HIPAA Breach Notification Rule
What the HIPAA Breach Notification Rule requires after a breach of unsecured PHI: the four-factor assessment, deadlines, and notices to patients, HHS, the media and covered entities.
HIPAA Breach Notification Rule at a glance
The HIPAA Breach Notification Rule (45 CFR 164.400–164.414) requires covered entities to notify affected individuals, HHS and, for breaches of more than 500 residents of a state, the media after a breach of unsecured protected health information. Individual notices are due without unreasonable delay and no later than 60 days after discovery. Business associates must notify the covered entity. PHI encrypted in line with HHS guidance, with the key and process not compromised, is not unsecured, so its loss may not require notification.
| Where | 45 CFR Part 164, Subpart D (164.400–164.414) |
|---|---|
| Trigger | Breach of unsecured PHI, presumed unless a four-factor assessment shows low probability of compromise |
| Individuals | Within 60 days of discovery |
| HHS | 500+: with individual notices; fewer: annual log within 60 days of year end |
| Media | More than 500 residents of a state or jurisdiction |
| Business associates | Notify the covered entity within 60 days of discovery |
How it works
| Step | Requirement | Section |
|---|---|---|
| Is it a breach? | Any impermissible use or disclosure of PHI is presumed a breach unless a documented four-factor assessment shows a low probability of compromise | 164.402 |
| Is the PHI unsecured? | PHI encrypted per HHS guidance (key not compromised) or properly destroyed is not unsecured | 164.402 |
| Notify individuals | Without unreasonable delay, no later than 60 days after discovery | 164.404 |
| Notify the media | If more than 500 residents of a state or jurisdiction are affected | 164.406 |
| Notify HHS | 500+: at the same time as individuals; fewer: annual log | 164.408 |
| Business associates | Notify the covered entity within 60 days | 164.410 |
| Law enforcement delay | Notices may be delayed at law enforcement’s request | 164.412 |
| Burden of proof | You must be able to show you complied | 164.414 |
For what to put in the notices and how to run the assessment, see Notifying patients of a breach. If something just happened, go to You had a data breach.
Requirements explained
Frequently asked questions
What is unsecured PHI?
PHI not rendered unusable, unreadable or indecipherable to unauthorized people using methods HHS specifies — in practice, encryption meeting HHS guidance or proper destruction.
Who has the burden of proof after an incident?
The covered entity or business associate must be able to show that all required notices were made, or that the incident was not a breach (164.414).