Skip to main content
Category: Breach Notification

Law Enforcement Delay

Also known as: Breach Notification Law Enforcement Delay, Delay of Breach Notification
Simply put

Law enforcement delay is a provision under HIPAA's Breach Notification Rule that lets a covered entity or business associate temporarily hold off on notifying individuals, HHS, or the media about a breach when a law enforcement official says that doing so would interfere with an investigation or harm national security. The length of the delay generally depends on whether the request is made in writing and how much time it specifies. This is a temporary postponement, not a cancellation, of the required notification.

Formal definition

Under 45 CFR § 164.412, if a law enforcement official states that a required notification, notice, or posting under the Breach Notification Rule would impede a criminal investigation or cause damage to national security, a covered entity or business associate must delay the notification. Where the statement is in writing and specifies a time period for the delay, notification is delayed for the specified time period; where the statement is made orally, the covered entity or business associate generally documents the statement (including the identity of the official) and delays notification for a limited period, unless a qualifying written statement is provided within that period. This provision applies only to the timing of notifications otherwise required under the Breach Notification Rule and does not eliminate the underlying notification obligations, alter the definition of a breach, or affect requirements under the Privacy Rule or Security Rule. Practitioners should confirm the current regulatory text and any applicable state-law notification requirements, which may impose additional or differing obligations, and note that the specific oral-statement delay window should be verified against the current regulation.

Why it matters

Breach notification timelines under HIPAA are strict, and covered entities and business associates that miss required deadlines can face enforcement scrutiny from HHS OCR. The law enforcement delay provision under 45 CFR § 164.412 exists precisely because there are situations where prompt public notification could compromise an active criminal investigation or damage national security. Without this safeguard, an organization could be forced to choose between meeting its HIPAA notification obligations and inadvertently tipping off a suspect or exposing sensitive investigative details.

The provision matters because it is narrow and conditional. It does not give organizations discretion to postpone notification on their own judgment; the delay must be triggered by a statement from a law enforcement official. It also is a postponement, not a cancellation. Organizations that misunderstand this risk assuming a delay relieves them of the underlying obligation, when in fact the duty to notify individuals, HHS, and in some cases the media remains fully intact once the delay period ends.

Because the mechanics differ depending on whether the law enforcement request is made in writing or orally, careful documentation is essential. An organization that fails to properly record an oral statement, or that extends a delay beyond what is permitted, may find itself unable to justify a late notification. Given that state breach notification laws and the HITECH Act may impose additional or differing timing requirements, practitioners should treat this provision as one piece of a broader compliance picture rather than a standalone shield.

Who it's relevant to

Privacy and Compliance Officers
Privacy officers responsible for managing breach response need to know when and how a law enforcement delay may apply, and must ensure that any delay is properly triggered, documented, and time-limited. They should recognize that the delay postpones but does not remove the notification obligation, and that responsibility for meeting the notification deadline resumes once the delay period ends.
Business Associates
Business associates are subject to the Breach Notification Rule and may encounter law enforcement delay situations directly or through coordination with the covered entities they serve. They should understand how the provision interacts with their breach reporting obligations under their business associate agreements and confirm which party is documenting the law enforcement statement.
Legal Counsel and Incident Response Teams
Attorneys and incident response teams advising on breach events must accurately capture the form and content of any law enforcement request, distinguish between written and oral statements, and track the applicable delay period. They should also assess whether state breach notification laws or the HITECH Act impose additional or differing timing obligations beyond the HIPAA provision.
Security Officers and IT Teams
Security and IT personnel who investigate incidents and preserve evidence may work alongside law enforcement during an investigation. While the Security Rule governs safeguards for ePHI rather than notification timing, these teams should understand that a law enforcement delay affects only the timing of required notifications and does not alter their ongoing safeguard responsibilities.

Inside Law Enforcement Delay

Breach Notification Rule Context
Law Enforcement Delay is a provision under the HIPAA Breach Notification Rule that allows a covered entity or business associate to delay the notifications otherwise required following a breach of unsecured PHI. It does not eliminate the notification obligation; it generally postpones the timing of required notices.
Triggering Request from a Law Enforcement Official
The delay generally applies when a law enforcement official states that notification, notice, or posting would impede a criminal investigation or cause damage to national security. The request is what activates the delay, and the specifics should be verified against the current Breach Notification Rule text.
Written vs. Oral Statement Distinction
The permissible length of delay generally depends on whether the law enforcement request is made in writing or orally. A written statement specifying a required time period typically permits delay for that stated period, while an oral statement typically permits a shorter delay unless subsequently documented. Readers should confirm the exact durations against current regulation.
Documentation Requirement
When a request is made orally, the covered entity or business associate generally must document the statement, including the identity of the official making it, and limit the delay accordingly. Documentation supports demonstrating that the delay was properly invoked.
Scope Limitation
The delay affects the timing of notification to individuals, HHS, and the media as applicable. It does not change the underlying determination that a breach occurred, nor the substantive content of required notices once the delay period ends.

