Skip to main content
Category: Breach Notification

Business Associate Breach Reporting

Also known as: Notification by a Business Associate, Business Associate Breach Notification
Simply put

Business associate breach reporting refers to the obligation of a business associate to tell the covered entity it works for when unsecured protected health information (PHI) is breached. The business associate generally must provide this notice without unreasonable delay and no later than 60 days after discovering the breach. The covered entity then typically carries the responsibility for notifying affected individuals and other required parties.

Formal definition

Under the HIPAA Breach Notification Rule (generally codified at 45 CFR § 164.410), a business associate that discovers a breach of unsecured protected health information must notify the affected covered entity of the breach. This notification must generally be made without unreasonable delay and in no case later than 60 calendar days following discovery of the breach, and it typically must identify the individuals whose unsecured PHI was, or is reasonably believed to have been, affected. This obligation is distinct from the covered entity's own downstream notification duties (to individuals, HHS OCR, and, where applicable, the media); the business associate's core role under this provision is upstream reporting to the covered entity rather than direct notification of individuals, unless otherwise specified by the business associate agreement. The precise timing, content, and any delegation of notice duties may be shaped by the terms of the business associate agreement, and subcontractors have analogous obligations to the business associates they serve. Readers should confirm specific requirements, deadlines, and the applicable regulatory text against the current Breach Notification Rule, and should note that the HITECH Act and state breach notification laws may impose additional or stricter requirements.

Why it matters

Business associate breach reporting is the mechanism that keeps a covered entity informed when unsecured PHI is compromised outside its own walls. Because a great deal of PHI is handled by vendors, cloud providers, billing companies, and other service organizations, a breach frequently occurs at a business associate rather than at the covered entity itself. If the business associate does not report the incident upstream in a timely manner, the covered entity cannot fulfill its own downstream notification duties to affected individuals, HHS OCR, and, where applicable, the media. In this sense, the business associate's reporting obligation is a critical link in the broader chain of breach response.

The timing matters because delays compound. The Breach Notification Rule generally requires a business associate to notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering the breach. A late or incomplete report from a business associate can leave a covered entity scrambling to meet its own deadlines, which are themselves keyed to when a breach is discovered. Clear, prompt, and well-documented reporting therefore protects both parties and helps ensure affected individuals receive notice they can act on.

Because the precise timing, content, and any delegation of notice duties are often shaped by the business associate agreement, organizations should treat these reporting provisions as substantive rather than boilerplate. Note also that the HITECH Act and state breach notification laws may impose additional or stricter requirements, so meeting the federal 60-day outer limit does not necessarily satisfy every obligation. Readers should confirm specific deadlines and content requirements against the current Breach Notification Rule and applicable state law.

Who it's relevant to

Business Associates
Vendors and service organizations that create, receive, maintain, or transmit PHI on behalf of a covered entity are directly subject to this reporting obligation. They should have processes to detect breaches, determine the discovery date, identify affected individuals, and notify the covered entity within the timeframe set by the rule and their business associate agreement.
Covered Entities
Covered entities depend on timely upstream reports from their business associates to meet their own downstream notification duties. They should ensure their business associate agreements clearly specify reporting timing and content, and should confirm whether any notification responsibilities have been delegated to the business associate.
Subcontractors
Subcontractors that handle PHI on behalf of a business associate have analogous reporting obligations to the business associate they serve. Breach information may need to flow up through multiple tiers before reaching the covered entity, so subcontractors should understand their place in this chain.
Privacy and Compliance Officers
Those responsible for breach response programs should coordinate the interplay between business associate reports and the organization's own notification obligations, track applicable deadlines, and verify that contractual terms align with current regulatory requirements and any stricter state or HITECH Act provisions.
Legal and Contracting Teams
Because timing, content, and delegation of notice duties can be shaped by the business associate agreement, legal and contracting professionals play a key role in drafting reporting provisions that meet the rule's outer limits while addressing state law and other applicable requirements.

Inside Business Associate Breach Reporting

Business Associate Discovery of a Breach
The point at which a business associate knows, or by exercising reasonable diligence would have known, of a breach of unsecured protected health information. Discovery is generally the trigger that starts applicable notification timelines. Readers should verify current timing requirements against the Breach Notification Rule as enforced by HHS OCR.
Notification to the Covered Entity
Under the Breach Notification Rule, a business associate that discovers a breach is generally required to notify the affected covered entity. In most cases the covered entity, not the business associate, then carries the primary obligation to notify affected individuals, HHS, and (where applicable) the media, though these responsibilities can be reallocated by contract.
Content of the Report
The notification to the covered entity generally must include, to the extent possible, the identification of individuals whose unsecured PHI was or is reasonably believed to have been affected, along with other information the covered entity needs to meet its own notification obligations. Specific required elements should be confirmed against the current regulatory text.
Role of the Business Associate Agreement (BAA)
The BAA between the covered entity and business associate typically specifies breach reporting timing, content, and the division of notification duties. Obligations flow through this defined contractual relationship; the BAA may impose reporting terms that are stricter than the regulatory baseline but cannot waive underlying legal duties.
Subcontractor Reporting Chain
A subcontractor that creates, receives, maintains, or transmits ePHI or PHI on behalf of a business associate is itself treated as a business associate under HIPAA. Breach reporting obligations generally flow up the chain from subcontractor to business associate to covered entity, governed by the agreements at each level.
Unsecured PHI and the Risk Assessment
The reporting obligation applies to breaches of unsecured PHI (PHI not rendered unusable, unreadable, or indecipherable through methods recognized by HHS guidance). Whether an impermissible use or disclosure constitutes a reportable breach generally depends on a risk assessment of the probability that PHI was compromised, subject to any applicable exceptions in the rule.

