Skip to main content
Category: Breach Notification

60-Day Notification Requirement

Simply put

The 60-Day Notification Requirement generally refers to the outer time limit within which certain notifications must be provided following a triggering event, such as the discovery of a data breach under HIPAA's Breach Notification Rule. In the HIPAA context, it is commonly understood as the requirement to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information. Readers should note that the evidence provided here does not contain HIPAA-specific source material, so the specific regulatory text and deadlines should be verified against the current Breach Notification Rule.

Formal definition

Within the HIPAA framework, a '60-day' notification standard is most commonly associated with the Breach Notification Rule, under which covered entities are generally required to notify affected individuals of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days following discovery of the breach; business associates are typically required to notify the covered entity following discovery, and applicable timing obligations should flow through the business associate agreement. IMPORTANT LIMITATION: The evidence packet supplied for this entry contains only non-HIPAA sources (WARN Act layoff notices, HUD/tenant lease termination notices, and Regulation B adverse-action notices), none of which govern HIPAA breach notification. Because no HIPAA-specific or HHS OCR source is present in the evidence, the precise trigger points, calendar-day counting, exceptions (such as law enforcement delay), and any media or HHS Secretary notification thresholds must be confirmed against the current text of the HIPAA Breach Notification Rule and current HHS OCR guidance. Practitioners should also note that state breach notification laws and the HITECH Act may impose shorter deadlines or additional obligations, and that this term carries different meanings in other regulatory contexts (e.g., WARN Act, landlord-tenant law, and consumer credit rules) that are outside the scope of HIPAA.

Why it matters

For HIPAA-covered entities and business associates, the 60-day outer limit on breach notification is one of the most consequential timing obligations in the compliance calendar. Missing it can transform a breach into a compounded compliance failure, because the delay itself may constitute a separate violation subject to enforcement by HHS OCR. The clock's practical difficulty lies in the phrase 'without unreasonable delay': the 60 calendar days is a ceiling, not a safe harbor, and waiting until day 59 when facts were known earlier can still be problematic.

The requirement also matters because timing obligations must be coordinated across relationships. When a business associate discovers a breach, the covered entity generally still bears responsibility for notifying affected individuals within the applicable window, so any lag in the business associate's notification to the covered entity effectively erodes the covered entity's remaining time. This makes the notification timing provisions of the business associate agreement a practical, not merely contractual, concern.

Readers should note an important limitation: the evidence supplied for this entry contains only non-HIPAA sources, WARN Act layoff notices, HUD tenant lease termination notices, and Regulation B adverse-action rules, none of which govern HIPAA breach notification. The '60-day' concept appears across many unrelated legal regimes with entirely different triggers and consequences. The specific HIPAA trigger points, day-counting rules, and exceptions should therefore be confirmed against the current text of the HIPAA Breach Notification Rule and current HHS OCR guidance rather than inferred from these other contexts.

Who it's relevant to

Privacy and Security Officers
Officers responsible for incident response must operationalize the 60-day ceiling as an outer boundary, not a target, and build workflows that document the discovery date and demonstrate notification without unreasonable delay. They should verify current day-counting rules and any applicable exceptions against the Breach Notification Rule and HHS OCR guidance.
Business Associates and Subcontractors
Because covered entities depend on timely notice from their vendors to meet their own deadlines, business associates must track discovery dates carefully and notify the covered entity within the timeframe set by the business associate agreement. Subcontractors should confirm how notification timing flows through their own agreements up the chain.
Compliance and Legal Counsel
Counsel should confirm that the 60-day federal ceiling is not superseded by shorter or additional state breach notification requirements or HITECH Act obligations, and should ensure that business associate agreements allocate notification timing clearly. They should also guard against confusing HIPAA's 60-day standard with the unrelated 60-day notices found in WARN Act, landlord-tenant, or consumer credit contexts.
Auditors and Assessors
Assessors reviewing breach response programs should test whether an organization can evidence its discovery date, its notification timeline, and coordination with business associates. Note that meeting the 60-day requirement addresses one specific obligation and does not by itself establish overall HIPAA compliance.

Inside 60-Day Notification Requirement

Outer Time Limit for Notification
Under the HIPAA Breach Notification Rule, covered entities are generally required to provide notification of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days. The 60-day period functions as an outer limit, not a safe harbor to delay notification when it could reasonably be provided sooner.
Trigger for the Clock
The 60-day period generally begins running from the date the breach is discovered, which is treated as the first day the breach is known, or by exercising reasonable diligence would have been known, to the covered entity. Verify the precise discovery standard against the current regulatory text.
Individual Notification
Affected individuals must generally be notified within the applicable timeframe following discovery, typically by first-class mail or, where agreed, by email, with substitute notice available in defined circumstances.
HHS Secretary (OCR) Notification
Notification to HHS is required, but the timing differs based on breach size. Breaches affecting larger numbers of individuals generally require notification to HHS OCR within the same timeframe as individuals, while smaller breaches may generally be reported on an annual basis. Confirm the applicable threshold and timing against current guidance.
Media Notification
For breaches affecting a number of residents of a state or jurisdiction that meets the regulatory threshold, notice to prominent media outlets serving that area is generally required within the applicable timeframe, in addition to individual notice.
Business Associate Obligations
Business associates are generally required to notify the covered entity of a breach, typically without unreasonable delay and no later than the applicable outer limit from discovery. The specific timing and responsibilities should be defined in the business associate agreement, and the covered entity's own notification obligations to individuals still generally apply.