Common questions

Answers to the questions practitioners most commonly ask about Law Enforcement Delay.

Does a law enforcement request automatically excuse a covered entity from ever notifying affected individuals of a breach?
No. A law enforcement request does not permanently eliminate the notification obligation; it generally allows for a temporary delay of the notification, documentation, or disclosure. Once the specified delay period expires or the law enforcement official indicates the delay is no longer needed, the covered entity or business associate is generally still expected to provide the required notifications. The delay provision suspends timing rather than removing the underlying obligation. You should verify the specific requirements and permissible delay periods against the current Breach Notification Rule text and any applicable state law, which may impose additional or stricter requirements.
Can a covered entity delay breach notification indefinitely just because it believes law enforcement might be interested in the matter?
Generally, no. The delay is not triggered by the covered entity's own assumption or general concern that an investigation could occur. It typically requires a statement or request from a law enforcement official indicating that notification would impede an investigation or cause harm. The permissible length of the delay generally depends on whether the request is made in writing or orally, with oral requests typically supporting a shorter delay and requiring documentation. Confirm the exact conditions and time frames against the current regulatory text before relying on this provision.
What should we document when we receive a law enforcement request to delay notification?
In most cases you should document the identity of the law enforcement official making the request, the date and time it was received, whether it was made in writing or orally, the scope of what is being delayed (notification, disclosure, or documentation), and the stated or requested duration. If the request is oral, documentation is generally especially important because it typically supports only a limited delay period. Retain this documentation with your broader breach investigation records. Verify retention expectations and specific documentation requirements against current HHS OCR guidance and the applicable regulatory text.
How should the law enforcement delay provision be reflected in our breach response policies and procedures?
Your breach response procedures should generally identify who is authorized to receive and validate a law enforcement delay request, how the request and its basis are documented, how the delay duration is tracked, and the process for resuming notification once the delay period ends. Because this provision intersects with strict notification timelines, procedures typically include a mechanism to calendar or otherwise monitor deadlines so that notifications are not missed after the delay lapses. Coordinate these procedures with legal counsel and confirm alignment with the current Breach Notification Rule and any applicable state law.
How does the law enforcement delay interact with business associates who discover a breach?
A business associate that experiences or discovers a breach generally has obligations to notify the covered entity as defined in the business associate agreement and under the Breach Notification Rule. Where a law enforcement delay applies, the parties typically need to coordinate so that the delay and its documentation are handled consistently. Because the covered entity generally bears the ultimate responsibility for notifying affected individuals, HHS, and in some cases the media, the business associate agreement and communication between the parties should address how a law enforcement delay request is conveyed and honored. Review your specific business associate agreement terms and confirm obligations against the current regulatory text.
What do we do when the law enforcement delay period expires?
When the delay period expires, or when the law enforcement official indicates the delay is no longer needed, the covered entity or business associate is generally expected to proceed with the required notifications and any delayed disclosures or documentation without further delay. Because the underlying deadlines are strict, organizations typically track the delay end date closely and resume the notification process promptly. Confirm the applicable timing, content, and recipient requirements for the resumed notifications against the current Breach Notification Rule, current HHS OCR guidance, and any applicable state law that may impose additional obligations.

Common misconceptions

A law enforcement request cancels the obligation to notify affected individuals about a breach.
The provision generally only delays the timing of required notifications; it does not remove the obligation. Once the applicable delay period ends, the covered entity or business associate is still generally expected to provide the notices otherwise required under the Breach Notification Rule.
Any request from law enforcement, in any form, permits an indefinite delay.
The permissible delay is generally tied to the form of the request. A written statement typically supports delay for the specific time period stated, while an oral statement typically supports a shorter delay unless it is documented. The delay is not open-ended, and exact parameters should be verified against current regulation.
The delay provision applies broadly to all HIPAA obligations, not just breach notification.
This delay is specific to notifications under the Breach Notification Rule. It does not suspend Privacy Rule, Security Rule, or other HIPAA obligations, and separate law enforcement provisions elsewhere in the rules address disclosures to law enforcement, which are distinct from this delay.

Best practices

Request that law enforcement provide the delay request in writing whenever possible, and ensure the written statement specifies the required time period so the permissible delay is clearly bounded.
When a request is received orally, promptly document it, including the identity of the official making the statement, and calendar the applicable delay limit so notifications resume on time.
Continue the breach risk assessment and investigation during any delay, since the delay affects notification timing rather than the underlying breach determination.
Track the end of the delay period and be prepared to issue individual, HHS, and media notifications, as applicable, without further postponement once the period expires.
Maintain records demonstrating the basis for the delay to support accountability and any subsequent review by HHS OCR.
Verify the specific written versus oral delay durations and documentation requirements against the current Breach Notification Rule text, and consider whether state law or other frameworks impose additional or shorter timelines.