Skip to main content
Category: Breach Notification

HHS Breach Portal

Also known as: OCR Breach Portal, Breach Reporting Portal, Notice to the Secretary of HHS Breach of Unsecured Protected Health Information, HHS Breach Reporting Tool
Simply put

The HHS Breach Portal is an online tool operated by the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) that covered entities and business associates use to notify the Secretary of HHS about breaches of unsecured protected health information. It is also the public-facing website where certain reported breaches are listed. Reports are submitted electronically by completing the required fields in the online breach notification form.

Formal definition

The HHS Breach Portal is the OCR-operated electronic system through which regulated parties submit the notice to the Secretary required under the HIPAA Breach Notification Rule for breaches of unsecured protected health information (PHI). Submission is made electronically, with all required fields of the breach notification form completed. The portal also supports OCR's public-facing breach list, which, according to the evidence, displays HIPAA breaches reported within the last 24 months that are currently under investigation; OCR investigates breaches of PHI and Part 2 records affecting 500 or more individuals. Note that the portal is a reporting and disclosure mechanism, not a source of the substantive breach-notification obligations themselves. This entry does not address the timing thresholds for reporting breaches affecting fewer than 500 individuals versus 500 or more, individual and media notification requirements, or the risk-assessment standards used to determine whether an impermissible use or disclosure constitutes a reportable breach; practitioners should verify current reporting deadlines, thresholds, and form requirements against the current Breach Notification Rule and OCR guidance, and should be aware that the HITECH Act and state breach-notification laws may impose additional or overlapping obligations.

Why it matters

The HHS Breach Portal is the official channel through which covered entities and business associates satisfy their obligation to notify the Secretary of HHS following a breach of unsecured protected health information. Because notification to the Secretary is a distinct requirement under the HIPAA Breach Notification Rule, the portal is a practical focal point in any breach-response workflow: knowing how and where to submit the notice is essential to meeting regulatory expectations. The portal is a reporting and disclosure mechanism, however, not the source of the underlying obligation itself, so compliance depends on correctly applying the substantive rules that determine whether a reportable breach has occurred.

Who it's relevant to

Covered entities
Covered entities use the HHS Breach Portal to submit the required notice to the Secretary following a breach of unsecured protected health information. Because breaches affecting 500 or more individuals are investigated by OCR and may appear on the public breach list, covered entities should integrate portal submission into a broader breach-response process that also addresses individual and media notification and the risk assessment used to determine whether an incident is reportable.
Business associates and subcontractors
Business associates that experience a breach have reporting responsibilities that flow through their business associate agreements and the Breach Notification Rule. In many cases the covered entity submits the notice to the Secretary, but business associates should understand the portal, coordinate with their covered-entity partners, and confirm through their agreements who is responsible for notifying the Secretary and within what timeframe.
Privacy and security officers
Privacy and security officers responsible for incident response need to know how to complete and submit the breach notification form and to retain the confirmation the portal generates. They should also account for the possibility that a large-scale breach becomes publicly visible on OCR's list while under investigation, and should verify current thresholds and deadlines against OCR guidance.
Compliance officers and legal counsel
Compliance officers and counsel should treat the portal as one component of a coordinated breach response, recognizing that it is a reporting mechanism rather than the source of substantive obligations. They should evaluate whether the HITECH Act and applicable state breach-notification laws impose additional or overlapping duties beyond HIPAA and confirm current requirements against the Breach Notification Rule.

Inside HHS Breach Portal

Public Breach List (the "Wall of Shame")
A publicly accessible listing maintained by HHS OCR of reported breaches of unsecured protected health information affecting 500 or more individuals. It is commonly referred to informally as the 'Wall of Shame.'
Covered Entity and Business Associate Information
Entries typically identify the reporting covered entity or business associate involved in the breach, reflecting the relationship structure under HIPAA where obligations attach through defined roles.
Breach Characteristics
Reported details generally include the approximate number of individuals affected, the type of breach (such as hacking/IT incident, unauthorized access/disclosure, theft, or loss), and the location or type of protected health information involved. Specific field labels and categories should be verified against the current portal.
Reporting Mechanism
The portal also serves as the electronic submission channel through which covered entities report breaches to HHS OCR as required under the Breach Notification Rule. Readers should confirm current submission requirements and timelines against current OCR guidance.
Investigation and Resolution Status
Listings may reflect the status of OCR's review, including breaches under investigation and archived or resolved matters, subject to how the portal is currently organized.

Common questions

Answers to the questions practitioners most commonly ask about HHS Breach Portal.

