Skip to main content
Category: Breach Notification

500-Individual Threshold

Also known as: 500-Person Threshold, 500 or More Individuals Threshold, Large Breach Threshold
Simply put

The 500-individual threshold is a benchmark under the HIPAA Breach Notification Rule that separates larger breaches from smaller ones for reporting purposes. When a breach of unsecured protected health information affects 500 or more individuals, the covered entity generally must report it to the government more quickly and take additional steps, rather than reporting it in an annual summary. This threshold determines the timing and manner of breach notifications, not whether a breach occurred.

Formal definition

Under the HIPAA Breach Notification Rule (enforced by HHS OCR), the 500-individual threshold determines the escalated notification obligations that apply to a breach of unsecured PHI. Where a breach affects 500 or more individuals, covered entities must notify the HHS Secretary without unreasonable delay and in no case later than 60 days following discovery, rather than through the annual log used for breaches affecting fewer than 500 individuals; media notification to prominent outlets serving the affected area is also generally triggered at or above this threshold. The count is generally assessed per breach incident and applies to affected individuals whose unsecured PHI was involved. This threshold governs only the timing and channels of notification and does not alter the underlying determination of whether a reportable breach exists, which is a separate analysis. Business associates have distinct notification obligations that generally flow to the covered entity through the business associate agreement rather than directly to the Secretary. State breach notification laws and the HITECH Act may impose additional or more stringent requirements, and specific deadlines and procedures should be verified against the current regulatory text.

Why it matters

The 500-individual threshold is one of the most operationally significant lines in the HIPAA Breach Notification Rule because it changes how quickly and through what channels a breach must be reported. Below the threshold, a covered entity may generally log qualifying breaches and report them to HHS OCR on an annual basis. At or above 500 affected individuals, the same event triggers expedited notification to the HHS Secretary, without unreasonable delay and in no case later than 60 days following discovery, along with notice to prominent media outlets serving the affected area. For compliance teams, misjudging which side of this line a breach falls on can mean the difference between a timely, compliant response and a reporting failure that draws regulatory scrutiny.

The threshold matters not because it defines whether a breach occurred, but because it governs the tempo and visibility of the response. The underlying determination of whether a reportable breach of unsecured PHI exists is a separate analysis that happens first; the 500 count only comes into play once a breach has been established. This distinction is easy to blur under the pressure of incident response, and treating the threshold as a test of whether to report at all, rather than how and when to report, is a common source of error.

Because breaches affecting 500 or more individuals are also posted publicly by HHS OCR and often attract media attention, the reputational and regulatory stakes escalate sharply at this line. Compliance officers should treat the threshold as a trigger for a coordinated legal, privacy, security, and communications response, while remembering that state breach notification laws and the HITECH Act may impose additional or more stringent obligations that apply regardless of the federal count.

Who it's relevant to

Privacy and Security Officers
These officers are typically responsible for classifying a breach and determining the affected-individual count that dictates whether expedited or annual reporting applies. They need to apply the threshold correctly under time pressure and coordinate the timely notifications to HHS OCR, affected individuals, and, where triggered, the media.
Compliance Officers
Compliance leaders use the threshold to build incident-response playbooks that escalate appropriately once a breach reaches 500 or more individuals. They must also account for state breach notification laws and HITECH Act provisions that may impose additional or more stringent requirements beyond the federal timeline and channels.
Business Associates and Subcontractors
Business associates that discover breaches must understand that their notification obligations generally flow to the covered entity through the business associate agreement rather than directly to the Secretary. Prompt and accurate reporting to the covered entity is critical, because the covered entity's ability to meet the expedited 60-day deadline for large breaches depends on it.
Legal and Regulatory Counsel
Counsel advising on breach response must confirm current deadlines and procedures against the applicable regulatory text, distinguish the separate breach-determination analysis from the threshold-based timing rules, and assess overlapping obligations under state law and the HITECH Act.

Inside 500-Individual Threshold

Breach Notification Rule Context
The 500-individual threshold is a concept arising under the HIPAA Breach Notification Rule, which governs how covered entities and business associates report breaches of unsecured protected health information (PHI). It is distinct from the Privacy, Security, and Enforcement Rules.
Threshold for Larger Breaches
The threshold generally distinguishes breaches affecting 500 or more individuals from those affecting fewer than 500. This distinction typically affects the timing and manner in which notifications must be made to HHS OCR and, in some cases, to the media.
Notification to HHS OCR
For breaches meeting or exceeding this threshold, covered entities generally must notify the Secretary of HHS (through OCR) without unreasonable delay, rather than aggregating and reporting the incident on the annual basis permitted for smaller breaches. Readers should verify current timing requirements against the applicable regulatory text.
Media Notification Consideration
The threshold is also generally associated with an obligation to notify prominent media outlets when a breach affects 500 or more residents of a state or jurisdiction. The specific geographic scope and mechanics should be confirmed against the current Breach Notification Rule.
Individual Notification (Unaffected by Threshold)
Notification to affected individuals is generally required regardless of the number of people involved. The 500-individual threshold does not change whether affected individuals must be notified; it primarily affects HHS and media notification obligations.
Unsecured PHI Scope
The threshold applies in the context of breaches of unsecured PHI. PHI rendered unusable, unreadable, or indecipherable through methods recognized by HHS guidance (such as certain encryption approaches) may fall outside breach notification obligations altogether. Readers should verify against current HHS guidance.

