Skip to main content
Category: Regulatory Framework

Breach Notification Rule

Also known as: HIPAA Breach Notification Rule
Simply put

The Breach Notification Rule is a HIPAA requirement that generally obligates healthcare organizations to notify affected individuals when their unsecured protected health information (PHI) has been improperly used or disclosed. Individuals must typically be notified without unreasonable delay and, in most cases, no later than 60 days after the breach is discovered. When a breach affects a large number of people, the organization must also notify federal regulators, and business associates must notify the covered entities they work with.

Formal definition

The Breach Notification Rule, issued and enforced by HHS OCR, requires covered entities and business associates to provide notification following a breach of unsecured PHI. Under the rule, a breach is generally an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, subject to applicable exceptions and risk assessment provisions in the regulatory text. Affected individuals must generally be notified without unreasonable delay and in no case later than 60 days after discovery of the breach; where a breach affects 500 or more individuals, the covered entity must also notify the Secretary of HHS without unreasonable delay and no later than 60 days. Business associates are generally required to notify the covered entity, typically no later than 60 days, with the covered entity's notification obligations to individuals then applying. This rule is distinct from the Privacy Rule, Security Rule, and Enforcement Rule; the specific deadlines, thresholds, and definitions cited here should be verified against the current regulatory text, and note that the HITECH Act and state breach notification laws may impose additional or more stringent requirements beyond HIPAA.

Why it matters

The Breach Notification Rule establishes what happens after protected health information has been compromised, making it a central pillar of accountability within the HIPAA framework. Without a clear notification obligation, individuals whose sensitive health information had been exposed might never learn of the incident and would be unable to take protective steps. The rule ensures that affected individuals are generally informed, that federal regulators are alerted to larger incidents, and that business associates communicate breaches back to the covered entities they serve.

For compliance officers and privacy and security officers, the rule turns breach response into a time-sensitive, documented process rather than an internal matter that can be handled quietly. Individuals must generally be notified without unreasonable delay and, in most cases, no later than 60 days after discovery, and breaches affecting 500 or more individuals trigger additional notification to the Secretary of HHS. These deadlines mean organizations must have detection, assessment, and notification workflows in place before an incident occurs, not after.

It is important to understand what this rule does not do. The Breach Notification Rule governs the response to a breach of unsecured PHI; it is distinct from the Privacy Rule, the Security Rule, and the Enforcement Rule. It also does not represent the full universe of an organization's obligations, because the HITECH Act and state breach notification laws may impose additional or more stringent requirements. Organizations should verify specific deadlines, thresholds, and definitions against the current regulatory text and account for applicable state law.

Who it's relevant to

Privacy and Security Officers
These professionals are typically responsible for designing and executing breach response workflows, including detection, risk assessment, and timely notification. The rule's deadlines, generally no later than 60 days after discovery, require them to have documented processes in place before an incident occurs.
Covered Entities
Covered entities carry the primary obligation to notify affected individuals of a breach of unsecured PHI and, for breaches affecting 500 or more individuals, to notify the Secretary of HHS. They must also be prepared to act on notifications received from their business associates.
Business Associates
Business associates are generally required to notify the covered entities they work with when a breach occurs, typically no later than 60 days, so that the covered entity can meet its own notification obligations. Understanding this chain of responsibility is essential to fulfilling contractual and regulatory duties.
Compliance Officers and Legal Counsel
These roles must ensure that notification practices align with HIPAA while also accounting for the HITECH Act and any state breach notification laws that may impose additional or more stringent requirements. They should verify specific thresholds and deadlines against current guidance from HHS OCR.

Inside Breach Notification Rule

Definition of a Breach
Generally defined as the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI. This applies to PHI in all forms, not only electronic PHI.
Risk Assessment Requirement
When an impermissible use or disclosure occurs, it is generally presumed to be a breach unless the covered entity or business associate demonstrates, through a documented risk assessment, that there is a low probability the PHI has been compromised. The assessment typically considers factors such as the nature of the PHI involved, the unauthorized person who received it, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated.
Notification to Affected Individuals
Covered entities are generally required to notify affected individuals following the discovery of a breach of unsecured PHI, within timeframes specified by the rule. Readers should verify the current notification deadlines against the applicable regulatory text.
Notification to HHS
Covered entities must notify the Secretary of HHS of breaches. The timing and method generally differ depending on the number of individuals affected, with distinct requirements for larger breaches versus smaller ones. Confirm current thresholds and timelines against current HHS guidance.
Media Notification
For breaches affecting a number of residents of a state or jurisdiction above a defined threshold, notification to prominent media outlets serving that area is generally required, in addition to individual notice.
Business Associate Obligations
Business associates are generally required to notify the covered entity following discovery of a breach of unsecured PHI. Specific notification responsibilities between the parties are typically detailed in the business associate agreement, and obligations attach through these defined relationships rather than to any vendor generally.
Unsecured PHI and Safe Harbor Concept
Notification obligations generally apply to unsecured PHI, PHI that has not been rendered unusable, unreadable, or indecipherable through methods such as encryption or destruction consistent with HHS guidance. PHI secured by such methods is generally not subject to breach notification, though readers should verify the applicable specifications.
Enforcement Authority
The Breach Notification Rule is enforced by HHS OCR. Penalties for violations are administered under the Enforcement Rule, and penalty tiers and figures are adjusted over time and should be confirmed against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about Breach Notification Rule.