Common questions

Answers to the questions practitioners most commonly ask about 60-Day Notification Requirement.

Does the 60-day period mean I can wait until day 60 to notify affected individuals?
No. The 60-day timeframe is an outer limit, not a target or a safe harbor. Under the HIPAA Breach Notification Rule, covered entities generally must notify affected individuals without unreasonable delay and in no case later than 60 calendar days following discovery of a breach. Waiting until the deadline when notification could reasonably have occurred sooner may itself be viewed as an unreasonable delay. Treat the 60 days as a maximum, and provide notice as soon as reasonably practicable. Verify specific timing expectations against the current regulatory text and any applicable state law, which may impose shorter deadlines.
Does the 60-day clock start when the breach actually occurred?
No. The clock generally begins on discovery of the breach, not on the date the breach occurred. A breach is typically treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to the covered entity. This distinction matters because a breach may go undetected for some time before discovery. Note also that knowledge is generally imputed based on what the entity's workforce members knew or should have known. Confirm the precise discovery standard against the current Breach Notification Rule.
How does the 60-day requirement work when a business associate discovers the breach rather than the covered entity?
The Breach Notification Rule generally requires a business associate to notify the covered entity of a breach, without unreasonable delay and no later than 60 calendar days from discovery, unless the business associate agreement specifies otherwise. The covered entity then generally remains responsible for notifying affected individuals within its own timeframe. Because the business associate's notification can consume part of the overall window, many covered entities negotiate shorter notification deadlines in their business associate agreements. Review your specific agreement terms and confirm obligations against the current regulation.
What should I document to demonstrate that notification was timely?
Maintain records that show when and how the breach was discovered, the steps taken to investigate and assess it, and the dates notifications were sent. Documentation of any risk assessment used to determine whether a breach occurred, and the reasoning behind timing decisions, can help demonstrate that notice was provided without unreasonable delay. Because covered entities generally bear the burden of demonstrating compliance, thorough contemporaneous records are advisable. Retain documentation consistent with the retention periods described in the applicable regulatory text.
Do the same timing rules apply to notifying HHS and the media?
Not identically. Individual notification generally must occur within the 60-day outer limit. Notification to HHS OCR and, where applicable, to prominent media outlets is triggered based on breach size thresholds and follows its own timing rules under the Breach Notification Rule. In general, breaches affecting a larger number of individuals carry more immediate media and HHS notification obligations, while smaller breaches may be reported to HHS on a different schedule. Confirm the current thresholds and deadlines against HHS OCR guidance, as these are specified in the regulation.
What if my investigation is not complete within 60 days?
The obligation to notify without unreasonable delay and within the outer limit generally does not pause because an investigation is ongoing. If you have determined that a reportable breach occurred, notification should proceed within the required timeframe even if some details remain under investigation. Notifications can generally include the information available at the time, with the understanding that ongoing investigation may surface additional facts. Coordinate timing decisions with legal counsel and verify requirements against the current Breach Notification Rule and any applicable state law.

Common misconceptions

You always have a full 60 days before you must notify anyone.
The rule generally requires notification without unreasonable delay; 60 days is the outer limit, not a guaranteed grace period. If notification can reasonably be provided sooner, waiting the full period may itself be viewed as an unreasonable delay.
The 60-day clock starts when the incident actually occurred.
The clock generally starts on discovery, meaning the first day the breach is known, or would have been known through reasonable diligence, to the covered entity, not on the date the underlying event happened.
A business associate's 60-day notification to the covered entity satisfies the covered entity's obligations.
A business associate notifying the covered entity is a separate obligation. The covered entity generally remains responsible for notifying affected individuals, HHS OCR, and, where applicable, the media within its own applicable timeframe. Responsibilities should be clarified in the business associate agreement.

Best practices

Establish an incident response process that documents the date of discovery for any suspected breach so the notification clock can be tracked accurately.
Treat the 60-day limit as an outer boundary and aim to notify affected individuals, and HHS OCR where applicable, as soon as reasonably possible rather than defaulting to the full period.
Define breach notification timelines and responsibilities explicitly in business associate agreements, including how quickly a business associate must report to the covered entity.
Maintain a breach log to support timely reporting of both larger breaches and smaller breaches that may be reportable to HHS on an annual basis, and confirm the applicable threshold against current guidance.
Prepare template notification letters and media notice procedures in advance so required content can be finalized quickly once a breach is confirmed.
Check whether state breach notification laws or the HITECH Act impose shorter timeframes or additional requirements, as those may apply in addition to the HIPAA Breach Notification Rule.