Business Associate Breach Reporting
Business associate breach reporting refers to the obligation of a business associate to tell the covered entity it works for when unsecured protected health information (PHI) is breached. The business associate generally must provide this notice without unreasonable delay and no later than 60 days after discovering the breach. The covered entity then typically carries the responsibility for notifying affected individuals and other required parties.
Under the HIPAA Breach Notification Rule (generally codified at 45 CFR § 164.410), a business associate that discovers a breach of unsecured protected health information must notify the affected covered entity of the breach. This notification must generally be made without unreasonable delay and in no case later than 60 calendar days following discovery of the breach, and it typically must identify the individuals whose unsecured PHI was, or is reasonably believed to have been, affected. This obligation is distinct from the covered entity's own downstream notification duties (to individuals, HHS OCR, and, where applicable, the media); the business associate's core role under this provision is upstream reporting to the covered entity rather than direct notification of individuals, unless otherwise specified by the business associate agreement. The precise timing, content, and any delegation of notice duties may be shaped by the terms of the business associate agreement, and subcontractors have analogous obligations to the business associates they serve. Readers should confirm specific requirements, deadlines, and the applicable regulatory text against the current Breach Notification Rule, and should note that the HITECH Act and state breach notification laws may impose additional or stricter requirements.
Why it matters
Business associate breach reporting is the mechanism that keeps a covered entity informed when unsecured PHI is compromised outside its own walls. Because a great deal of PHI is handled by vendors, cloud providers, billing companies, and other service organizations, a breach frequently occurs at a business associate rather than at the covered entity itself. If the business associate does not report the incident upstream in a timely manner, the covered entity cannot fulfill its own downstream notification duties to affected individuals, HHS OCR, and, where applicable, the media. In this sense, the business associate's reporting obligation is a critical link in the broader chain of breach response.
The timing matters because delays compound. The Breach Notification Rule generally requires a business associate to notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering the breach. A late or incomplete report from a business associate can leave a covered entity scrambling to meet its own deadlines, which are themselves keyed to when a breach is discovered. Clear, prompt, and well-documented reporting therefore protects both parties and helps ensure affected individuals receive notice they can act on.
Because the precise timing, content, and any delegation of notice duties are often shaped by the business associate agreement, organizations should treat these reporting provisions as substantive rather than boilerplate. Note also that the HITECH Act and state breach notification laws may impose additional or stricter requirements, so meeting the federal 60-day outer limit does not necessarily satisfy every obligation. Readers should confirm specific deadlines and content requirements against the current Breach Notification Rule and applicable state law.
Who it's relevant to
Inside Business Associate Breach Reporting
Common questions
Answers to the questions practitioners most commonly ask about Business Associate Breach Reporting.