Does every unauthorized access or disclosure of PHI automatically count as a reportable breach?
No. Not every impermissible use or disclosure of PHI is automatically a reportable breach. Under the Breach Notification Rule, an acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule is generally presumed to be a breach unless the covered entity or business associate demonstrates, through a risk assessment, that there is a low probability the PHI has been compromised. The rule also identifies certain exceptions. Because the analysis is fact-specific, organizations should document their risk assessment and verify the current regulatory standard rather than assume any incident is either automatically reportable or automatically exempt.
Is the Breach Notification Rule the same thing as the Security Rule, since both deal with protecting data?
No, they are distinct rules with different scopes and purposes. The Security Rule sets forth safeguards specifically for electronic protected health information (ePHI). The Breach Notification Rule, by contrast, governs what happens after an impermissible use or disclosure of protected health information occurs, and it applies to PHI in all forms, not only electronic. Complying with the Security Rule does not eliminate breach notification obligations, and the Breach Notification Rule can be triggered by incidents involving paper or oral PHI that fall outside the Security Rule's scope. Readers should treat these as separate but related requirements.
Who is responsible for notifying affected individuals when a business associate causes a breach?
In general, the obligation to notify affected individuals rests with the covered entity, even when the breach originates with a business associate. A business associate is typically required to notify the covered entity of a breach, and the business associate agreement often specifies the timing and content of that notification and may allocate responsibility for individual notifications. Organizations should review their business associate agreements to confirm how notification duties are assigned and should verify the applicable timing requirements against the current regulatory text.
What steps should an organization take when it discovers a potential breach?
Organizations generally begin by identifying and containing the incident, then conducting a documented risk assessment to determine whether there is a low probability that the PHI has been compromised. If notification is required, the organization typically must provide notice to affected individuals, and depending on the scope, to HHS OCR and in some cases to the media. Documentation of the assessment and any notifications is important. Because timing thresholds and specific notification triggers are set by regulation and adjusted over time, organizations should confirm current requirements against the applicable regulatory text and consider whether state laws or the HITECH Act impose additional obligations.
How does the number of individuals affected change breach notification obligations?
The scale of a breach generally affects certain notification requirements. In most cases, breaches are categorized differently depending on whether they affect a smaller or larger number of individuals, which can influence how and when notice must be provided to HHS OCR and whether media notification applies. The specific threshold that distinguishes larger breaches, and the associated timing, is set by regulation and should be verified against current guidance rather than assumed.
Does achieving HITRUST certification satisfy the Breach Notification Rule?
No. HITRUST certification, based on the HITRUST CSF, is a private framework and does not by itself establish compliance with the Breach Notification Rule or any other HIPAA requirement. While a strong control environment may help an organization prevent, detect, and respond to incidents, the legal obligations under the Breach Notification Rule are enforced by HHS OCR and exist independently of any certification. Organizations should treat certification as a supporting measure, not a substitute for meeting the rule's requirements, and should verify their obligations against the current regulation.

Common misconceptions

The Breach Notification Rule applies only to electronic PHI, like the Security Rule.
The Breach Notification Rule applies to breaches of unsecured PHI in all forms, including oral and paper, not only electronic PHI. The scope tied exclusively to ePHI belongs to the Security Rule, which is a separate rule.
Every impermissible use or disclosure of PHI automatically counts as a reportable breach.
An impermissible use or disclosure is generally presumed to be a breach, but this presumption can be overcome through a documented risk assessment demonstrating a low probability that the PHI was compromised. Certain exceptions may also apply. The presumption is rebuttable, not absolute.
Achieving HITRUST CSF certification satisfies the Breach Notification Rule and eliminates the need for breach reporting.
HITRUST is a private organization and its CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. The Breach Notification Rule is a federal obligation enforced by HHS OCR, and its notification requirements apply regardless of certification status.

Best practices

Establish and document a formal breach risk assessment process that evaluates the factors relevant under the rule, and retain that documentation to support any determination that notification was or was not required.
Maintain clear breach notification procedures with defined internal roles and timelines so that discovery of an incident can trigger prompt evaluation and, where required, notification to individuals, HHS, and media within applicable deadlines.
Address breach notification responsibilities explicitly in business associate agreements, including the timing and content of notice a business associate must provide to the covered entity following discovery.
Consider rendering PHI unusable, unreadable, or indecipherable through methods such as encryption or secure destruction consistent with HHS guidance, recognizing that this may reduce notification obligations for secured PHI but does not guarantee compliance with all HIPAA requirements.
Verify current notification deadlines, breach reporting thresholds, and penalty figures against the current regulatory text and current HHS OCR guidance, as these are adjusted over time.
Review applicable state breach notification laws and any additional HITECH Act requirements, which may impose obligations beyond those in the federal Breach Notification Rule.