hipaa.systems
Breach Notification Rule · 45 CFR 164.402, 164.404

Notifying patients of a breach

An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor assessment shows a low probability of compromise. Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery.

Checked 2026-10-05Sources 4

Notifying patients of a breach at a glance

Under HIPAA, an impermissible use or disclosure of protected health information is presumed to be a breach unless a documented assessment of four factors shows a low probability that the information was compromised. For a breach of unsecured PHI, the covered entity must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery, report to HHS, and for more than 500 residents of a state, notify the media.

Rules45 CFR 164.402, 164.404, 164.406, 164.408, 164.410
Deadline to notify individualsWithout unreasonable delay, no later than 60 days after discovery
HHS — 500 or moreAt the same time as individual notices
HHS — fewer than 500Annual log, within 60 days after year end
MediaIf more than 500 residents of a state or jurisdiction are affected
Encrypted PHINot unsecured — notification duties may not apply

Is it a breach?

A breach is the acquisition, access, use or disclosure of PHI in a way the Privacy Rule does not permit, which compromises its security or privacy (164.402). Any impermissible use or disclosure is presumed to be a breach unless you can demonstrate a low probability that the PHI was compromised, based on a risk assessment of at least four factors:

  1. the nature and extent of the PHI involved, including identifiers and the likelihood of re-identification;
  2. the unauthorized person who used the PHI or received it;
  3. whether the PHI was actually acquired or viewed;
  4. the extent to which the risk has been mitigated.

Document this assessment either way. There are also narrow exceptions — for example, unintentional good-faith access by a workforce member acting within their authority.

Notification duties apply to unsecured PHI. PHI encrypted according to HHS guidance, with the key not compromised, is not unsecured.

Notifying individuals

If it is a breach of unsecured PHI, each affected individual must be notified without unreasonable delay and in no case later than 60 calendar days after discovery (164.404(b)). The notice must, to the extent possible, include:

  • what happened, with the date of the breach and of its discovery;
  • the types of information involved;
  • steps individuals should take to protect themselves;
  • what you are doing to investigate, mitigate harm and prevent recurrence;
  • how to contact you.

Notice goes by first-class mail, or by email if the individual has agreed to electronic notice.

Beyond individual notices

Breaches also have to be reported to HHS: for 500 or more individuals, at the same time as you notify them; for fewer than 500, through a log submitted no later than 60 days after the end of the calendar year (164.408). Breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media there (164.406). A business associate must notify you without unreasonable delay and within 60 days of discovering a breach (164.410). Check the HHS Breach Notification Rule page for the current reporting process.

Guides

Scenarios

Frequently asked questions

What are the four factors in a HIPAA breach risk assessment?

The nature and extent of the PHI, who received or used it, whether it was actually acquired or viewed, and how far the risk has been mitigated (45 CFR 164.402).

How long do I have to notify patients of a breach?

Without unreasonable delay and no later than 60 calendar days after discovering the breach.

Is a misdirected email a HIPAA breach?

It is presumed to be one unless your documented four-factor assessment shows a low probability that the PHI was compromised.