Notifying patients of a breach
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor assessment shows a low probability of compromise. Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery.
Notifying patients of a breach at a glance
Under HIPAA, an impermissible use or disclosure of protected health information is presumed to be a breach unless a documented assessment of four factors shows a low probability that the information was compromised. For a breach of unsecured PHI, the covered entity must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery, report to HHS, and for more than 500 residents of a state, notify the media.
| Rules | 45 CFR 164.402, 164.404, 164.406, 164.408, 164.410 |
|---|---|
| Deadline to notify individuals | Without unreasonable delay, no later than 60 days after discovery |
| HHS — 500 or more | At the same time as individual notices |
| HHS — fewer than 500 | Annual log, within 60 days after year end |
| Media | If more than 500 residents of a state or jurisdiction are affected |
| Encrypted PHI | Not unsecured — notification duties may not apply |
Is it a breach?
A breach is the acquisition, access, use or disclosure of PHI in a way the Privacy Rule does not permit, which compromises its security or privacy (164.402). Any impermissible use or disclosure is presumed to be a breach unless you can demonstrate a low probability that the PHI was compromised, based on a risk assessment of at least four factors:
- the nature and extent of the PHI involved, including identifiers and the likelihood of re-identification;
- the unauthorized person who used the PHI or received it;
- whether the PHI was actually acquired or viewed;
- the extent to which the risk has been mitigated.
Document this assessment either way. There are also narrow exceptions — for example, unintentional good-faith access by a workforce member acting within their authority.
Notification duties apply to unsecured PHI. PHI encrypted according to HHS guidance, with the key not compromised, is not unsecured.
Notifying individuals
If it is a breach of unsecured PHI, each affected individual must be notified without unreasonable delay and in no case later than 60 calendar days after discovery (164.404(b)). The notice must, to the extent possible, include:
- what happened, with the date of the breach and of its discovery;
- the types of information involved;
- steps individuals should take to protect themselves;
- what you are doing to investigate, mitigate harm and prevent recurrence;
- how to contact you.
Notice goes by first-class mail, or by email if the individual has agreed to electronic notice.
Beyond individual notices
Breaches also have to be reported to HHS: for 500 or more individuals, at the same time as you notify them; for fewer than 500, through a log submitted no later than 60 days after the end of the calendar year (164.408). Breaches affecting more than 500 residents of a state or jurisdiction also require notice to prominent media there (164.406). A business associate must notify you without unreasonable delay and within 60 days of discovering a breach (164.410). Check the HHS Breach Notification Rule page for the current reporting process.
Guides
- HIPAA compliance →What HIPAA compliance actually means for a small practice or health tech company, what it consists of, and what it is not.
- HIPAA compliance checklist →A practical HIPAA checklist for small practices and business associates, with each item linked to the rule behind it — not a list of things to buy.
- HIPAA penalties →Current HIPAA civil penalty amounts by tier after the 2025 inflation adjustment, annual caps, criminal penalties, and what determines the amount.
- HIPAA training →What HIPAA training has to cover, who needs it, how to structure a program for a small practice, and how to judge an online course.
- HIPAA violation →What counts as a HIPAA violation, common examples in small practices and health tech companies, how violations differ from breaches, and what happens next.
- What is HIPAA? →A plain-English overview of HIPAA: what it protects, who it applies to, the three main rules, patients' rights and how it is enforced.
Scenarios
Related requirements
Frequently asked questions
What are the four factors in a HIPAA breach risk assessment?
The nature and extent of the PHI, who received or used it, whether it was actually acquired or viewed, and how far the risk has been mitigated (45 CFR 164.402).
How long do I have to notify patients of a breach?
Without unreasonable delay and no later than 60 calendar days after discovering the breach.
Is a misdirected email a HIPAA breach?
It is presumed to be one unless your documented four-factor assessment shows a low probability that the PHI was compromised.