HIPAA Breach Notification Rule: Who, When, and How

HIPAA breach notification rule who when how
HIPAA Breach Notification Rule: Who, When, and How | Osto

The HIPAA Breach Notification Rule decides what you must do when protected health information is exposed. Here is what counts as a breach, who to tell, and how fast.

Osto Security Team8 min readCompliance & Trust

TL;DR

The Breach Notification Rule requires you to notify affected individuals, HHS, and sometimes the media when unsecured protected health information is exposed. Individuals must be told without unreasonable delay and no later than 60 days after discovery.

Not every incident is a reportable breach: a four-factor risk assessment decides. And only unsecured PHI triggers notice, encrypted data generally does not. Business associates must alert the covered entity so it can notify.

What counts as a HIPAA breach?

A breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The key qualifier is unsecured: the Breach Notification Rule applies to unsecured PHI, meaning data that has not been rendered unreadable, such as through encryption. If exposed data was properly encrypted, notification is generally not required, which is one reason encryption matters so much.

Why encryption changes everything here
Notification obligations attach to unsecured PHI. Encrypted health data that is exposed generally does not trigger the breach notification requirements, because it is not readable. Strong encryption is both a safeguard and a shield against notification burden.

The four-factor risk assessment

An impermissible use or disclosure is presumed to be a breach, but you can rebut that presumption. You do so with a risk assessment that weighs whether there is a low probability the PHI was compromised. If four factors together show low probability, notification may not be required, and you document that conclusion.

Is it a reportable breach?
Not every incident triggers notification
An impermissible use or disclosure of unsecured PHI is presumed a breach unless a risk assessment shows a low probability that the data was compromised.
Impermissible use or disclosure of PHI Run the 4-factor risk assessment is there a low probability of compromise? Low probability Document it. No notice required. Reportable breach Notify per the timelines below.

The four factors are: the nature and extent of the PHI involved, who received or accessed it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Together they determine whether the incident crosses into reportable-breach territory.

Who you must notify

When an incident is a reportable breach, the rule can require up to three separate notifications, depending on scale.

Who you must notify
A breach can trigger up to three notifications
Affected individuals
Without unreasonable delay, and no later than 60 days after discovery.
HHS (OCR)
Within 60 days for large breaches; annually for smaller ones.
The media
Required when 500+ residents of one state or jurisdiction are affected.
RecipientWhenDeadline
Affected individualsEvery reportable breachWithout unreasonable delay, within 60 days of discovery
HHS (large breach)500 or more individualsWithin 60 days of discovery
HHS (small breach)Fewer than 500 individualsWithin 60 days after the calendar year ends
The media500+ residents of one state or jurisdictionWithout unreasonable delay, within 60 days

The deadlines, on a timeline

The headline number is 60 days, but exactly what that 60 days is measured from depends on the size of the breach.

The deadlines
The 60-day clock, and the exception
Large breaches are reported to individuals and HHS within 60 days. Smaller ones can be logged and reported after the calendar year.
DiscoveryIndividuals + HHSSmaller breaches day 0 within 60 days(500+ individuals) 60 days afteryear-end (under 500)
The public dimension
Breaches affecting 500 or more individuals are posted on the public HHS breach portal. Beyond the legal deadlines, that visibility is why breach handling is also a matter of trust and reputation, not just compliance.

What business associates must do

If you are a business associate, a SaaS vendor, cloud host, or processor handling PHI, and you discover a breach, your primary duty is to notify the covered entity without unreasonable delay and within 60 days, providing the information it needs to notify individuals, HHS, and the media. Your business associate agreement should spell out exactly how and how fast you will do this, so agree it in advance.

The lean-team path to breach readiness

Breach readiness is not just about reacting fast. It is about the controls that prevent breaches, detect them early, and, through encryption, reduce which incidents even become reportable, plus the evidence trail regulators expect if they investigate. Running that across scattered tools is where detection lags and the evidence trail fragments.

Be ready before a breach, not scrambling after.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Encrypt PHI, detect incidents early, and keep the evidence trail, all on one platform mapped to HIPAA. No security team required.

Book a Demo →

Frequently asked questions

What is the HIPAA Breach Notification Rule?

It requires covered entities and business associates to notify affected individuals, HHS, and sometimes the media when unsecured protected health information is breached. Individuals must be notified without unreasonable delay and no later than 60 days after discovery.

What is the HIPAA breach notification deadline?

Individuals and, for breaches of 500 or more, HHS must be notified within 60 days of discovery. Breaches affecting fewer than 500 individuals can be logged and reported to HHS within 60 days after the end of the calendar year.

Does every incident require notification?

No. An impermissible use or disclosure is presumed a breach, but a four-factor risk assessment can show a low probability that PHI was compromised, in which case notification may not be required. You document that determination.

Does encryption affect breach notification?

Yes, significantly. The rule applies to unsecured PHI. If exposed data was properly encrypted and therefore unreadable, notification is generally not required. Encryption both protects data and reduces notification burden.

When is media notification required?

When a breach affects 500 or more residents of a single state or jurisdiction. The covered entity must notify prominent media outlets serving that area without unreasonable delay and no later than 60 days after discovery.

What must a business associate do after a breach?

Notify the covered entity without unreasonable delay and within 60 days, providing the details it needs to notify individuals, HHS, and the media. The specific responsibilities and timing should be defined in the business associate agreement.