Skip to main content
Category: Breach Notification

Individual Notice

Simply put

Individual notice generally refers to the requirement that affected people be directly informed when their protected health information may have been involved in a breach. In most cases this means a covered entity sends a notification to each affected individual so they are aware of what happened and can take protective steps. The evidence provided does not contain HIPAA-specific source material, so the details below should be verified against the current HIPAA Breach Notification Rule and HHS OCR guidance.

Formal definition

Within the HIPAA framework, 'individual notice' typically denotes the obligation under the Breach Notification Rule for a covered entity to notify affected individuals following a breach of unsecured protected health information, generally through written notice sent to the individual's last known address or by other permitted means. This concept aligns broadly with the general legal principle of notice, which the Legal Information Institute describes as the requirement that a party whose rights may be affected be informed of an action affecting those interests. Specific content requirements, timing deadlines, and substitute-notice provisions are set by the applicable regulatory text and are not established by the evidence packet provided; readers should confirm these against the current Breach Notification Rule and current HHS OCR guidance. Note that this term is distinct from a Notice of Privacy Practices under the Privacy Rule, and that state law or the HITECH Act may impose additional notification obligations beyond HIPAA. The provided sources address unrelated tax and privacy-notice contexts and do not substantiate HIPAA-specific requirements.

Why it matters

Individual notice sits at the heart of how the HIPAA Breach Notification Rule protects people whose protected health information may have been compromised. When affected individuals are informed directly, they can take practical protective steps such as monitoring accounts, watching for identity theft, or requesting corrections. Without direct notice, the people most at risk from a breach would generally have no way of knowing their information was involved or that they should act to protect themselves.

For covered entities, getting individual notice right is a compliance obligation as well as a matter of trust. HHS OCR enforces the Breach Notification Rule, and failures to notify affected individuals appropriately can factor into enforcement outcomes. Because the specific content, timing, and delivery requirements are set by the regulatory text rather than by the general legal concept of notice, organizations should treat individual notice as a defined process to be documented and executed, not an ad hoc communication.

The evidence provided for this entry addresses unrelated tax and privacy-notice contexts and does not substantiate HIPAA-specific requirements. As a result, the practical details of individual notice, including deadlines and required content, should be confirmed against the current HIPAA Breach Notification Rule and current HHS OCR guidance before being relied upon.

Who it's relevant to

Privacy and Security Officers
These officers are typically responsible for operationalizing individual notice as part of an organization's breach response process. They need to understand how the general legal principle of notice maps onto the specific requirements of the Breach Notification Rule, and should verify content, timing, and delivery method details against current HHS OCR guidance rather than relying on general definitions.
Covered Entities
Covered entities generally bear the primary obligation to notify affected individuals following a breach of unsecured protected health information. They should maintain documented procedures for identifying affected individuals and delivering notice through permitted means, confirming all specifics against the current Breach Notification Rule.
Compliance and Legal Professionals
Legal and compliance staff advising on breach response must distinguish individual notice under the Breach Notification Rule from a Notice of Privacy Practices under the Privacy Rule, and should account for additional notification obligations that state law or the HITECH Act may impose beyond HIPAA.
Auditors
Auditors reviewing an organization's breach readiness may assess whether documented individual-notice procedures exist and align with current regulatory requirements. Because specific deadlines and content elements are set by the regulatory text, auditors should benchmark practices against the current Breach Notification Rule and HHS OCR guidance rather than general notice concepts.

Inside Individual Notice

Notification Trigger
Individual notice is generally required following the discovery of a breach of unsecured protected health information (PHI) affecting an individual, as provided under the HIPAA Breach Notification Rule enforced by HHS OCR.
Recipient
The notice is directed to each individual whose unsecured PHI was, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach.
Content Elements
The notice generally includes a description of what happened, the types of information involved, steps individuals should take to protect themselves, what the covered entity is doing to investigate and mitigate, and contact procedures for obtaining more information.
Method of Delivery
Individual notice is typically provided in writing by first-class mail to the individual's last known address, or by electronic mail if the individual has agreed to electronic notice. Substitute notice methods may apply where contact information is insufficient or out of date.
Timing
Notice is generally required without unreasonable delay and no later than a defined period following discovery of the breach. The specific deadline should be confirmed against the current text of the Breach Notification Rule.
Responsible Party
The covered entity generally bears the obligation to provide individual notice. A business associate that discovers a breach typically must notify the covered entity, and specific responsibilities are allocated through the business associate agreement.

