Skip to main content
Category: Breach Notification

Annual Breach Log

Also known as: Annual Breach Report, Small Breach Log, Breaches Affecting Fewer Than 500 Individuals Log
Simply put

An Annual Breach Log is a running record a covered entity keeps of smaller breaches of unsecured protected health information that occur over a calendar year. Rather than reporting each of these smaller breaches to the government as they happen, the covered entity generally submits them together in a single annual notice to HHS. This process is separate from the faster reporting timelines that typically apply to larger breaches.

Formal definition

Under the HIPAA Breach Notification Rule, a covered entity that discovers a breach of unsecured protected health information (PHI) must notify the HHS Secretary (45 C.F.R. § 164.408). For breaches affecting fewer than 500 individuals, the covered entity generally logs or documents such breaches as they are discovered throughout the calendar year and submits notice to OCR on an annual basis (commonly cited as no later than 60 days after the end of the calendar year; some guidance references an early-in-the-year deadline such as March 1st). Practitioners should verify the current applicable deadline and submission requirements against 45 C.F.R. § 164.408 and current OCR guidance, as reporting is made through the OCR breach portal. This annual log mechanism is distinct from the notification obligations for larger breaches (generally those affecting 500 or more individuals), which typically require more prompt notice to the Secretary, affected individuals, and in some cases the media. Note that breach determination, risk assessment, and individual/media notification obligations are governed by other provisions of the Breach Notification Rule and are out of scope for this entry, and that state breach-notification laws or the HITECH Act may impose additional requirements.

Why it matters

The Annual Breach Log addresses a practical reality for covered entities: smaller breaches of unsecured protected health information happen with some frequency, and reporting each one to HHS the moment it is discovered would be burdensome for both the organization and the regulator. The Breach Notification Rule generally allows breaches affecting fewer than 500 individuals to be documented as they occur and submitted together in a single annual notice, rather than triggering the faster, incident-by-incident reporting timeline that typically applies to larger breaches. Understanding this distinction helps compliance teams route each breach to the correct process instead of over- or under-reporting.

Getting the annual log right matters because the underlying obligation still stands: a covered entity that discovers a breach of unsecured PHI must notify the HHS Secretary, and the smaller-breach pathway does not eliminate that duty, it simply changes the timing and mechanism. Missing the annual deadline, failing to log breaches consistently throughout the year, or misclassifying a large breach as a small one can expose an organization to enforcement scrutiny by HHS OCR, which investigates reported breaches. A well-maintained log also serves as internal evidence that the organization is tracking incidents systematically.

It is important to keep the annual log narrowly in view. Deadlines and submission requirements are cited variously in guidance (for example, some sources reference a March 1st deadline, while the rule is commonly described as no later than 60 days after the end of the calendar year), so practitioners should confirm the current applicable deadline against 45 C.F.R. § 164.408 and current OCR guidance. In addition, state breach-notification laws or the HITECH Act may impose separate or stricter requirements that are not satisfied by the federal annual log alone.

Who it's relevant to

Privacy and Compliance Officers
Privacy and compliance officers at covered entities are typically responsible for maintaining the running log of smaller breaches throughout the year and ensuring the annual submission to OCR is made by the applicable deadline. They should confirm the current deadline and portal requirements against 45 C.F.R. § 164.408 and current OCR guidance rather than relying on any single secondary source.
Security Officers and Incident Response Teams
Security officers and incident response staff are often the first to identify potential breaches of unsecured ePHI. They play a key role in feeding accurate, timely information into the breach log so that each incident is correctly classified as either a smaller breach eligible for annual reporting or a larger breach subject to prompt notification obligations.
Legal and Regulatory Counsel
Legal counsel advising covered entities should confirm how the federal annual log interacts with state breach-notification laws and any additional HITECH Act requirements, since satisfying the federal annual submission does not necessarily satisfy separate or stricter obligations under other authorities.
Business Associates Supporting Covered Entities
Business associates that discover breaches must generally report them to the covered entity, whose obligations to HHS then follow the Breach Notification Rule. While the annual log is a covered-entity submission, business associate agreements typically define the reporting flow, so business associates should understand how their reporting feeds the covered entity's logging and annual notice process.

Inside Annual Breach Log

Log of Smaller Breaches
A running record maintained by a covered entity documenting breaches of unsecured protected health information affecting fewer than 500 individuals during a calendar year, which are generally reported to HHS OCR on an annual basis rather than immediately.
Individual Breach Entries
Details of each qualifying incident, typically including a description of what happened, the date of the breach and the date of its discovery, the types of PHI involved, and the number of individuals affected, so that the information can support the required annual submission to HHS OCR.
Remediation and Response Information
Notes on the mitigation steps taken, notifications provided to affected individuals, and any corrective actions implemented, which help demonstrate the entity's response to each incident.
Annual Submission Reference
Records supporting the reporting of these smaller breaches to HHS OCR, which under the Breach Notification Rule is generally required within a set period after the end of the calendar year; the specific deadline should be verified against current HHS guidance.

