{"id":845,"date":"2026-08-17T05:15:07","date_gmt":"2026-08-17T05:15:07","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=845"},"modified":"2026-08-17T05:15:07","modified_gmt":"2026-08-17T05:15:07","slug":"hipaa-breach-notification-rule","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/hipaa-breach-notification-rule\/","title":{"rendered":"Breach Notification Rule: The 60-Day Clock"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: BREACH NOTIFICATION RULE\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">The HIPAA Breach Notification Rule sets who must be told after protected health information is exposed, and how quickly.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>After a breach of unsecured PHI, a covered entity must notify affected individuals without unreasonable delay and within 60 days, notify HHS, and notify prominent media if 500 or more residents of a state are affected. Business associates must notify the covered entity. An impermissible use or disclosure is presumed to be a breach unless a documented four-factor risk assessment shows a low probability that PHI was compromised.<\/p>\n<\/div>\n\n<p>Note the word unsecured. Properly encrypted data rendered unreadable is generally outside the rule, which is the strongest practical argument for encrypting everything.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What counts as a breach<\/a><\/li>\n    <li><a href=\"#factors\">The four-factor assessment<\/a><\/li>\n    <li><a href=\"#who\">Who to notify, and when<\/a><\/li>\n    <li><a href=\"#contains\">What the notice must say<\/a><\/li>\n    <li><a href=\"#osto\">How Osto shortens the clock<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What counts as a breach<\/h2>\n\n<p>An acquisition, access, use or disclosure of PHI not permitted by the Privacy Rule, which compromises its security or privacy. Three exceptions sit outside the definition.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Exception<\/th><th>Example<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Unintentional access by workforce, in good faith and within scope<\/td><td>A nurse opens the wrong chart, closes it, shares nothing<\/td><\/tr>\n    <tr><td>Inadvertent disclosure between authorised people at the same entity<\/td><td>An internal email reaches the wrong colleague who is also authorised<\/td><\/tr>\n    <tr><td>Good-faith belief the recipient could not retain the information<\/td><td>Discharge papers handed to the wrong patient and immediately returned<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Encryption is the safe harbour<\/p>\n  <p>If PHI was encrypted to the standard HHS specifies, and the key was not compromised, it is not unsecured PHI and notification is generally not triggered. A stolen laptop becomes a property loss rather than a reportable breach.<\/p>\n<\/div>\n\n<h2 id=\"factors\" class=\"c-sage\">The four-factor assessment<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 200\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four factors assessed after an impermissible disclosure: nature of the data, who received it, whether it was actually viewed, and how far risk was mitigated.\">\n  <text x=\"20\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">PRESUMED A BREACH UNLESS ALL FOUR POINT LOW<\/text>\n\n  <rect x=\"12\" y=\"42\" width=\"178\" height=\"86\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"101\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">1. The data<\/text>\n  <text x=\"101\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Nature and extent,<\/text>\n  <text x=\"101\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">identifiers involved<\/text>\n\n  <rect x=\"198\" y=\"42\" width=\"178\" height=\"86\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"287\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">2. The recipient<\/text>\n  <text x=\"287\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Who saw it, and are<\/text>\n  <text x=\"287\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">they HIPAA-bound<\/text>\n\n  <rect x=\"384\" y=\"42\" width=\"178\" height=\"86\" rx=\"14\" fill=\"#fbe9dc\"\/>\n  <text x=\"473\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">3. Acquisition<\/text>\n  <text x=\"473\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Was PHI actually<\/text>\n  <text x=\"473\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">viewed or acquired<\/text>\n\n  <rect x=\"570\" y=\"42\" width=\"178\" height=\"86\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"659\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">4. Mitigation<\/text>\n  <text x=\"659\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Recovered, deleted,<\/text>\n  <text x=\"659\" y=\"108\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">attested destroyed<\/text>\n\n  <text x=\"380\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">The burden of proof sits with you. Undocumented reasoning defaults to a reportable breach.<\/text>\n  <text x=\"380\" y=\"184\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Factor 3 is where log data decides the outcome.