Common questions

Answers to the questions practitioners most commonly ask about Individual Notice.

Does providing individual notice satisfy all of a covered entity's breach notification obligations?
No. Individual notice is only one component of the Breach Notification Rule's requirements. Depending on the circumstances, a covered entity may also need to notify HHS OCR and, in certain cases involving larger breaches, prominent media outlets serving the affected area. Business associates generally must notify the covered entity, which then typically carries the notification duties. Individual notice alone does not discharge these separate obligations, and readers should confirm the applicable notification pathways against the current regulation.
Is email an acceptable default method for delivering individual notice?
Not by default. Individual notice is generally required to be provided by written notification by first-class mail to the individual's last known address. Electronic notice, such as email, is typically permitted only where the individual has agreed to receive notices electronically and that agreement has not been withdrawn. Substitute notice methods may apply where contact information is insufficient or out of date. Verify the specific conditions against the current regulatory text.
How quickly must individual notice be sent after a breach is discovered?
Individual notice is generally required to be sent without unreasonable delay and no later than the outer time limit specified in the Breach Notification Rule following discovery of the breach. Because the precise deadline is set by regulation and may be affected by law enforcement delay requests, confirm the current timing requirement and any exceptions against the applicable regulatory text.
What information should be included in an individual notice?
The Breach Notification Rule generally identifies specific content elements, which typically include a brief description of what happened, the types of unsecured PHI involved, steps individuals should take to protect themselves, what the covered entity is doing to investigate and mitigate, and contact procedures for individuals to ask questions. Confirm the full list of required elements against the current regulation, as the wording and scope of each element are defined there.
What should a covered entity do when it cannot reach affected individuals by mail?
When there is insufficient or out-of-date contact information for some or all affected individuals, the rule generally provides for substitute forms of notice. The permitted substitute methods and any triggering thresholds, such as those distinguishing smaller numbers of affected individuals from larger ones, are set by regulation, so verify the specific approach and any website posting or toll-free number requirements against the current regulatory text.
Who is responsible for sending individual notice when a business associate causes the breach?
In most cases, individual notice is the covered entity's responsibility. When a breach occurs at or is caused by a business associate, the business associate generally must notify the covered entity, and the covered entity then typically issues the individual notice. Responsibilities can be allocated through the business associate agreement, so parties should review those terms and confirm the applicable obligations against the current regulation.

Common misconceptions

Individual notice is required for any incident involving PHI.
Notice obligations under the Breach Notification Rule generally attach to breaches of unsecured PHI. PHI that has been rendered unusable, unreadable, or indecipherable through methods recognized by HHS guidance (such as certain encryption or destruction) may fall outside the notification requirement, and a risk assessment may determine whether an impermissible use or disclosure constitutes a reportable breach. Readers should verify the current standard against the applicable regulatory text.
Business associates are always responsible for sending individual notices.
The obligation to notify affected individuals generally rests with the covered entity. A business associate typically must notify the covered entity of a breach it discovers, and the precise allocation of notification duties is defined through the business associate agreement rather than being imposed directly on every vendor.
Meeting HIPAA individual notice requirements satisfies all applicable breach obligations.
State breach notification laws, the HITECH Act, and other frameworks may impose additional or stricter obligations, including different content, timing, or recipients. Holding a HITRUST CSF certification does not by itself establish compliance with these notice requirements. Practitioners should review all applicable federal and state requirements.

Best practices

Maintain a documented breach response process that specifies who evaluates incidents, how the risk assessment is conducted, and how the individual notice timeline is tracked from the date of discovery.
Keep individual contact information current so that first-class mail or agreed-upon electronic notice can be delivered, and establish substitute notice procedures for cases where contact information is insufficient or out of date.
Draft notice templates that address the required content elements and have them reviewed by legal counsel before an incident occurs, so notices can be issued without unreasonable delay.
Ensure business associate agreements clearly allocate breach discovery, reporting timelines, and any support for individual notification, recognizing that the covered entity generally retains the core notification obligation.
Cross-check individual notice practices against applicable state breach notification laws and HITECH requirements, since these may impose additional content, timing, or recipient obligations beyond HIPAA.
Confirm specific notification deadlines, thresholds, and content requirements against the current text of the Breach Notification Rule and current HHS OCR guidance, as these details are subject to change over time.