Individuals, HHS (for 500+), and media must be notified without unreasonable delay and no later than 60 days after discovery.
When 500 or more individuals (or 500+ residents of a state) are affected, prompt HHS reporting and a media notice are required.
| Recipient | Deadline | Notes |
|---|---|---|
| Affected individuals | Without unreasonable delay; no later than 60 days after discovery | Clock starts at discovery, not at completion of the investigation. |
| HHS, 500 or more individuals affected | Without unreasonable delay; no later than 60 days after discovery | Submit electronically via the HHS breach portal. |
| HHS, fewer than 500 individuals affected | Within 60 days after the end of the calendar year in which breaches occurred | Report smaller breaches in aggregate on the annual log submission. |
| Media, 500+ residents of a state or jurisdiction affected | Without unreasonable delay; no later than 60 days after discovery | Notify prominent media outlets serving the affected state or jurisdiction. |
| Business associate to covered entity | Without unreasonable delay; no later than 60 days after BA discovery | BA must provide identities of affected individuals (if known) and details to enable CE notifications. BAA may specify a shorter window. |
- Incident log and forensics summary: date of discovery, systems and data involved, scope of unauthorized access.
- Risk assessment: nature and extent of PHI involved, identity of the unauthorized person, whether PHI was actually acquired or viewed, and mitigation actions taken.
- Affected individual roster: names, last-known mailing addresses, and email addresses (if applicable); count by state and jurisdiction.
- BAA details: if a business associate is involved, BAA terms, BA contact points, and the BA's notice to the covered entity.
- Notice templates: individual notice letter, media statement, and HHS submission checklist. See Templates & Resources below.
- Individuals: First-class mail to last-known address. Email is permitted if the individual previously agreed to receive communications electronically.
- Substitute notice, more than 10 individuals with insufficient contact info: Post a conspicuous notice on the organization's website for at least 90 days, or provide notice to major print or broadcast media in the affected area.
- Substitute notice, 10 or fewer individuals with insufficient contact info: Alternative written notice, telephone, or other means.
- Media: Press release or equivalent to prominent media outlets serving the affected state or jurisdiction; required when 500+ residents are affected.
- HHS: Electronic submission via the HHS breach portal. Large breaches (500+) are reported promptly; smaller breaches are reported on the annual log.
- All individual notices must include a toll-free contact number active for at least 90 days, steps individuals can take, and, if applicable, credit monitoring or other services being offered.
- Determination recordsRisk assessment, investigation reports, and the final breach/not-breach determination with supporting rationale.
- Notices and proofsCopies of all notices sent (individual, HHS submission confirmation, media release) and delivery proofs or logs.
- Substitute notice recordsRecord of substitute notice actions taken (website postings, media outlets notified).
- Inquiry and remediation logsCall center or inquiry logs and remediation or corrective action plans.
- RetentionAt least 6 years from the date of creation or last effective date, consistent with HIPAA's general documentation standard.
Common traps
FAQs
What is a "breach of unsecured PHI"?
An impermissible acquisition, access, use, or disclosure of PHI that compromises the privacy or security of the information, unless the covered entity or BA demonstrates that there is a low probability the PHI has been compromised based on a four-factor risk assessment, or that another exception applies (such as the encryption safe harbor).
Who must be notified?
Always: affected individuals and HHS. Additionally: prominent media outlets if 500 or more residents of a single state or jurisdiction are affected. If a business associate caused or discovered the breach, the BA must notify the covered entity so the CE can fulfill its notice obligations.
What are the penalties for late or missing notification?
Civil monetary penalties under HIPAA/HITECH are tiered by culpability, from situations where the entity did not know and could not have known, up to willful neglect. Annual caps apply per violation category. Criminal penalties are possible in cases of knowing misuse of PHI. OCR corrective action plans are common outcomes of enforcement investigations.
Does this apply to self-insured employer health plans?
Yes. A self-insured group health plan is a covered entity under HIPAA. The employer acting as plan sponsor has obligations under the plan's HIPAA policies. If the plan uses a TPA, the TPA is likely a business associate; ensure the BAA addresses breach notification timelines and cooperation.
- HHS: HIPAA Breach Notification Rule: overview of requirements, timelines, and covered entity obligations.
- HHS: Guidance on Unsecured PHI: encryption/destruction safe harbor and risk assessment methodology.
Report to HHS through the official OCR portal, and use the drop-in starters below for the individual notice letter, the media statement, and your HHS submission checklist. Tailor each to the specific incident and have counsel review before sending.
- HHS OCR Breach Portal: the official site for submitting breach reports to HHS (large breaches promptly; smaller breaches on the annual log).
- HHS: Breach Reporting instructions: what information the portal requires and how the 500+ vs. under-500 timing works.
Individual notice letter (drop-in starter; must contain all five required elements):
We are writing to notify you of a data security incident that may have involved some of your protected health information. What happened: On [discovery date], we discovered that [brief description of what happened and the date/range of the breach]. Information involved: The information that may have been involved included [types of PHI, e.g., name, date of birth, Social Security number, member ID, claims/diagnosis information]. What you can do: [Steps the individual should take to protect themselves, e.g., review statements, place a fraud alert, monitor credit; include any credit-monitoring offer]. What we are doing: [Investigation, mitigation, and steps to prevent recurrence]. For more information: Please contact us at [toll-free number active at least 90 days], [email], or [postal address].
Sincerely, [Plan/Plan Sponsor name]"
Media statement (drop-in starter; required when 500+ residents of one state/jurisdiction are affected):
HHS submission checklist:
- Covered entity and (if applicable) business associate contact information.
- Dates of the breach and of discovery.
- Approximate number of individuals affected (and, for the portal, the type of breach and location of breached information).
- Types of PHI involved and a brief description of what happened.
- Safeguards in place before the breach and actions taken in response (investigation, mitigation, notification, prevention).
- Whether the 500+ (prompt) or under-500 (annual log) timing applies.
Note: HIPAA notice content is federally required, but many states impose additional or stricter requirements (shorter deadlines, notice to the state attorney general, specific letter content). Confirm state-law obligations before finalizing any notice.