HHS Breach Portal
The HHS Breach Portal is an online tool operated by the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) that covered entities and business associates use to notify the Secretary of HHS about breaches of unsecured protected health information. It is also the public-facing website where certain reported breaches are listed. Reports are submitted electronically by completing the required fields in the online breach notification form.
The HHS Breach Portal is the OCR-operated electronic system through which regulated parties submit the notice to the Secretary required under the HIPAA Breach Notification Rule for breaches of unsecured protected health information (PHI). Submission is made electronically, with all required fields of the breach notification form completed. The portal also supports OCR's public-facing breach list, which, according to the evidence, displays HIPAA breaches reported within the last 24 months that are currently under investigation; OCR investigates breaches of PHI and Part 2 records affecting 500 or more individuals. Note that the portal is a reporting and disclosure mechanism, not a source of the substantive breach-notification obligations themselves. This entry does not address the timing thresholds for reporting breaches affecting fewer than 500 individuals versus 500 or more, individual and media notification requirements, or the risk-assessment standards used to determine whether an impermissible use or disclosure constitutes a reportable breach; practitioners should verify current reporting deadlines, thresholds, and form requirements against the current Breach Notification Rule and OCR guidance, and should be aware that the HITECH Act and state breach-notification laws may impose additional or overlapping obligations.
Why it matters
The HHS Breach Portal is the official channel through which covered entities and business associates satisfy their obligation to notify the Secretary of HHS following a breach of unsecured protected health information. Because notification to the Secretary is a distinct requirement under the HIPAA Breach Notification Rule, the portal is a practical focal point in any breach-response workflow: knowing how and where to submit the notice is essential to meeting regulatory expectations. The portal is a reporting and disclosure mechanism, however, not the source of the underlying obligation itself, so compliance depends on correctly applying the substantive rules that determine whether a reportable breach has occurred.
Who it's relevant to
Inside HHS Breach Portal
Common questions
Answers to the questions practitioners most commonly ask about HHS Breach Portal.