Is a breach only reportable if it appears on the HHS Breach Portal?
No. The publicly viewable HHS Breach Portal (often called the 'Wall of Shame') generally displays breaches affecting 500 or more individuals, but reporting obligations under the Breach Notification Rule are not limited to those large breaches. Covered entities must also report breaches affecting fewer than 500 individuals, typically on an annual basis, and these smaller breaches are generally not listed on the public portal. The absence of an entry on the public portal does not mean an incident was not reportable. Confirm current reporting thresholds and timeframes against the applicable regulatory text.
Does submitting a breach report through the HHS Breach Portal by itself satisfy all breach notification requirements?
No. Notifying HHS through the portal is only one component of the Breach Notification Rule. Covered entities generally must also notify affected individuals, and in the case of breaches affecting 500 or more residents of a state or jurisdiction, notify prominent media outlets, within the applicable timeframes. Business associates typically must notify the covered entity rather than filing directly. Filing with HHS does not replace these other obligations, and state law or other frameworks may impose additional notification requirements. Verify the full set of obligations against current guidance.
Who is responsible for submitting a report through the HHS Breach Portal?
Under the Breach Notification Rule, the covered entity generally bears the responsibility for reporting breaches to HHS. When a breach occurs at or involves a business associate, the business associate is typically obligated to notify the covered entity, and the terms of the business associate agreement may address which party actually files the report. In most cases, however, the ultimate reporting obligation to HHS rests with the covered entity. Confirm the specific allocation of responsibilities in your business associate agreements and against current regulatory guidance.
What information is generally needed to complete a submission on the HHS Breach Portal?
Submissions typically request details such as the type of breach, the type of PHI involved, the approximate number of individuals affected, the dates of the breach and its discovery, a description of what happened, and the safeguards and remediation steps taken. Because the specific fields and requirements can change, organizations should review the current portal submission form and any accompanying HHS instructions before filing rather than relying on a fixed checklist.
How should an organization handle the difference between large and small breach reporting timeframes on the portal?
Breaches affecting 500 or more individuals generally must be reported to HHS without unreasonable delay and within the applicable outer time limit following discovery, while breaches affecting fewer than 500 individuals are typically reported on an annual basis for breaches discovered during the prior calendar year. Organizations should maintain an internal log of smaller breaches throughout the year to support timely annual reporting. Verify the exact deadlines against the current regulatory text, as timeframes should be confirmed against current guidance.
Should breach reporting through the portal be the extent of an organization's incident documentation?
Generally no. The portal submission is a regulatory filing, not a substitute for internal documentation. Organizations typically should maintain their own records of the risk assessment used to determine whether an incident constituted a reportable breach, the notifications issued, and the remediation performed, as this documentation may be needed to demonstrate compliance during an OCR inquiry. Retention obligations and the level of detail required should be confirmed against current guidance, and state law or other frameworks may impose additional documentation expectations.

Common misconceptions

All breaches, regardless of size, appear on the public HHS Breach Portal.
The public list generally reflects breaches of unsecured protected health information affecting 500 or more individuals. Smaller breaches are still reportable to OCR, but under different reporting timing and are generally not published on the public list in the same manner. Verify current thresholds and reporting requirements against the Breach Notification Rule and current OCR guidance.
Appearing on the portal automatically means the entity violated HIPAA and will be penalized.
A listing reflects that a reportable breach was disclosed to OCR; it does not by itself establish a HIPAA violation or a penalty. OCR, the enforcement authority for HIPAA, determines whether a violation occurred and any resulting action. Penalty tiers and figures are adjusted over time and should be confirmed against current OCR guidance.
The portal only lists covered entities, so business associates need not worry about it.
Reported breaches can involve business associates, and business associate obligations flow through business associate agreements and the Breach Notification Rule. Business associates may be identified in connection with reported breaches, so they are not outside the portal's scope.

Best practices

Treat the portal as a reference for understanding common breach types and patterns, but confirm current reporting thresholds, timelines, and submission requirements against the Breach Notification Rule and current OCR guidance before acting.
Establish an internal breach response process that determines, on a case-by-case basis, whether an incident is a reportable breach and which reporting pathway applies based on the number of individuals affected.
Ensure breach notification and reporting responsibilities between covered entities and business associates are clearly allocated in business associate agreements so the correct party submits to OCR.
Maintain accurate documentation of breach assessments, affected individual counts, and remediation, since this supports timely and consistent submissions and any subsequent OCR review.
Do not treat absence from the public list as evidence of compliance, and do not assume a listing alone establishes a violation; verify enforcement outcomes and current penalty information against current OCR guidance.
Remember that HIPAA is not the only source of obligations; state breach laws and the HITECH Act may impose additional or stricter requirements, and HITRUST CSF certification does not by itself satisfy these reporting duties.