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"who\" class=\"c-apri\">Who to notify, and when<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Recipient<\/th><th>Timing<\/th><th>Method<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Affected individuals<\/strong><\/td><td>Without unreasonable delay, no later than 60 days from discovery<\/td><td>Written notice by first-class mail, or email if agreed<\/td><\/tr>\n    <tr><td><strong>HHS, 500 or more affected<\/strong><\/td><td>Within 60 days of discovery<\/td><td>Electronic submission to the HHS portal<\/td><\/tr>\n    <tr><td><strong>HHS, fewer than 500<\/strong><\/td><td>Within 60 days of the end of the calendar year<\/td><td>Annual log submitted to the portal<\/td><\/tr>\n    <tr><td><strong>Media<\/strong><\/td><td>Within 60 days, if 500 or more residents of one state or jurisdiction<\/td><td>Prominent outlets serving that area<\/td><\/tr>\n    <tr><td><strong>Covered entity, by a business associate<\/strong><\/td><td>Without unreasonable delay, within 60 days unless the BAA is stricter<\/td><td>As specified in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/business-associate-agreement\/\">BAA<\/a><\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The clock starts on discovery, and you are treated as having discovered a breach when any workforce member knew or reasonably should have known. Delaying investigation does not delay the clock.<\/p>\n\n<h2 id=\"contains\" class=\"c-plum\">What the notice must say<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">What happened<\/p>\n    <p>A description of the breach, the date it occurred and the date it was discovered.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">What was involved<\/p>\n    <p>The types of information exposed, such as name, diagnosis or social security number.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">What happens next<\/p>\n    <p>Steps individuals should take, what you are doing to investigate and mitigate, and contact details.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto shortens the clock<\/h2>\n\n<p>Sixty days sounds generous until you are trying to establish who accessed what. Osto&#8217;s <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM with cross-module correlation<\/a> keeps the access record that answers factor three, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">file access DLP<\/a> flags PHI moving where it should not, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption<\/a> keeps you inside the safe harbour in the first place. Endpoint and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture<\/a> data completes the timeline without a forensic scramble.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Answer who accessed what, in hours not weeks<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Correlated logs across endpoint, identity, cloud and network give you the access record the four-factor assessment needs.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Cross-module correlation &middot; DLP and encryption &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is the HIPAA Breach Notification Rule?<\/summary>\n  <p>The rule requiring covered entities to notify affected individuals, HHS and sometimes the media after a breach of unsecured protected health information, and requiring business associates to notify the covered entity.<\/p>\n<\/details>\n\n<details>\n  <summary>How long do you have to report a HIPAA breach?<\/summary>\n  <p>Individuals must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people are reported to HHS in the same window; smaller ones are logged and submitted annually.<\/p>\n<\/details>\n\n<details>\n  <summary>Is every impermissible disclosure a breach?<\/summary>\n  <p>It is presumed to be one unless a documented four-factor risk assessment shows a low probability that PHI was compromised, or one of three narrow exceptions applies. The burden of proof sits with the organisation.<\/p>\n<\/details>\n\n<details>\n  <summary>Does encryption avoid breach notification?<\/summary>\n  <p>Generally yes. PHI encrypted to the standard HHS specifies is not unsecured PHI, so its loss does not usually trigger notification, provided the decryption key was not also compromised.<\/p>\n<\/details>\n\n<details>\n  <summary>What must a business associate do after a breach?<\/summary>\n  <p>Notify the covered entity without unreasonable delay and within 60 days, or sooner if the BAA requires it, supplying the detail the covered entity needs to make its own notifications. Many BAAs set far shorter windows.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> HIPAA Security Rule &middot; HIPAA Privacy Rule &middot; PHI &middot; Business Associate Agreement &middot; Encryption at Rest and in Transit &middot; SIEM<\/p>\n\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The HIPAA Breach Notification Rule sets who must be told after protected health information is exposed, and how quickly. Glossary\u2026<\/p>\n","protected":false},"author":8,"featured_media":846,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[338,337],"class_list":["post-845","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-breach-notification","tag-hipaa-breach-notification-rule"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=845"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/845\/revisions"}],"predecessor-version":[{"id":847,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/845\/revisions\/847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/846"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}