← Back to blog

HIPAA Breach Notification Requirements: A Compliance Guide

August 8, 2026
HIPAA Breach Notification Requirements: A Compliance Guide

Under the HIPAA Breach Notification Rule — codified at 45 C.F.R. §§164.400–414 and enacted through the HITECH Act — covered entities must notify affected individuals, the HHS Secretary (via OCR), and in some cases the media following a breach of unsecured protected health information (PHI). Business associates have a parallel obligation to notify the covered entity. The governing deadline is 60 calendar days from the date of discovery, though smaller breaches affecting fewer than 500 individuals may be reported to OCR on an annual basis rather than immediately.

Your immediate action checklist after discovery:

  • Preserve evidence. Secure logs, access records, and any forensic data before they are overwritten or lost.
  • Document the discovery date. The 60-day clock starts the moment any workforce member (other than the wrongdoer) knew or should have known about the incident.
  • Begin the four-factor risk assessment. Evaluate the nature and extent of PHI involved, who accessed it, whether it was actually acquired or viewed, and the degree to which risk has been mitigated.
  • Notify your business associate or covered entity. Per your contractual obligations and 45 C.F.R. §164.410, this must happen without unreasonable delay.
  • Prepare individual notices. Draft written notifications for affected individuals using first-class mail or email (with prior agreement).
  • Submit the OCR breach report. Use the OCR breach-reporting portal for breaches affecting 500 or more individuals within 60 days; log smaller breaches for annual submission.

Key Takeaways

HIPAA's Breach Notification Rule requires covered entities and business associates to notify affected individuals and OCR within 60 days of discovery, with media notice required for breaches affecting more than 500 residents of a single state, and validated encryption or secure destruction can exempt an incident from notification entirely.

PointDetails
60-day discovery clockNotifications to individuals and OCR are due within 60 calendar days of the date any workforce member knew or should have known.
Annual reporting for small breachesBreaches affecting fewer than 500 individuals may be logged and reported to OCR annually, no later than 60 days after the end of the calendar year in which the breaches were discovered.
Encryption exemption requires documentationValidated encryption (NIST/FIPS standards) and secure destruction exempt PHI from notification, but only with key management logs and destruction certificates to prove it.
Business associate 60-day ceilingBAs must notify the covered entity without unreasonable delay; BAAs should set internal deadlines of 3–7 days to preserve the covered entity's response window.
Signalpgx supports the burden of proofSignalpgx's encryption-at-rest, audit trails, and role-based access controls provide the documentation infrastructure covered entities and labs need to demonstrate compliance during OCR review.

Table of Contents

What counts as a breach under HIPAA, and when is it "discovered"?

The Breach Notification Rule defines a breach as the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the HIPAA Privacy Rule (45 C.F.R. §164.402). The rule establishes a presumption: any impermissible use or disclosure is treated as a breach unless the covered entity or business associate can demonstrate a low probability that the PHI has been compromised. That demonstration requires completing the four-factor risk assessment.

The four factors are: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the identity of the unauthorized person who used or received the PHI; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated. A clear, time-stamped record of this assessment is your strongest defense in an OCR investigation.

Discovery rule: A breach is considered "discovered" on the first day it is known — or would have been known through the exercise of reasonable diligence — by any workforce member of the covered entity or business associate other than the person who committed the breach. The 60-day notification clock starts on that date, not the date an investigation concludes.

Practical example: A hospital's IT team detects unusual access to an EHR system on March 5. Even if the forensic investigation is not completed until March 20, the discovery date is March 5. Individual notices and the OCR report must be sent no later than May 4 for a breach affecting 500 or more individuals.


When PHI is "unsecured" and how encryption can exempt you from notification

"Unsecured PHI" is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through methods specified in HHS guidance. Two categories of implementation qualify for the exemption:

  • Validated encryption. PHI encrypted using a process that meets the standards referenced in HHS guidance — for data at rest, NIST SP 800-111; for data in motion, FIPS 140-2 validated modules. The encryption must be properly implemented, meaning the decryption key is not stored with or accessible alongside the encrypted data.
  • Secure destruction. Paper PHI shredded or destroyed so that it cannot be reconstructed; electronic media cleared, purged, or destroyed per NIST SP 800-88 guidelines.

If either method is properly applied, the incident is not subject to breach notification obligations under the HITECH-based Breach Notification Rule. "Properly applied" is the operative phrase — deploying an encryption algorithm without managing keys correctly does not qualify.

Documentation you must maintain to prove the exemption:

  • Encryption certificates and algorithm specifications for each system holding PHI
  • Key management logs showing the decryption key was stored separately from the encrypted data
  • Destruction certificates with date, method, and the identity of the person performing destruction
  • Validation records confirming the encryption implementation meets the referenced NIST/FIPS standards

Pro Tip: Design your evidence-capture process before an incident occurs. Maintain a living encryption inventory that maps each data store to its encryption standard, key custodian, and last validation date. When OCR asks whether PHI was secured at the time of the incident, you need a dated record, not a verbal assurance.


