You've just discovered suspicious network activity. Or worse, you've confirmed unauthorized access. The clock is ticking, and you're facing decisions that will determine your regulatory exposure, notification obligations, and your organization's reputation.
Let's walk through the decision points that matter.
The Decision You're Facing
When you detect a potential security incident, you must decide whether the event constitutes a reportable breach under the Breach Notification Rule. This isn't a simple yes-or-no question. It's a series of assessments, each with specific regulatory triggers and timelines.
Your primary decision branches:
- Does this incident involve Protected Health Information (PHI)?
- Was there an impermissible use or disclosure?
- Does the breach exception apply (low probability of compromise)?
- How many individuals are affected?
- What notification timeline applies?
Each answer determines your next step and your regulatory obligations.
Key Factors That Affect Your Choice
Access vs. Acquisition
The Breach Notification Rule distinguishes between unauthorized access and actual data exfiltration. For example, when North Carolina rehabilitation practices discovered that a third party used stolen credentials to access their vendor's system, they faced this exact question. The vendor confirmed that files containing patient names, Social Security numbers, and health information were copied, not just viewed.
If you can demonstrate that an unauthorized actor accessed systems but did not acquire PHI, you may avoid breach notification requirements. But proving non-acquisition requires forensic evidence, not assumptions.
The Four-Factor Risk Assessment
When you cannot prove a breach exception applies, you must conduct a risk assessment examining:
- The nature and extent of PHI involved
- The unauthorized person who accessed or received the PHI
- Whether PHI was actually acquired or viewed
- The extent to which risk has been mitigated
Atrium Centers discovered unauthorized access affecting files containing patient and employee data. They're still conducting their file review months later because this assessment takes time. You cannot shortcut this process.
Business Associate Involvement
If the breach originated with a Business Associate, you're still responsible for notification, but the timeline and responsibility shift. Your Business Associate Agreement should specify notification timelines, but the Breach Notification Rule gives Business Associates only 60 days to notify you after discovery.
Path A: Immediate Notification (Fewer Than 500 Individuals)
Choose this path when:
- Your risk assessment confirms a reportable breach
- Fewer than 500 individuals are affected
- You've completed your investigation and know who's impacted
Your obligations: Notify each affected individual within 60 days of discovering the breach. No media notice is required. File a report with the Office for Civil Rights (OCR) within 60 days of the end of the calendar year in which the breach occurred.
What this looks like: Rockwood Retirement Communities identified suspicious activity and engaged forensic experts, completed their data review, verified contact information, and mailed notification letters within the required timeframe.
Critical steps:
- Document your discovery date precisely
- Complete your risk assessment before notification
- Verify addresses and contact methods
- Offer credit monitoring when Social Security numbers are involved
- Prepare for OCR questions even though you're not reporting immediately
Path B: Expedited Notification (500 or More Individuals)
Choose this path when:
- Your risk assessment confirms a reportable breach
- 500 or more individuals are affected
- The breach affects residents of a single state or multiple states
Your obligations: Notify each affected individual within 60 days. Notify prominent media outlets serving the affected area. Report to OCR within 60 days of discovery.
What this looks like: The Health Trust identified suspicious activity and their forensic investigation determined unauthorized access. When a threat actor publicly claims responsibility and specifies data volume, your risk assessment becomes straightforward. You cannot argue low probability of compromise.
Critical steps:
- Count carefully (498 vs. 502 individuals changes everything)
- Identify which states are affected for media notification
- Report to OCR concurrently with individual notification
- Prepare for public scrutiny and media inquiries
- Document every step for potential OCR investigation
Path C: Exception Documentation (No Notification Required)
Choose this path when:
- You can demonstrate a low probability that PHI has been compromised
- Your four-factor risk assessment supports this conclusion
- You have forensic evidence, not assumptions
Your obligations: Document your risk assessment and retain it for six years. No notification is required, but you must be prepared to defend your decision if OCR inquires.
When this applies:
- Unintentional acquisition, access, or use by workforce members acting in good faith within scope of authority
- Inadvertent disclosure between persons authorized to access PHI at the same covered entity
- Good faith belief that the unauthorized recipient could not reasonably retain the information
The documentation requirement: You cannot rely on a threat actor's promise to avoid notification. You need evidence that acquisition never occurred.
Summary Matrix
| Decision Point | Notification Timeline | Media Notice | OCR Report Due | Documentation Required |
|---|---|---|---|---|
| Breach < 500 | 60 days from discovery | None | Year-end | Risk assessment, notification proof |
| Breach ≥ 500 | 60 days from discovery | Required | 60 days from discovery | Risk assessment, media outreach, notification proof |
| Exception applies | None | None | None | Six-year retention of risk assessment |
| Business Associate breach | Business Associate notifies you within 60 days; you notify individuals within 60 days of Business Associate notice | Depends on count | Depends on count | Business Associate Agreement, Business Associate notification |
The timeline that matters most:
Discovery date drives everything. Your 60-day clock starts when you knew or should have known about the breach, not when the breach occurred.
One final consideration:
Every organization mentioned here is enhancing technical safeguards or implementing additional security measures post-breach. But your decision tree should include a pre-breach branch: Are you conducting regular risk analyses under the HIPAA Security Rule? Are you testing your incident response plan? Are you auditing Business Associate compliance?
The best breach decision is the one you never have to make.



