The HIPAA Breach Notification Rule: Timelines and Who You Must Tell
A breach is presumed guilty until you prove otherwise, and the notification clock starts the day anyone on your team should have known. Here is the rule, with the actual deadlines.

What counts as a breach
A breach is the acquisition, access, use, or disclosure of patient information in a way the Privacy Rule does not allow — and it is presumed to be a breach unless you can show otherwise. That presumption matters. The starting position is “this is a breach” until you prove it is not.
The way out is a written four-factor risk assessment showing a low probability the information was compromised. The four factors: what kind of information was involved and how identifiable it is, who received it, whether it was actually acquired or viewed, and how far you went to mitigate the risk. A fax sent to the wrong number but immediately confirmed destroyed by the recipient is a very different event from a stolen unencrypted laptop — but both start as presumed breaches, and both need the analysis documented.
Common real-world breaches in small clinics: ransomware encrypting the server, a laptop or phone with patient data stolen from a car, email sent to the wrong patient, a former employee whose access was never turned off, a misconfigured cloud folder anyone could open.
Who you must notify, and when
Once you determine a breach occurred, the clock is running. “Discovery” means the day anyone in your workforce — not just the owner — knew or should have known about it.
- Affected individuals: notify each person in writing, without unreasonable delay, and no later than 60 days after discovery. The notice must describe what happened, what types of information were involved, what you are doing about it, and how they can reach you with questions.
- HHS: for breaches affecting fewer than 500 people, you may log them and report once a year, within 60 days after the end of the calendar year. For breaches affecting 500 or more, notify HHS at the same time you notify individuals.
- The media: if a breach affects more than 500 residents of a state or jurisdiction, you must also notify a prominent media outlet serving that area. A Coastal Bend dental practice was hit by ransomware recently — breaches this size become local news, and the rule expects you to get ahead of it rather than hide from it.
- Your business associate notifies you: if a vendor discovers the breach, they must notify you without unreasonable delay and no later than 60 days. Your contract with them — the BAA — should spell out exactly how.
The mistakes that make breaches worse
Waiting to “see how bad it is.” The 60-day clock does not pause while you investigate. Notify on time with what you know; you can supplement later.
No written risk assessment. If you decide something was not a breach, document the four-factor analysis. “We decided it was fine” with nothing written down will not survive an audit.
Forgetting the workforce. Discovery starts when any employee should have known — including the temp at the front desk who saw the weird email and said nothing for two weeks.
No incident response plan. The worst time to figure out who calls whom is during the incident. A one-page plan — who decides, who notifies, who talks to IT — turns panic into process.
Documenting the four-factor analysis
When you decide an incident was not a breach, the analysis is the whole ballgame. Write it down while the facts are fresh: one, describe the information involved and how identifiable it was — a full chart versus an appointment time with no name attached are different universes. Two, name the unauthorized recipient — a trusted business associate who immediately deleted it is different from an unknown third party. Three, state whether the information was actually acquired or viewed, with the evidence — “recipient confirmed by phone they deleted it unread” beats “probably fine.” Four, list everything you did to mitigate the risk. Date it, sign it, file it with your incident records. If HHS ever asks, this page is your defense.
What to do Monday morning
Write the one-page incident response plan before you need it: who is in charge, who calls the IT provider, who drafts notifications, and where the BAA contact list lives. Then ask your IT provider one question: “If ransomware hit us tonight, what is the exact first step?” If the answer is vague, that is the problem to fix first.
Keep a simple incident log even when nothing qualifies as a breach — date, what happened, what you decided, and where the analysis lives. The clinics that handle breaches well are the ones that practiced the paperwork on the small stuff.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
What is the deadline for notifying patients after a breach?
Without unreasonable delay, and no later than 60 days after the breach was discovered. Discovery counts from when anyone in your workforce knew or should have known — not when the owner found out.
Do we have to notify HHS about every breach?
Yes, but the timing differs. Breaches affecting fewer than 500 individuals can be logged and reported to HHS once a year, within 60 days after the end of the calendar year. Breaches of 500 or more must be reported to HHS at the same time you notify individuals.
When does the media have to be notified?
When a breach affects more than 500 residents of a state or jurisdiction, you must notify a prominent media outlet serving that area, in addition to notifying individuals and HHS.
Is every impermissible disclosure automatically a breach?
It is presumed to be a breach unless you demonstrate, through a documented four-factor risk assessment, that there is a low probability the information was compromised. The burden of proof is on you.
What should the patient notification letter include?
A description of what happened, the types of information involved, steps individuals can take to protect themselves, what you are doing about it, and contact information for questions. Keep the language plain — no legalese.