Skip to main content
Category: Breach Notification

Date of Discovery

Also known as: Discovery Date
Simply put

In the HIPAA context, the date of discovery generally refers to the point at which a breach of protected health information is first known, or reasonably should have been known, to the organization responsible for the information. This date is important because it typically starts the clock for breach notification obligations. Note: the evidence packet provided does not contain HIPAA-specific source material defining this term, so the description here reflects general usage and should be verified against the current HIPAA Breach Notification Rule and HHS OCR guidance.

Formal definition

The concept of a 'date of discovery' denotes the date on which a party obtains valid knowledge or proof that a triggering event has occurred. In one non-HIPAA administrative context, it is defined as the date an oversight unit 'has valid proof that an overpayment exists' (see Source 1), illustrating the general pattern that the date of discovery is tied to when reliable knowledge of an event is established rather than when the event itself occurred. The evidence packet does not include authoritative HIPAA sources; under the HIPAA Breach Notification Rule the operative discovery standard and the resulting notification timelines are set by HHS OCR and applicable regulatory text, and practitioners should confirm the specific definition, deadlines, and knowledge-attribution rules against the current regulation. State breach-notification laws and the HITECH Act may impose additional or differing requirements beyond HIPAA.

Why it matters

In the HIPAA breach notification context, the date of discovery is significant because it generally starts the clock for an organization's notification obligations. Under the HIPAA Breach Notification Rule, the timelines for notifying affected individuals, HHS OCR, and in some cases the media are tied to when a breach is discovered rather than when it actually occurred. An error in identifying or documenting this date can cascade into missed deadlines and potential enforcement exposure, so precision here matters to both covered entities and business associates.

A notable feature of the discovery standard is that it typically turns not only on when a breach is actually known, but also on when it reasonably should have been known to the organization. This 'known or reasonably should have been known' concept generally means an organization cannot avoid its obligations by failing to investigate or by ignoring indicators of a possible breach. Because knowledge may be attributed to the organization based on what its workforce members or agents knew or should have known, internal detection, escalation, and documentation practices directly affect when the discovery clock is deemed to start.

The evidence packet provided does not contain HIPAA-specific authoritative source material defining this term; the discussion here reflects general usage and the broader pattern that a 'date of discovery' is tied to when reliable knowledge of a triggering event is established. Practitioners should verify the specific definition, deadlines, and knowledge-attribution rules against the current HIPAA Breach Notification Rule and HHS OCR guidance, and should note that the HITECH Act and state breach-notification laws may impose additional or differing requirements.

Who it's relevant to

Privacy and Security Officers
These officers generally rely on the date of discovery to determine when notification timelines begin. They typically need internal detection, escalation, and documentation processes that establish when a potential breach became known or reasonably should have been known, and should confirm the applicable standard and deadlines against the current HIPAA Breach Notification Rule and HHS OCR guidance.
Business Associates and Subcontractors
Business associates, and their subcontractors, generally have breach notification obligations that flow through business associate agreements. The date they discover a breach can affect when they must notify the covered entity, so understanding how discovery is determined is relevant even though HIPAA obligations attach through these defined contractual relationships rather than to every vendor generally.
Compliance and Legal Professionals
Compliance officers and legal counsel typically assess whether notification obligations have been triggered and whether deadlines have been met, using the date of discovery as a starting reference. They should verify the specific discovery standard and timelines against current regulation, and account for the possibility that the HITECH Act and state breach-notification laws impose additional or differing requirements.
Auditors and Incident Responders
Those who investigate and document security incidents help establish when an organization obtained valid knowledge of a breach, which informs the date of discovery. Accurate, contemporaneous documentation of detection and escalation is generally important for demonstrating when the discovery clock started.

Inside Date of Discovery

Discovery Standard
Under the Breach Notification Rule, a breach is generally treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to the covered entity or business associate. This 'known or should have known' standard means actual awareness is not required to trigger the discovery clock.
Knowledge Attribution
Knowledge of a breach is generally imputed to a covered entity or business associate if any person, other than the individual committing the breach, who is a workforce member or agent of the entity, knew or should have known of it. This affects when the date of discovery is deemed to occur.
Reasonable Diligence Element
The date of discovery is tied to the exercise of reasonable diligence, generally understood as the business care and prudence expected of a person seeking to satisfy a legal requirement under similar circumstances. Entities cannot indefinitely delay discovery by failing to investigate.
Trigger for Notification Timelines
The date of discovery is the starting point from which notification deadlines to affected individuals, HHS OCR, and, where applicable, the media are generally measured. Business associates typically must notify the covered entity following discovery, though specific timing may be set by the business associate agreement.
Business Associate Considerations
When a breach occurs at a business associate that is an agent of the covered entity, the business associate's date of discovery may be attributed to the covered entity. The precise allocation of discovery and notification duties often depends on the terms of the business associate agreement and applicable agency principles.

