Skip to main content
Category: Breach Notification

Media Notice

Also known as: Notification to the Media, Media Notification
Simply put

Media Notice is a step required under the HIPAA Breach Notification Rule where a covered entity notifies prominent media outlets after certain breaches of protected health information. It is generally triggered when a breach affects a large number of individuals in a particular state or jurisdiction. This notice must generally be provided without unreasonable delay, and in no case later than 60 days following discovery of the breach.

Formal definition

Media Notice refers to the obligation under the HIPAA Breach Notification Rule (generally at 45 CFR § 164.406) for a covered entity to notify prominent media outlets serving a state or jurisdiction following a breach of unsecured protected health information affecting more than a threshold number of residents of that state or jurisdiction (commonly cited as more than 500 residents; verify against the current regulatory text). Like individual notice, media notification must be provided without unreasonable delay and no later than 60 days following discovery of the breach. This 'to the media' notice is directed at media outlets and is distinct from the substitute notice provision (generally at 45 CFR § 164.404(d)), which may permit notice via media or web posting when contact information for affected individuals is insufficient or out of date. Media Notice does not, by itself, satisfy the separate requirements for individual notice or notice to the HHS Secretary; those are distinct obligations. This entry addresses the HIPAA federal requirement only; state breach notification laws or other frameworks may impose additional or differing obligations, and the specific affected-individual threshold, timing, and citation should be confirmed against the current Breach Notification Rule.

Why it matters

Media Notice is one of the more visible obligations under the HIPAA Breach Notification Rule because it moves a breach response out of private correspondence and into public view. When a breach affects a large number of residents of a particular state or jurisdiction (commonly cited as more than 500, though the specific threshold should be verified against the current regulatory text), a covered entity is generally required to notify prominent media outlets serving that area. This public-facing requirement creates reputational and operational stakes that internal notifications do not, and it signals to regulators and the public that the breach met a significant scale.

Because media notification carries the same timing discipline as individual notice, without unreasonable delay and in no case later than 60 days following discovery of the breach, covered entities need to identify quickly whether a breach crosses the applicable jurisdictional threshold. Misjudging that threshold, or treating media notice as interchangeable with other notification steps, can leave an entity out of compliance even when it believes it has responded appropriately.

It is important to keep Media Notice distinct from the other obligations that may be triggered by the same breach. Providing notice to the media does not, by itself, satisfy the separate requirements for individual notice or for notice to the HHS Secretary, which are independent obligations. Entities should also be aware that state breach notification laws or other frameworks may impose additional or differing requirements beyond the HIPAA federal rule addressed here.

Who it's relevant to

Privacy and Security Officers
These officers are typically responsible for assessing whether a breach crosses the jurisdictional threshold that triggers Media Notice and for coordinating notification within the required timeframe. They need to distinguish this obligation from individual notice, notice to the HHS Secretary, and the substitute notice provision, and to confirm the applicable threshold against the current regulatory text.
Covered Entities, Including Health Plans
Covered entities, including group health plans subject to HIPAA, bear the direct obligation to notify prominent media outlets when a qualifying breach affects residents of a state or jurisdiction. They should have policies and procedures in place to identify triggering breaches and to issue media notice without unreasonable delay and no later than 60 days following discovery.
Compliance and Legal Teams
Legal and compliance professionals advise on breach response and help ensure that Media Notice is treated as a distinct obligation rather than a substitute for other required notifications. They should also evaluate whether state breach notification laws or other frameworks impose additional or differing requirements beyond the HIPAA federal rule.
Communications and Public Relations Staff
Because Media Notice is public-facing, communications teams often draft and coordinate the notification to prominent media outlets. They should work closely with compliance and legal staff to ensure the content and timing align with the Breach Notification Rule's requirements rather than treating it purely as a public relations matter.

Inside Media Notice

Trigger Threshold
Under the HIPAA Breach Notification Rule, media notice is generally required when a breach of unsecured protected health information affects more than a specified number of residents of a state or jurisdiction. The commonly cited threshold is 500 residents, but practitioners should confirm the exact figure and its application against the current regulatory text.
Prominent Media Outlets
The notice must generally be provided to prominent media outlets serving the state or jurisdiction where the affected individuals reside. This is a public-facing notification distinct from the direct individual notice and the notice to HHS OCR.
Content Requirements
Media notice typically must include the same categories of information required for individual notice, such as a brief description of the breach, the types of information involved, steps individuals should take to protect themselves, what the covered entity is doing, and contact procedures for more information.
Timing
Media notice generally must be provided without unreasonable delay and within the outer time limit established by the Breach Notification Rule following discovery of the breach. Practitioners should verify the current deadline against the applicable regulation.
Responsible Party
The obligation to provide media notice generally rests with the covered entity. A business associate that experiences a breach typically must notify the covered entity, which then determines and carries out required notifications, subject to the terms of the business associate agreement.

