hipaa.systems
Rule overview · 45 CFR 164.400–164.414

HIPAA Breach Notification Rule

What the HIPAA Breach Notification Rule requires after a breach of unsecured PHI: the four-factor assessment, deadlines, and notices to patients, HHS, the media and covered entities.

Checked 2026-10-06Requirements 1

HIPAA Breach Notification Rule at a glance

The HIPAA Breach Notification Rule (45 CFR 164.400–164.414) requires covered entities to notify affected individuals, HHS and, for breaches of more than 500 residents of a state, the media after a breach of unsecured protected health information. Individual notices are due without unreasonable delay and no later than 60 days after discovery. Business associates must notify the covered entity. PHI encrypted in line with HHS guidance, with the key and process not compromised, is not unsecured, so its loss may not require notification.

Where45 CFR Part 164, Subpart D (164.400–164.414)
TriggerBreach of unsecured PHI, presumed unless a four-factor assessment shows low probability of compromise
IndividualsWithin 60 days of discovery
HHS500+: with individual notices; fewer: annual log within 60 days of year end
MediaMore than 500 residents of a state or jurisdiction
Business associatesNotify the covered entity within 60 days of discovery

How it works

Step Requirement Section
Is it a breach? Any impermissible use or disclosure of PHI is presumed a breach unless a documented four-factor assessment shows a low probability of compromise 164.402
Is the PHI unsecured? PHI encrypted per HHS guidance (key not compromised) or properly destroyed is not unsecured 164.402
Notify individuals Without unreasonable delay, no later than 60 days after discovery 164.404
Notify the media If more than 500 residents of a state or jurisdiction are affected 164.406
Notify HHS 500+: at the same time as individuals; fewer: annual log 164.408
Business associates Notify the covered entity within 60 days 164.410
Law enforcement delay Notices may be delayed at law enforcement’s request 164.412
Burden of proof You must be able to show you complied 164.414

For what to put in the notices and how to run the assessment, see Notifying patients of a breach. If something just happened, go to You had a data breach.

Requirements explained

Frequently asked questions

What is unsecured PHI?

PHI not rendered unusable, unreadable or indecipherable to unauthorized people using methods HHS specifies — in practice, encryption meeting HHS guidance or proper destruction.

Who has the burden of proof after an incident?

The covered entity or business associate must be able to show that all required notices were made, or that the incident was not a breach (164.414).