Common questions

Answers to the questions practitioners most commonly ask about Date of Discovery.

Does the breach notification clock start when the organization confirms a breach occurred?
No. This is a common misconception. Under the HIPAA Breach Notification Rule, a breach is generally treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to the covered entity or business associate. The clock does not wait for a completed investigation or formal confirmation. Notification timelines generally run from the date of discovery, not the date the incident is fully verified. You should confirm the specific timing requirements against the current regulatory text, and note that state laws or the HITECH Act may impose additional or shorter timeframes.
Is a breach only considered discovered once senior management or the privacy officer becomes aware of it?
Not necessarily. Knowledge is generally imputed to the organization when the breach is known, or should have been known through reasonable diligence, to any workforce member or agent other than the individual who committed the breach. This means discovery can occur at the staff level, not just at the management or privacy officer level. Because of this, discovery may predate awareness by leadership. Readers should verify how agency principles apply in their specific circumstances against current guidance.
How does the date of discovery differ between a covered entity and a business associate?
For a covered entity, discovery is generally measured from when the covered entity or its workforce first knew or should have known of the breach. For a business associate, discovery is measured from when the business associate knew or should have known. When a business associate experiences a breach, the timing of its notification to the covered entity, and how that affects the covered entity's own obligations, is typically governed by the business associate agreement. Organizations should review their BAAs to confirm how discovery and notification timing are allocated.
What should we document to establish the date of discovery?
Organizations generally maintain records showing when and how an incident was first identified, who identified it, and the steps taken through reasonable diligence. Contemporaneous documentation such as help desk tickets, incident logs, and escalation timestamps can help support a defensible discovery date. This documentation is also generally useful if HHS OCR later reviews the organization's response. You should align your documentation practices with the current regulatory text and any applicable state requirements.
How does the date of discovery relate to the notification deadlines?
Notification timelines under the Breach Notification Rule generally run from the date of discovery rather than from any later point in the investigation. Because the exact number of days and the outer limits are set by regulation and can be affected by other authorities, you should confirm the specific deadlines against the current regulatory text. Note that state law or other frameworks may require faster notification than HIPAA.
Can the date of discovery be delayed while we complete a risk assessment?
No. Conducting a risk assessment to determine whether an impermissible use or disclosure is a reportable breach does not postpone the date of discovery. The discovery date is generally fixed at the point the incident was first known or should have been known through reasonable diligence, and the assessment occurs after that point. The time needed for the assessment generally falls within, and does not extend, the notification period. Confirm these expectations against current HHS guidance.

Common misconceptions

The date of discovery is only the date an entity actually confirms a breach occurred.
The standard is generally 'known or, by exercising reasonable diligence, would have been known.' An entity can be deemed to have discovered a breach even before actual confirmation if reasonable diligence should have surfaced it. Readers should verify the precise language against the current Breach Notification Rule text.
The notification clock only starts once the entity finishes its full investigation and risk assessment.
In most cases, applicable notification timelines are generally measured from the date of discovery rather than from the conclusion of an investigation. Investigation and any risk assessment typically proceed within, not before, the notification window. Confirm specific timeframes against current regulatory guidance.
Only knowledge held by senior management or the privacy officer counts as discovery.
Knowledge is generally imputed to the entity if any workforce member or agent (other than the person who committed the breach) knew or should have known. Awareness is not limited to designated compliance staff. State law or the HITECH Act may impose additional considerations.

Best practices

Establish and document internal reporting channels so that any workforce member who identifies a potential breach can promptly escalate it, since knowledge may be imputed to the entity through any workforce member or agent.
Log the date and time a potential breach is first known or reasonably should have been known, and maintain records supporting the reasonable diligence exercised, to substantiate the date of discovery if questioned.
Treat the date of discovery, not the conclusion of the investigation, as the start of applicable notification timelines, and confirm the specific deadlines against the current Breach Notification Rule and any stricter state law requirements.
Define discovery and notification obligations explicitly in business associate agreements, including how quickly a business associate must report to the covered entity following its own discovery.
Provide workforce training so staff recognize potential breaches and understand their duty to report, reducing the gap between when a breach occurs and when it is discovered through reasonable diligence.
Coordinate with legal counsel and, where applicable, verify obligations under the HITECH Act, state breach laws, and any HITRUST CSF controls in use, recognizing that HITRUST certification does not by itself establish HIPAA compliance.