Common questions

Answers to the questions practitioners most commonly ask about Business Associate Breach Reporting.

Does a business associate report a breach directly to HHS OCR?
Generally, no. Under the Breach Notification Rule, a business associate's primary obligation is typically to notify the covered entity (or, for a subcontractor, the business associate that engaged it) rather than to report directly to HHS OCR. It is usually the covered entity that carries the obligation to notify affected individuals, HHS OCR, and, where applicable, the media. Parties may allocate certain reporting responsibilities by contract, so the specific division of duties should be confirmed against the business associate agreement and the current regulatory text. Note that state law or other frameworks may impose additional notification requirements beyond HIPAA.
Does discovery of any impermissible use or disclosure by a business associate automatically count as a reportable breach?
Not automatically. Under the Breach Notification Rule, an impermissible acquisition, access, use, or disclosure of PHI is generally presumed to be a breach unless the business associate or covered entity demonstrates a low probability that the PHI has been compromised, typically through a risk assessment considering factors such as the nature of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated. Certain regulatory exceptions may also apply. The applicable analysis should be confirmed against the current regulation.
How quickly must a business associate notify the covered entity after discovering a breach?
The Breach Notification Rule generally requires notification without unreasonable delay and within a defined outer time limit measured from discovery. Business associate agreements frequently specify a shorter internal deadline to give the covered entity adequate time to meet its own downstream obligations. Because the specific timeframe carries a precise regulatory meaning and BAAs vary, confirm the exact deadline against the current regulatory text and the governing agreement before relying on it.
What information should a business associate include in its breach notification to the covered entity?
Notifications generally should identify each affected individual to the extent known and provide the information the covered entity needs to fulfill its own notification duties, such as a description of what occurred, the types of PHI involved, and any steps taken to investigate and mitigate. The specific content elements have defined regulatory meaning, and the business associate agreement may require additional detail. Verify required contents against the current Breach Notification Rule provisions.
How should breach reporting responsibilities be addressed in a business associate agreement?
A business associate agreement typically documents how and when the business associate must report breaches, what information it must supply, and how discovery is defined. Parties may allocate certain notification tasks by contract, but such allocation does not remove the covered entity's underlying regulatory accountability. Because contract terms interact with the regulation, agreements should be drafted or reviewed against the current regulatory requirements and, where relevant, applicable state law.
How do subcontractor breaches flow up through the reporting chain?
Obligations under HIPAA generally attach through defined relationships. A subcontractor that creates, receives, maintains, or transmits PHI is itself treated as a business associate and typically reports breaches to the business associate that engaged it, which in turn reports to the covered entity. Each link in the chain should have an agreement addressing breach reporting. The precise flow and timing should be confirmed against the governing agreements and the current regulatory text.

Common misconceptions

A business associate must notify affected individuals and HHS directly whenever it discovers a breach.
In most cases the business associate's primary duty under the Breach Notification Rule is to notify the covered entity, which then typically handles notification to individuals and HHS. These duties can be reallocated in the BAA, but the default structure places direct notification on the covered entity.
If a business associate holds HITRUST CSF certification, it has satisfied its HIPAA breach reporting obligations.
HITRUST is a private organization and its CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA compliance or relieve a business associate of its breach reporting duties under the HIPAA Breach Notification Rule enforced by HHS OCR.
Any impermissible use or disclosure by a business associate is automatically a reportable breach.
The rule generally requires a risk assessment of the probability that PHI was compromised, and certain exceptions may apply. In addition, breaches of secured PHI (rendered unusable, unreadable, or indecipherable per HHS guidance) are generally outside the reporting obligation. Specific determinations should be confirmed against the current regulation.

Best practices

Define breach reporting timelines, required content, and the allocation of notification duties explicitly in every business associate agreement, and ensure equivalent terms flow down to subcontractors.
Establish and document a discovery-to-report workflow so that when a breach is known or reasonably should be known, notification to the covered entity is prompt and consistent with the BAA and the applicable regulatory timeframe.
Perform and document a risk assessment for each impermissible use or disclosure to determine whether it is a reportable breach of unsecured PHI, retaining evidence of the analysis.
Track whether affected PHI was secured under recognized HHS methods, since properly secured PHI generally falls outside the reporting obligation.
Maintain the information the covered entity will need to meet its own obligations, including identification of affected individuals to the extent possible, and coordinate to avoid duplicated or conflicting notifications.
Verify current breach notification timing, content requirements, and any HITECH Act or state-law obligations against the current regulatory text, as state law may impose additional or stricter requirements beyond HIPAA.