Common questions

Answers to the questions practitioners most commonly ask about Annual Breach Log.

Does the annual breach log mean small breaches don't have to be reported until the end of the year?
Not exactly. Under the Breach Notification Rule, breaches affecting fewer than 500 individuals generally may be reported to HHS OCR on an annual basis, typically within a set period after the end of the calendar year in which they were discovered. However, affected individuals themselves must still generally be notified without unreasonable delay, so the annual log timing applies to the HHS submission for smaller breaches, not to individual notice. Breaches affecting 500 or more individuals follow different, more immediate reporting requirements. Confirm current deadlines against the applicable regulatory text.
Is the annual breach log something HITRUST requires, or is it a HIPAA obligation?
The annual breach log arises from the HIPAA Breach Notification Rule, which is enforced by HHS OCR. It is a federal regulatory obligation, not a HITRUST requirement. While maintaining breach documentation may support controls within the HITRUST CSF, HITRUST is a private organization and its certification does not by itself establish HIPAA compliance or satisfy the breach reporting obligation. Covered entities remain responsible for meeting the HIPAA requirement regardless of any HITRUST certification status.
Who is responsible for maintaining and submitting the annual breach log?
The covered entity is generally responsible for reporting breaches to HHS OCR, including submitting the annual log for smaller breaches. Business associates typically must report breaches they discover to the covered entity, with the specifics governed by the business associate agreement. In many cases the covered entity then makes the required HHS submission, though arrangements may vary based on contract terms. Readers should verify allocation of these responsibilities against their agreements and current guidance.
What information should generally be captured for each breach entry in the log?
While the exact fields are defined by HHS OCR submission requirements, a breach log entry typically captures details such as the date of the breach, the date of discovery, a description of what occurred, the type of PHI involved, the approximate number of individuals affected, and the safeguards or remediation actions taken. Because the specific submission format and required fields are set by HHS, verify current requirements against the applicable regulatory text and OCR guidance.
How should an organization track breaches throughout the year so the annual log is accurate?
Organizations generally maintain an internal incident and breach tracking process that records suspected incidents, the results of any risk assessment used to determine whether an incident is a reportable breach, and the disposition of each. Recording discovery dates is important because reporting timelines are typically measured from discovery. This internal tracking supports both timely individual notification and accurate compilation of the annual submission. The specific process is not dictated by the rule, so approaches vary by organization.
Does completing the annual breach log satisfy all of an organization's breach-related obligations?
No. The annual log addresses the HHS reporting requirement for smaller breaches, but it does not replace other obligations, such as timely individual notification, media notice where applicable for larger breaches, or the separate immediate reporting requirements for breaches affecting 500 or more individuals. State breach notification laws and the HITECH Act may also impose additional requirements. Organizations should treat the annual log as one component of a broader breach response program and verify all applicable obligations against current guidance.

Common misconceptions

All breaches can simply be recorded in the annual log and reported once a year.
Under the Breach Notification Rule, breaches affecting 500 or more individuals generally must be reported to HHS OCR and affected individuals without unreasonable delay, typically within a much shorter timeframe. The annual log approach generally applies only to breaches affecting fewer than 500 individuals; readers should confirm current thresholds and timelines against HHS guidance.
Maintaining an annual breach log by itself demonstrates HIPAA compliance.
The log is one documentation practice supporting the Breach Notification Rule. It does not by itself establish compliance with the Privacy Rule, Security Rule, or other Breach Notification Rule obligations such as timely individual notification and, where applicable, media notice.
Only covered entities need to track smaller breaches.
Business associates also have breach notification obligations, though these generally flow through business associate agreements and typically involve notifying the covered entity of a breach rather than reporting directly to HHS OCR; the specific responsibilities depend on the agreement and the applicable regulatory text.

Best practices

Establish a consistent, centralized process for documenting each qualifying breach as it is discovered, capturing the date of the incident, the date of discovery, the PHI involved, and the number of individuals affected.
Clearly distinguish in your tracking between breaches affecting fewer than 500 individuals (generally reported annually) and those affecting 500 or more (generally requiring prompt reporting), since the reporting timelines differ.
Verify the current annual submission deadline and reporting mechanism against current HHS OCR guidance before each filing, rather than relying on assumed dates.
Record the mitigation and corrective actions taken for each incident so the log supports both regulatory reporting and internal review.
Coordinate with business associates so that breaches they identify are communicated in accordance with the business associate agreement and reflected appropriately in your records.
Review applicable state breach notification laws and the HITECH Act, which may impose additional or stricter requirements beyond the federal HIPAA Breach Notification Rule.