Who you must notify and when: individuals, OCR, and the media

The notification obligations defined in federal regulations apply to three audiences, each with distinct timing rules.

Individual notice must be provided without unreasonable delay and no later than 60 calendar days after discovery. The notice must be written and sent by first-class mail to the individual's last known address, or by email if the individual has agreed to electronic communications.

Notice to the HHS Secretary (OCR) follows a two-track system based on the number of individuals affected:

Media notice is required when a breach affects more than 500 residents of a single state or jurisdiction. The notice must be sent to prominent media outlets serving that state or jurisdiction, using the same 60-day deadline as individual notices.

Breach SizeOCR Reporting DeadlineMedia Notice Required?
≥500 individualsWithin 60 days of discoveryYes, if ≥500 in one state/jurisdiction
<500 individualsNo later than 60 days after end of calendar yearNo

For breaches affecting fewer than 500 individuals, covered entities may maintain a breach log and submit annual reports to OCR no later than 60 days after the close of the calendar year in which the breaches were discovered. A breach discovered in November 2025, for example, must be reported to OCR no later than March 1, 2026.


What individual notices must include and how to deliver them

The regulatory requirements for individual notification specify both the content of the notice and the acceptable delivery methods. A compliant notice must include:

  • A brief description of what happened, including the date of the breach and the date of discovery (if known)
  • A description of the types of unsecured PHI involved (e.g., name, Social Security number, diagnosis codes, medication history, genomic data)
  • Steps the individual should take to protect themselves from potential harm (credit monitoring, fraud alerts, contacting their insurer)
  • A brief description of what the covered entity is doing to investigate the breach, mitigate harm, and prevent future incidents
  • Contact information: a toll-free telephone number, email address, website, or postal address where individuals can ask questions or get additional information

Delivery methods:

  • First-class mail to the individual's last known address is the default method.
  • Email is permitted if the individual has previously agreed to receive communications electronically.
  • Substitute notice applies when contact information is insufficient or out of date for 10 or more individuals. The covered entity must post a conspicuous notice on its website for at least 90 days and provide a toll-free number, or notify major print or broadcast media in the affected area.
  • Fewer than 10 individuals with insufficient contact information: alternative written notice, telephone, or other means are acceptable.
  • Urgent situations: when the breach involves imminent misuse of PHI, telephone or other expedited methods should supplement the written notice.

A short template for the opening paragraph of an individual notice: "On [date], [Organization Name] discovered that your protected health information may have been accessed without authorization. The information involved included [types of PHI]. We are writing to inform you of this incident and the steps we are taking to protect your information."


How to report breaches to HHS/OCR and what to submit

The OCR breach-reporting process differs based on breach size, and the documentation you assemble before submitting directly affects how smoothly an OCR review proceeds.

Step-by-step for breaches affecting 500 or more individuals:

  1. Access the OCR breach-reporting portal and complete the electronic breach report form.
  2. Enter the discovery date, the date notifications were sent to individuals, the number of individuals affected, and the type of PHI involved.
  3. Describe the type of breach (hacking/IT incident, unauthorized access, theft, improper disposal, etc.) and the safeguards in place at the time.
  4. Submit the report within 60 calendar days of discovery.
  5. Retain a copy of the submitted report and the confirmation receipt from OCR.

For breaches affecting fewer than 500 individuals:

  • Maintain an internal breach log throughout the calendar year, recording each incident's discovery date, number of individuals affected, type of PHI, and corrective actions taken.
  • Submit all logged breaches to OCR annually, no later than 60 days after the end of the calendar year in which they were discovered.

Documentation to retain alongside your OCR submission:

  • Dated notes from the initial discovery and escalation
  • The completed four-factor risk assessment with timestamps
  • Copies of all individual notices sent, with proof of mailing or email delivery confirmation
  • Copies of any media notices
  • Internal approvals and sign-offs from legal counsel and leadership
  • Any communications with law enforcement, if applicable

What business associates must do after discovering a breach

A business associate's notification obligation runs to the covered entity, not directly to affected individuals (unless the covered entity delegates that responsibility by contract). Under 45 C.F.R. §164.410, the business associate must notify the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery.

