Breach Notification Rule
When protected health information is breached, HIPAA requires you to notify the affected patients, the government, and sometimes the media, all within set deadlines. The Breach Notification Rule spells out exactly who to tell, when, and how.
What is a Breach Notification Rule?
The Breach Notification Rule is the part of HIPAA that requires covered entities and their business associates to notify affected individuals, the Department of Health and Human Services, and in some cases the media when a breach of unsecured protected health information occurs. It sets clear deadlines and requirements for how those notifications must be made.
How It Works
Under the rule, once a breach of unsecured protected health information is discovered, a series of notification obligations begins. Affected individuals must be notified without unreasonable delay and no later than 60 days from discovery.
The scale of the breach determines who else must be told. For breaches affecting 500 or more individuals, the organization must also notify HHS and prominent media outlets within that same 60-day window. For breaches affecting fewer than 500 individuals, HHS is notified annually rather than immediately.
Importantly, HIPAA presumes that any impermissible use or disclosure of protected health information is a breach, unless the organization can demonstrate through a risk assessment that there is a low probability the information was compromised. Only unsecured, meaning unencrypted, information triggers these obligations.
Why It Matters
The Breach Notification Rule matters because failing to report a breach correctly and on time is itself a violation, separate from the breach. Late or missing notifications can bring significant penalties and lasting damage to patient trust. Understanding the rule in advance is what allows a practice to respond quickly and compliantly when an incident occurs, rather than scrambling under a tight deadline.
Related Terms
- What Counts as a HIPAA Breach?
- What Is ePHI?
- What Is the HIPAA Security Rule?
- What Is Incident Response?
For a complete guide, read our full article on what small clinics must do in the first 72 hours after a breach.
SecTec helps clinics prepare for and respond to breaches as part of our HIPAA compliance service.
Years Protecting Businesses
BAA Coverage on Healthcare Engagements