500-Individual Threshold
The 500-individual threshold is a benchmark under the HIPAA Breach Notification Rule that separates larger breaches from smaller ones for reporting purposes. When a breach of unsecured protected health information affects 500 or more individuals, the covered entity generally must report it to the government more quickly and take additional steps, rather than reporting it in an annual summary. This threshold determines the timing and manner of breach notifications, not whether a breach occurred.
Under the HIPAA Breach Notification Rule (enforced by HHS OCR), the 500-individual threshold determines the escalated notification obligations that apply to a breach of unsecured PHI. Where a breach affects 500 or more individuals, covered entities must notify the HHS Secretary without unreasonable delay and in no case later than 60 days following discovery, rather than through the annual log used for breaches affecting fewer than 500 individuals; media notification to prominent outlets serving the affected area is also generally triggered at or above this threshold. The count is generally assessed per breach incident and applies to affected individuals whose unsecured PHI was involved. This threshold governs only the timing and channels of notification and does not alter the underlying determination of whether a reportable breach exists, which is a separate analysis. Business associates have distinct notification obligations that generally flow to the covered entity through the business associate agreement rather than directly to the Secretary. State breach notification laws and the HITECH Act may impose additional or more stringent requirements, and specific deadlines and procedures should be verified against the current regulatory text.
Why it matters
The 500-individual threshold is one of the most operationally significant lines in the HIPAA Breach Notification Rule because it changes how quickly and through what channels a breach must be reported. Below the threshold, a covered entity may generally log qualifying breaches and report them to HHS OCR on an annual basis. At or above 500 affected individuals, the same event triggers expedited notification to the HHS Secretary, without unreasonable delay and in no case later than 60 days following discovery, along with notice to prominent media outlets serving the affected area. For compliance teams, misjudging which side of this line a breach falls on can mean the difference between a timely, compliant response and a reporting failure that draws regulatory scrutiny.
The threshold matters not because it defines whether a breach occurred, but because it governs the tempo and visibility of the response. The underlying determination of whether a reportable breach of unsecured PHI exists is a separate analysis that happens first; the 500 count only comes into play once a breach has been established. This distinction is easy to blur under the pressure of incident response, and treating the threshold as a test of whether to report at all, rather than how and when to report, is a common source of error.
Because breaches affecting 500 or more individuals are also posted publicly by HHS OCR and often attract media attention, the reputational and regulatory stakes escalate sharply at this line. Compliance officers should treat the threshold as a trigger for a coordinated legal, privacy, security, and communications response, while remembering that state breach notification laws and the HITECH Act may impose additional or more stringent obligations that apply regardless of the federal count.
Who it's relevant to
Inside 500-Individual Threshold
Common questions
Answers to the questions practitioners most commonly ask about 500-Individual Threshold.