Key obligations for business associates:

  • Notify the covered entity promptly. The 60-day deadline is a ceiling, not a target. OCR treats "without unreasonable delay" strictly, and a business associate that waits 55 days to notify the covered entity leaves that entity almost no time to meet its own obligations.
  • Provide available identifying information. To the extent possible, the business associate must identify the individuals whose PHI was involved and provide any other information the covered entity needs to complete its individual notices.
  • Apply the same discovery rule. The BA's clock starts when any of its workforce members (other than the wrongdoer) knew or should have known about the incident.
  • Follow contractual terms. Business associate agreements (BAAs) frequently specify shorter internal notification windows. A best-practice BAA sets an internal BA-to-covered-entity notification deadline of 3–7 days, giving the covered entity adequate time to investigate and prepare individual notices before the 60-day deadline expires.
  • Delegation option. A covered entity may contractually delegate the task of sending individual notices to the business associate. If that delegation exists, the BA must send those notices on behalf of the covered entity and provide documentation of delivery.

When law enforcement can delay required notifications

Law enforcement agencies may request that a covered entity or business associate delay breach notifications when notification could impede a criminal investigation or cause damage to national security. The process and documentation requirements are specific.

  • Written request: If law enforcement provides a written statement specifying the delay period, the covered entity must delay notification for that stated period.
  • Oral request: If the request is oral, the covered entity must document the identity of the law enforcement official, the date of the request, and the basis for the delay. The oral delay is limited to 30 days unless a written statement follows.
  • Hold notifications in escrow. Prepare all required notices (individual, media, OCR) but do not send them until the delay period ends or law enforcement confirms that notification will no longer impede the investigation.
  • Record when the delay ends. Document the date the delay period expired and the date notifications were sent, and retain that record alongside the law enforcement communication.
  • Scope of the delay. The delay applies only to the notifications themselves, not to the internal investigation or risk assessment, which should continue uninterrupted.

Recordkeeping, burden of proof, and administrative requirements

The administrative requirements under 45 C.F.R. §164.414 place the burden of proof squarely on the covered entity or business associate. If OCR investigates, you must demonstrate either that required notifications were sent or that the impermissible use or disclosure did not constitute a breach because the risk assessment showed a low probability of PHI compromise.

Records to maintain for at least six years (consistent with HIPAA's general documentation retention standard):

  • Breach log. A running record of all incidents assessed, including those determined not to be reportable breaches, with the rationale documented.
  • Four-factor risk assessments. Time-stamped, signed, and specific to each incident.
  • Evidence of notices sent. Proof of mailing (USPS tracking or certified mail receipts), email delivery confirmations, website posting screenshots with dates, and media notice confirmations.
  • Forensic and investigation reports. Technical findings that support the risk assessment conclusions.
  • Communications with law enforcement. Written requests and your documented responses.
  • OCR submissions. Copies of all breach reports submitted, with confirmation receipts.

Audit-ready documentation means each record is dated, attributed to a named individual, and stored in a system that preserves version history. A folder of undated notes will not satisfy OCR's evidentiary standard. Treat your breach documentation the same way you treat a legal file: organized, indexed, and retrievable within hours.


Your operational checklist for submitting breach notices to HHS/OCR

Translating the regulatory requirements into a repeatable workflow reduces the risk of missed deadlines and incomplete submissions.

Immediate steps (first 24–72 hours after discovery):

  1. Preserve all relevant logs, access records, and system states before routine processes overwrite them.
  2. Document the discovery date and the name of the workforce member who first identified the incident.
  3. Notify your HIPAA Privacy Officer, Security Officer, and legal counsel.
  4. Begin the four-factor risk assessment; assign a named owner and a completion deadline.
  5. Notify your covered entity or business associate per your BAA terms.

Preparation phase (days 3–30):

  • Complete and sign the four-factor risk assessment.
  • Determine the number of individuals affected and whether the 500-individual thresholds apply.
  • Draft individual notices using the required content elements.
  • Identify individuals with insufficient contact information and plan substitute notice if needed.
  • Engage legal counsel and communications/PR if the breach is large or likely to attract media attention.
  • Prepare the OCR breach report form with all required fields completed.

Execution and submission (by day 60):

  1. Send individual notices by first-class mail (or email with prior consent).
  2. Send media notices if the breach affects more than 500 residents of a state or jurisdiction.
  3. Submit the OCR breach report via the HHS breach-reporting portal.
  4. Retain confirmation of all submissions and delivery records.
  5. Update your breach log with final counts, dates, and outcomes.

Internal sign-off: Individual notices should be reviewed and approved by your Privacy Officer and legal counsel before distribution. For large breaches, executive leadership sign-off is standard practice and demonstrates organizational accountability in any subsequent OCR review.


Prevention and mitigation controls that reduce notification risk

The most effective way to manage breach notification obligations is to reduce the number of incidents that qualify as notifiable breaches. HHS guidance identifies two controls that can exempt an incident entirely: validated encryption and secure destruction. Everything else reduces the probability of a breach occurring or limits its scope.

