The HIPAA Breach Notification Rule decides what you must do when protected health information is exposed. Here is what counts as a breach, who to tell, and how fast.
TL;DR
The Breach Notification Rule requires you to notify affected individuals, HHS, and sometimes the media when unsecured protected health information is exposed. Individuals must be told without unreasonable delay and no later than 60 days after discovery.
Not every incident is a reportable breach: a four-factor risk assessment decides. And only unsecured PHI triggers notice, encrypted data generally does not. Business associates must alert the covered entity so it can notify.
On this page
What counts as a HIPAA breach?
A breach is an impermissible use or disclosure of protected health information that compromises its security or privacy. The key qualifier is unsecured: the Breach Notification Rule applies to unsecured PHI, meaning data that has not been rendered unreadable, such as through encryption. If exposed data was properly encrypted, notification is generally not required, which is one reason encryption matters so much.
The four-factor risk assessment
An impermissible use or disclosure is presumed to be a breach, but you can rebut that presumption. You do so with a risk assessment that weighs whether there is a low probability the PHI was compromised. If four factors together show low probability, notification may not be required, and you document that conclusion.
The four factors are: the nature and extent of the PHI involved, who received or accessed it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Together they determine whether the incident crosses into reportable-breach territory.
Who you must notify
When an incident is a reportable breach, the rule can require up to three separate notifications, depending on scale.
| Recipient | When | Deadline |
|---|---|---|
| Affected individuals | Every reportable breach | Without unreasonable delay, within 60 days of discovery |
| HHS (large breach) | 500 or more individuals | Within 60 days of discovery |
| HHS (small breach) | Fewer than 500 individuals | Within 60 days after the calendar year ends |
| The media | 500+ residents of one state or jurisdiction | Without unreasonable delay, within 60 days |
The deadlines, on a timeline
The headline number is 60 days, but exactly what that 60 days is measured from depends on the size of the breach.
What business associates must do
If you are a business associate, a SaaS vendor, cloud host, or processor handling PHI, and you discover a breach, your primary duty is to notify the covered entity without unreasonable delay and within 60 days, providing the information it needs to notify individuals, HHS, and the media. Your business associate agreement should spell out exactly how and how fast you will do this, so agree it in advance.
The lean-team path to breach readiness
Breach readiness is not just about reacting fast. It is about the controls that prevent breaches, detect them early, and, through encryption, reduce which incidents even become reportable, plus the evidence trail regulators expect if they investigate. Running that across scattered tools is where detection lags and the evidence trail fragments.
Be ready before a breach, not scrambling after.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Encrypt PHI, detect incidents early, and keep the evidence trail, all on one platform mapped to HIPAA. No security team required.
Frequently asked questions
What is the HIPAA Breach Notification Rule?
It requires covered entities and business associates to notify affected individuals, HHS, and sometimes the media when unsecured protected health information is breached. Individuals must be notified without unreasonable delay and no later than 60 days after discovery.
What is the HIPAA breach notification deadline?
Individuals and, for breaches of 500 or more, HHS must be notified within 60 days of discovery. Breaches affecting fewer than 500 individuals can be logged and reported to HHS within 60 days after the end of the calendar year.
Does every incident require notification?
No. An impermissible use or disclosure is presumed a breach, but a four-factor risk assessment can show a low probability that PHI was compromised, in which case notification may not be required. You document that determination.
Does encryption affect breach notification?
Yes, significantly. The rule applies to unsecured PHI. If exposed data was properly encrypted and therefore unreadable, notification is generally not required. Encryption both protects data and reduces notification burden.
When is media notification required?
When a breach affects 500 or more residents of a single state or jurisdiction. The covered entity must notify prominent media outlets serving that area without unreasonable delay and no later than 60 days after discovery.
What must a business associate do after a breach?
Notify the covered entity without unreasonable delay and within 60 days, providing the details it needs to notify individuals, HHS, and the media. The specific responsibilities and timing should be defined in the business associate agreement.

