay the clock.
What the notice must say
What happened
A description of the breach, the date it occurred and the date it was discovered.
What was involved
The types of information exposed, such as name, diagnosis or social security number.
What happens next
Steps individuals should take, what you are doing to investigate and mitigate, and contact details.
How Osto shortens the clock
Sixty days sounds generous until you are trying to establish who accessed what. Osto’s SIEM with cross-module correlation keeps the access record that answers factor three, file access DLP flags PHI moving where it should not, and encryption keeps you inside the safe harbour in the first place. Endpoint and cloud posture data completes the timeline without a forensic scramble.
Free security assessment
Answer who accessed what, in hours not weeks
Correlated logs across endpoint, identity, cloud and network give you the access record the four-factor assessment needs.
Get a free security assessment Book a platform walkthroughCross-module correlation · DLP and encryption · One platform, everything
Frequently asked questions
What is the HIPAA Breach Notification Rule?
The rule requiring covered entities to notify affected individuals, HHS and sometimes the media after a breach of unsecured protected health information, and requiring business associates to notify the covered entity.
How long do you have to report a HIPAA breach?
Individuals must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people are reported to HHS in the same window; smaller ones are logged and submitted annually.
Is every impermissible disclosure a breach?
It is presumed to be one unless a documented four-factor risk assessment shows a low probability that PHI was compromised, or one of three narrow exceptions applies. The burden of proof sits with the organisation.
Does encryption avoid breach notification?
Generally yes. PHI encrypted to the standard HHS specifies is not unsecured PHI, so its loss does not usually trigger notification, provided the decryption key was not also compromised.
What must a business associate do after a breach?
Notify the covered entity without unreasonable delay and within 60 days, or sooner if the BAA requires it, supplying the detail the covered entity needs to make its own notifications. Many BAAs set far shorter windows.