ControlNotification Exemption?Primary Benefit
Validated encryption (NIST SP 800-111 / FIPS 140-2)Yes, if properly implementedRenders PHI unusable to unauthorized parties
Secure destruction (NIST SP 800-88)Yes, for destroyed media/paperEliminates residual data exposure
Role-based access controlsNoLimits who can access PHI, reducing breach scope
Multi-factor authentication (MFA)NoReduces unauthorized access incidents
Least-privilege access policiesNoMinimizes data exposed in any single incident
Regular key-management auditsNoMaintains encryption validity over time
Workforce training and phishing simulationsNoReduces human-error incidents

Diagram of HIPAA breach controls and exemption status

Encryption is only as strong as its key management. A covered entity that encrypts PHI but stores the decryption key in the same system or folder cannot claim the exemption. Key custodianship, rotation schedules, and access logs for the key management system are all part of the implementation record OCR will examine.

For laboratories handling genomic or genetic data, the risk profile is compounded. California's AB 825 expanded state breach-notification law to classify genetic data as personal information, triggering separate state-level notification obligations that run parallel to HIPAA. Labs operating across multiple states must map each state's genetic-data breach laws alongside the federal rule, since state requirements can specify shorter timelines or additional notice content.

Pro Tip: Build your evidence-capture architecture around the four-factor risk assessment. For each data store containing PHI, document in advance: the encryption standard in use, the key custodian, the last validation date, and the destruction protocol. When an incident occurs, you can complete the risk assessment in hours rather than days, and the documentation already exists to support a low-probability-of-compromise finding if the facts warrant it.


The compliance leader's real challenge is documentation, not speed

Speed matters in breach response, but the compliance leaders who fare best in OCR investigations are not the ones who notified fastest. They are the ones who documented most thoroughly. The 60-day deadline is achievable for almost any organization with a basic incident-response plan. What separates a resolved OCR inquiry from a prolonged enforcement action is the quality of the paper trail.

The four-factor risk assessment is where most teams underinvest. It gets completed quickly, often by a single person, and filed without independent review. OCR examiners read these assessments closely. A risk assessment that reaches a "low probability of compromise" conclusion without specific evidence for each factor, or without a timestamp that predates the notification decision, will draw scrutiny. The assessment should read like a legal brief: factual, specific, and signed by the person who conducted it.

Cross-functional tabletop exercises are the single most effective preparation tool available to compliance teams. Running a simulated breach with legal, IT, operations, and communications in the same room reveals gaps in your BAA notification chains, your substitute-notice procedures, and your OCR submission workflow before an actual incident exposes them. Most organizations run these exercises annually at best; quarterly is more defensible given the pace of threat evolution.

The other underappreciated risk is the business associate chain. A covered entity can have a flawless internal response and still miss the 60-day deadline because a BA delayed notification for three weeks while conducting its own investigation. Your BAA should specify a hard internal deadline, not just reference the regulatory ceiling. Treat the BA notification clause the same way you treat a service-level agreement: it needs a number, not a principle.


The compliance leader's real challenge is documentation, not speed — overview diagram

Signalpgx supports your lab's HIPAA compliance posture

Labs handling pharmacogenomic data face a specific compliance burden: genetic and genomic PHI is among the most sensitive data HIPAA protects, and state-level laws in jurisdictions like California impose additional breach-notification requirements on top of the federal rule. Signalpgx is built with that burden in mind.

Signalpgx

The platform's security and compliance architecture includes encryption in transit and at rest, role-based access controls, and a complete audit trail for every report generated, reviewed, and delivered. Those controls are not incidental features. They are the documentation infrastructure your team needs to support a low-probability-of-compromise finding or to demonstrate that PHI was secured at the time of an incident. The audit trail captures who accessed what, when, and from which system, giving your Privacy Officer the evidence base for a defensible four-factor risk assessment.

For labs evaluating a white-label PGx reporting platform, Signalpgx's compliance-first design means your reporting infrastructure does not create a separate compliance liability. To discuss your lab's specific requirements or to see the platform's security controls in detail, contact the Signalpgx team to schedule a demo.

This article provides general compliance information and does not constitute legal advice. Verify current regulatory requirements with the HHS/OCR primary sources cited below or consult qualified legal counsel for your organization's specific circumstances.


Sources

The following primary sources are the authoritative references for HIPAA breach notification compliance. Each is appropriate to cite in internal reports, policy documents, and OCR submissions.

State-law note: HIPAA sets the federal floor, but state breach-notification laws frequently impose stricter or additional requirements, particularly for genetic and genomic data. Labs operating in multiple states should map each state's specific rules against the federal baseline. California's treatment of genetic data as personal information under its breach law is one example; other states have enacted or are considering similar provisions. Consult state-specific legal counsel or your state's attorney general guidance for the current requirements in each jurisdiction where your lab operates.