Annual Breach Log
An Annual Breach Log is a running record a covered entity keeps of smaller breaches of unsecured protected health information that occur over a calendar year. Rather than reporting each of these smaller breaches to the government as they happen, the covered entity generally submits them together in a single annual notice to HHS. This process is separate from the faster reporting timelines that typically apply to larger breaches.
Under the HIPAA Breach Notification Rule, a covered entity that discovers a breach of unsecured protected health information (PHI) must notify the HHS Secretary (45 C.F.R. § 164.408). For breaches affecting fewer than 500 individuals, the covered entity generally logs or documents such breaches as they are discovered throughout the calendar year and submits notice to OCR on an annual basis (commonly cited as no later than 60 days after the end of the calendar year; some guidance references an early-in-the-year deadline such as March 1st). Practitioners should verify the current applicable deadline and submission requirements against 45 C.F.R. § 164.408 and current OCR guidance, as reporting is made through the OCR breach portal. This annual log mechanism is distinct from the notification obligations for larger breaches (generally those affecting 500 or more individuals), which typically require more prompt notice to the Secretary, affected individuals, and in some cases the media. Note that breach determination, risk assessment, and individual/media notification obligations are governed by other provisions of the Breach Notification Rule and are out of scope for this entry, and that state breach-notification laws or the HITECH Act may impose additional requirements.
Why it matters
The Annual Breach Log addresses a practical reality for covered entities: smaller breaches of unsecured protected health information happen with some frequency, and reporting each one to HHS the moment it is discovered would be burdensome for both the organization and the regulator. The Breach Notification Rule generally allows breaches affecting fewer than 500 individuals to be documented as they occur and submitted together in a single annual notice, rather than triggering the faster, incident-by-incident reporting timeline that typically applies to larger breaches. Understanding this distinction helps compliance teams route each breach to the correct process instead of over- or under-reporting.
Getting the annual log right matters because the underlying obligation still stands: a covered entity that discovers a breach of unsecured PHI must notify the HHS Secretary, and the smaller-breach pathway does not eliminate that duty, it simply changes the timing and mechanism. Missing the annual deadline, failing to log breaches consistently throughout the year, or misclassifying a large breach as a small one can expose an organization to enforcement scrutiny by HHS OCR, which investigates reported breaches. A well-maintained log also serves as internal evidence that the organization is tracking incidents systematically.
It is important to keep the annual log narrowly in view. Deadlines and submission requirements are cited variously in guidance (for example, some sources reference a March 1st deadline, while the rule is commonly described as no later than 60 days after the end of the calendar year), so practitioners should confirm the current applicable deadline against 45 C.F.R. § 164.408 and current OCR guidance. In addition, state breach-notification laws or the HITECH Act may impose separate or stricter requirements that are not satisfied by the federal annual log alone.
Who it's relevant to
Inside Annual Breach Log
Common questions
Answers to the questions practitioners most commonly ask about Annual Breach Log.