Common questions

Answers to the questions practitioners most commonly ask about Media Notice.

Does a covered entity have to issue a media notice for every breach it experiences?
No. Media notice is generally triggered only when a breach of unsecured protected health information affects more than 500 residents of a single state or jurisdiction. Breaches below that threshold, or those affecting fewer than 500 residents in a given state, are typically handled through individual notice and the applicable reporting to HHS, without a media notification. You should confirm the current threshold and requirements against the Breach Notification Rule text, as details are subject to change.
Is media notice the same thing as notifying HHS OCR or the affected individuals?
No. These are separate obligations under the Breach Notification Rule. Individual notice goes to the affected persons, notice to HHS is submitted to the Secretary (via HHS OCR), and media notice is a distinct requirement directed to prominent media outlets serving the affected state or jurisdiction. Satisfying one does not satisfy the others; a covered entity generally must address each applicable requirement separately. Verify the specifics against current regulatory guidance.
What kind of media outlet counts as satisfying the media notice requirement?
The requirement generally calls for notifying prominent media outlets serving the state or jurisdiction where the affected individuals reside. In most cases this means outlets with meaningful reach across the relevant area rather than a narrowly targeted or obscure publication. The precise expectations should be confirmed against the current Breach Notification Rule and any relevant HHS guidance.
How quickly must a media notice be provided after a breach is discovered?
Media notice is generally required without unreasonable delay and no later than the outer time limit that applies to breach notifications under the rule. Because specific deadlines are set by the regulatory text and can be adjusted over time, you should confirm the applicable timeframe against the current Breach Notification Rule rather than relying on a fixed number of days from memory.
What information should a media notice typically contain?
A media notice generally includes the same core content elements expected of individual notices, such as a description of what happened, the types of information involved, steps individuals can take to protect themselves, what the entity is doing in response, and contact procedures for more information. Confirm the required content elements against the current Breach Notification Rule, and note that state law may impose additional content or notification requirements.
Does issuing a media notice replace the obligation to notify individuals directly?
No. Media notice is generally provided in addition to individual notice, not as a substitute for it. Where the threshold is met, a covered entity typically still must attempt individual notification through the methods specified in the rule. Media notice supplements those efforts rather than replacing them; verify the interplay of these obligations against the current regulatory text.

Common misconceptions

Media notice is required for every reportable breach.
Media notice is generally triggered only when a breach of unsecured PHI affects more than the specified number of residents of a single state or jurisdiction. Smaller breaches still require individual notice and notification to HHS OCR, but not media notice. Verify the applicable threshold against current guidance.
Media notice replaces the requirement to notify affected individuals directly.
Media notice is an additional obligation, not a substitute. Direct notice to affected individuals and notification to HHS OCR are separate requirements under the Breach Notification Rule and generally still apply.
A breach involving encrypted or otherwise secured data still requires media notice once the count is high.
The Breach Notification Rule generally applies to unsecured PHI. Information rendered unusable, unreadable, or indecipherable through methods recognized under HHS guidance may fall outside breach notification obligations, though practitioners should confirm this against the current standards and consider any additional state-law requirements.

Best practices

Maintain an incident response plan that clearly identifies the residency-based threshold triggering media notice and the outer notification deadline, and verify both against the current Breach Notification Rule text.
Track affected individuals by state or jurisdiction so you can accurately determine whether the media notice threshold is met in any single jurisdiction.
Prepare template notice content in advance that satisfies the required content elements, and coordinate legal and communications review before release.
Identify prominent media outlets for each state or jurisdiction where you hold PHI so distribution can occur promptly if a qualifying breach occurs.
Ensure business associate agreements specify prompt breach reporting from business associates to the covered entity so notification timelines can be met.
Confirm whether applicable state laws or the HITECH Act impose additional or stricter notification obligations beyond the federal HIPAA requirements, and document all notification steps and timing for enforcement and audit purposes.