Breach Notification Rule: The 60-Day Clock

HIPAA Breach Notification Rule four-factor risk assessment

The HIPAA Breach Notification Rule sets who must be told after protected health information is exposed, and how quickly.

  • Glossary
  • HIPAA

The short answer

After a breach of unsecured PHI, a covered entity must notify affected individuals without unreasonable delay and within 60 days, notify HHS, and notify prominent media if 500 or more residents of a state are affected. Business associates must notify the covered entity. An impermissible use or disclosure is presumed to be a breach unless a documented four-factor risk assessment shows a low probability that PHI was compromised.

Note the word unsecured. Properly encrypted data rendered unreadable is generally outside the rule, which is the strongest practical argument for encrypting everything.

What counts as a breach

An acquisition, access, use or disclosure of PHI not permitted by the Privacy Rule, which compromises its security or privacy. Three exceptions sit outside the definition.

ExceptionExample
Unintentional access by workforce, in good faith and within scopeA nurse opens the wrong chart, closes it, shares nothing
Inadvertent disclosure between authorised people at the same entityAn internal email reaches the wrong colleague who is also authorised
Good-faith belief the recipient could not retain the informationDischarge papers handed to the wrong patient and immediately returned

Encryption is the safe harbour

If PHI was encrypted to the standard HHS specifies, and the key was not compromised, it is not unsecured PHI and notification is generally not triggered. A stolen laptop becomes a property loss rather than a reportable breach.

The four-factor assessment

PRESUMED A BREACH UNLESS ALL FOUR POINT LOW 1. The data Nature and extent, identifiers involved 2. The recipient Who saw it, and are they HIPAA-bound 3. Acquisition Was PHI actually viewed or acquired 4. Mitigation Recovered, deleted, attested destroyed The burden of proof sits with you. Undocumented reasoning defaults to a reportable breach. Factor 3 is where log data decides the outcome.

Who to notify, and when

RecipientTimingMethod
Affected individualsWithout unreasonable delay, no later than 60 days from discoveryWritten notice by first-class mail, or email if agreed
HHS, 500 or more affectedWithin 60 days of discoveryElectronic submission to the HHS portal
HHS, fewer than 500Within 60 days of the end of the calendar yearAnnual log submitted to the portal
MediaWithin 60 days, if 500 or more residents of one state or jurisdictionProminent outlets serving that area
Covered entity, by a business associateWithout unreasonable delay, within 60 days unless the BAA is stricterAs specified in the BAA

The clock starts on discovery, and you are treated as having discovered a breach when any workforce member knew or reasonably should have known. Delaying investigation does not delay the clock.

What the notice must say

What happened

A description of the breach, the date it occurred and the date it was discovered.

What was involved

The types of information exposed, such as name, diagnosis or social security number.

What happens next

Steps individuals should take, what you are doing to investigate and mitigate, and contact details.

How Osto shortens the clock

Sixty days sounds generous until you are trying to establish who accessed what. Osto’s SIEM with cross-module correlation keeps the access record that answers factor three, file access DLP flags PHI moving where it should not, and encryption keeps you inside the safe harbour in the first place. Endpoint and cloud posture data completes the timeline without a forensic scramble.

Free security assessment

Answer who accessed what, in hours not weeks

Correlated logs across endpoint, identity, cloud and network give you the access record the four-factor assessment needs.

Get a free security assessment Book a platform walkthrough

Cross-module correlation · DLP and encryption · One platform, everything

Frequently asked questions

What is the HIPAA Breach Notification Rule?

The rule requiring covered entities to notify affected individuals, HHS and sometimes the media after a breach of unsecured protected health information, and requiring business associates to notify the covered entity.

How long do you have to report a HIPAA breach?

Individuals must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people are reported to HHS in the same window; smaller ones are logged and submitted annually.

Is every impermissible disclosure a breach?

It is presumed to be one unless a documented four-factor risk assessment shows a low probability that PHI was compromised, or one of three narrow exceptions applies. The burden of proof sits with the organisation.

Does encryption avoid breach notification?

Generally yes. PHI encrypted to the standard HHS specifies is not unsecured PHI, so its loss does not usually trigger notification, provided the decryption key was not also compromised.

What must a business associate do after a breach?

Notify the covered entity without unreasonable delay and within 60 days, or sooner if the BAA requires it, supplying the detail the covered entity needs to make its own notifications. Many BAAs set far shorter windows.