Breach Notification Rule
The Breach Notification Rule is a HIPAA requirement that generally obligates healthcare organizations to notify affected individuals when their unsecured protected health information (PHI) has been improperly used or disclosed. Individuals must typically be notified without unreasonable delay and, in most cases, no later than 60 days after the breach is discovered. When a breach affects a large number of people, the organization must also notify federal regulators, and business associates must notify the covered entities they work with.
The Breach Notification Rule, issued and enforced by HHS OCR, requires covered entities and business associates to provide notification following a breach of unsecured PHI. Under the rule, a breach is generally an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, subject to applicable exceptions and risk assessment provisions in the regulatory text. Affected individuals must generally be notified without unreasonable delay and in no case later than 60 days after discovery of the breach; where a breach affects 500 or more individuals, the covered entity must also notify the Secretary of HHS without unreasonable delay and no later than 60 days. Business associates are generally required to notify the covered entity, typically no later than 60 days, with the covered entity's notification obligations to individuals then applying. This rule is distinct from the Privacy Rule, Security Rule, and Enforcement Rule; the specific deadlines, thresholds, and definitions cited here should be verified against the current regulatory text, and note that the HITECH Act and state breach notification laws may impose additional or more stringent requirements beyond HIPAA.
Why it matters
The Breach Notification Rule establishes what happens after protected health information has been compromised, making it a central pillar of accountability within the HIPAA framework. Without a clear notification obligation, individuals whose sensitive health information had been exposed might never learn of the incident and would be unable to take protective steps. The rule ensures that affected individuals are generally informed, that federal regulators are alerted to larger incidents, and that business associates communicate breaches back to the covered entities they serve.
For compliance officers and privacy and security officers, the rule turns breach response into a time-sensitive, documented process rather than an internal matter that can be handled quietly. Individuals must generally be notified without unreasonable delay and, in most cases, no later than 60 days after discovery, and breaches affecting 500 or more individuals trigger additional notification to the Secretary of HHS. These deadlines mean organizations must have detection, assessment, and notification workflows in place before an incident occurs, not after.
It is important to understand what this rule does not do. The Breach Notification Rule governs the response to a breach of unsecured PHI; it is distinct from the Privacy Rule, the Security Rule, and the Enforcement Rule. It also does not represent the full universe of an organization's obligations, because the HITECH Act and state breach notification laws may impose additional or more stringent requirements. Organizations should verify specific deadlines, thresholds, and definitions against the current regulatory text and account for applicable state law.
Who it's relevant to
Inside Breach Notification Rule
Common questions
Answers to the questions practitioners most commonly ask about Breach Notification Rule.