Common questions

Answers to the questions practitioners most commonly ask about 500-Individual Threshold.

Does the 500-individual threshold mean I only have to report breaches that affect 500 or more people?
No. This is a common misconception. Under the Breach Notification Rule, a covered entity must notify all affected individuals of a breach of unsecured PHI regardless of the number of people involved. The 500-individual threshold does not exempt smaller breaches from notification; it governs the timing and method of notifying HHS OCR (and, for larger breaches, the media). Breaches affecting fewer than 500 individuals still require individual notice and must generally be reported to HHS OCR, though typically on a different schedule. Always verify current requirements against the applicable regulatory text.
Is the 500-individual threshold a HIPAA penalty tier that determines how much I could be fined?
No. The 500-individual threshold is not a penalty tier and does not by itself set any fine amount. It is a reporting and notification trigger within the Breach Notification Rule that affects how and when HHS OCR and the media are notified. HIPAA civil monetary penalties are determined under the Enforcement Rule based on factors such as culpability, and penalty figures are adjusted over time by HHS OCR. Any specific penalty amounts should be confirmed against current HHS guidance rather than inferred from breach-size thresholds.
How do I count whether a breach reaches the 500-individual threshold?
In general, the count is based on the number of individuals whose unsecured PHI was affected by a single breach incident. Determining the affected population typically flows from the breach risk assessment used to establish that a breach occurred. Because counting methodology and edge cases (such as breaches spanning multiple states or uncertain totals) can be complex, and because state law or the HITECH Act may impose additional obligations, you should document your basis for the count and verify the approach against current regulatory guidance.
What notification obligations are triggered when a breach meets or exceeds the 500-individual threshold?
For a breach of unsecured PHI affecting 500 or more individuals, a covered entity generally must notify the affected individuals, notify HHS OCR, and provide notice to prominent media outlets serving the relevant area, within the timeframes set by the Breach Notification Rule. The specific deadlines, methods, and any regional or state-level variations should be confirmed against the current regulatory text, as state breach notification laws may add further requirements.
As a business associate, what is my role in relation to the 500-individual threshold?
A business associate that discovers a breach of unsecured PHI is generally obligated to notify the covered entity, with the specific obligations defined by the business associate agreement and the Breach Notification Rule. In most cases the covered entity is responsible for the individual, HHS OCR, and media notifications tied to the 500-individual threshold, though responsibilities may be allocated by contract. Subcontractors have parallel obligations flowing up through their agreements. Review your business associate agreement to confirm who handles which notification steps.
How should we prepare our incident response process to handle a breach that could cross the 500-individual threshold?
Organizations typically build breach response procedures that include a documented risk assessment, a reliable method for identifying and counting affected individuals, and predefined workflows for individual, HHS OCR, and media notifications when the 500-individual threshold is reached. Because timing requirements are strict and state laws may impose additional or shorter deadlines, many entities prepare notification templates and escalation paths in advance. Note that no procedure guarantees compliance; processes should be tested and aligned with the current Breach Notification Rule and applicable state law.

Common misconceptions

Breaches affecting fewer than 500 individuals do not need to be reported to HHS.
Smaller breaches generally still must be reported to HHS OCR, but typically may be logged and submitted on an annual basis rather than promptly. The threshold affects timing and media notification, not whether reporting occurs at all. Confirm current requirements against the applicable regulatory text.
Individual notifications are only required once a breach reaches 500 people.
Notification to affected individuals is generally required regardless of how many individuals are involved. The 500-individual threshold primarily governs notification to HHS and the media, not to the individuals themselves.
The 500 figure counts individuals nationwide for media notification purposes.
The media notification obligation is generally tied to breaches affecting 500 or more residents of a particular state or jurisdiction, not simply a nationwide total. The exact geographic scope should be confirmed against the current Breach Notification Rule.

Best practices

Maintain an incident response process that promptly assesses the number of individuals affected so you can determine which notification timelines and channels apply.
Do not treat sub-500 breaches as exempt from reporting; keep a running log of smaller breaches to support required periodic submissions to HHS OCR and verify current submission deadlines against the applicable regulation.
Notify affected individuals as required regardless of the total count, since individual notification obligations generally apply independently of the 500-individual threshold.
Assess whether affected PHI qualifies as unsecured, since PHI rendered unusable, unreadable, or indecipherable under current HHS guidance may fall outside breach notification obligations.
Confirm which entity bears reporting responsibility when a business associate or subcontractor is involved, and address breach notification timing and responsibilities explicitly in business associate agreements.
Check for additional or stricter state breach notification laws and HITECH-related requirements that may impose obligations beyond the HIPAA threshold, and verify all timing and geographic specifics against the current regulatory text.