glossary

Breach Notification Rule

When protected health information is breached, HIPAA requires you to notify the affected patients, the government, and sometimes the media, all within set deadlines. The Breach Notification Rule spells out exactly who to tell, when, and how.

What is a Breach Notification Rule?

The Breach Notification Rule is the part of HIPAA that requires covered entities and their business associates to notify affected individuals, the Department of Health and Human Services, and in some cases the media when a breach of unsecured protected health information occurs. It sets clear deadlines and requirements for how those notifications must be made.

How It Works

Under the rule, once a breach of unsecured protected health information is discovered, a series of notification obligations begins. Affected individuals must be notified without unreasonable delay and no later than 60 days from discovery.

The scale of the breach determines who else must be told. For breaches affecting 500 or more individuals, the organization must also notify HHS and prominent media outlets within that same 60-day window. For breaches affecting fewer than 500 individuals, HHS is notified annually rather than immediately.

Importantly, HIPAA presumes that any impermissible use or disclosure of protected health information is a breach, unless the organization can demonstrate through a risk assessment that there is a low probability the information was compromised. Only unsecured, meaning unencrypted, information triggers these obligations.

Why It Matters

The Breach Notification Rule matters because failing to report a breach correctly and on time is itself a violation, separate from the breach. Late or missing notifications can bring significant penalties and lasting damage to patient trust. Understanding the rule in advance is what allows a practice to respond quickly and compliantly when an incident occurs, rather than scrambling under a tight deadline.

Related Terms

For a complete guide, read our full article on what small clinics must do in the first 72 hours after a breach.

SecTec helps clinics prepare for and respond to breaches as part of our HIPAA compliance service.

Rated 5 out of 5
15

Years Protecting Businesses

500+
Clients Trust SecTec
100%
Projects

BAA Coverage on Healthcare Engagements

Zero
HIPAA Penalties Under Active Management