Skip to main content
Category: Breach Notification

Reportable Events

Also known as: Reportable Incidents, Adverse Events (context-dependent)
Simply put

Reportable events are incidents, adverse occurrences, or notable deviations that an organization is required to report to an oversight authority, such as a state health department, an institutional review board, or a regulatory agency. What counts as a reportable event and to whom it must be reported depends entirely on the specific program, regulator, or framework involved. The term does not have a single universal meaning and is used differently across healthcare research, patient safety, and provider-oversight contexts.

Formal definition

"Reportable Events" is a context-dependent term referring to a category of incidents, adverse events, deviations, or unanticipated problems that trigger a mandatory notification obligation to a designated oversight body under a specific program or regulatory scheme. Based on the available evidence, the term appears across distinct domains: state human-services and provider oversight systems (for example, event reporting systems operated by state health departments for licensed facilities and services for individuals receiving services), human-subjects research oversight (where an institutional review board defines reportable events to include adverse events, deviations, and unanticipated problems posing risks to participants or others), and state patient-safety programs that enumerate specific reportable adverse health events (such as surgical, device, patient-protection, and care-management events). The precise definition, reporting thresholds, timelines, and recipient authority are established by the governing program, statute, or institutional policy rather than by any single national standard, and readers must verify the applicable definition against the specific regulation, state requirement, or oversight body that applies to their situation. Note that this term as documented in the evidence is distinct from HIPAA-specific concepts such as breach notification obligations under the HIPAA Breach Notification Rule enforced by HHS OCR; where a HIPAA reporting obligation is intended, that specific rule and its own thresholds, timelines, and definitions should be consulted, and state law or other frameworks may impose additional or overlapping reporting requirements.

Why it matters

The term "reportable events" carries significant weight in healthcare compliance precisely because it does not mean one single thing. Depending on the program, an organization may face mandatory notification obligations to a state health department, an institutional review board, or another oversight authority, each with its own definitions, thresholds, and timelines. Failing to recognize which reporting regime applies to a given incident can leave an organization out of compliance with the correct authority even while it believes it has met its obligations. Because these requirements are established by the governing program, statute, or institutional policy rather than by any single national standard, professionals cannot rely on general intuition and must confirm what applies to their specific situation.

The stakes are concrete across multiple domains. In human-subjects research, an institutional review board may define reportable events to include adverse events, deviations, and unanticipated problems that pose risks to participants or others; deviations, in particular, are commonly encountered. In patient-safety contexts, states may enumerate specific categories of reportable adverse health events, for example, Minnesota maintains a list of 29 reportable adverse health events spanning surgical, product or device, patient-protection, and care-management categories. In provider and human-services oversight, states operate dedicated event reporting systems, such as Maine's Reportable Events System serving individuals receiving services and Pennsylvania's Event Reporting System for licensed provider types.

A critical caution for HIPAA-focused professionals: "reportable events" as documented here is distinct from breach notification obligations under the HIPAA Breach Notification Rule enforced by HHS OCR. Where a HIPAA reporting obligation is intended, that specific rule and its own thresholds, timelines, and definitions govern. State law or other frameworks may impose additional or overlapping reporting requirements, so identifying the correct authority and rule at the outset is essential.

Who it's relevant to

Research Compliance and IRB Professionals
Those managing human-subjects research must understand how their institution's IRB defines reportable events, which typically include adverse events, deviations, and unanticipated problems posing risks to participants or others. Because deviations are among the most common reportable events, ongoing monitoring and prompt reporting to the IRB are central responsibilities. The precise definition and timelines should be confirmed against institutional policy.
Healthcare Facility and Provider Oversight Staff
Licensed facilities and providers subject to state oversight may be required to report certain events through state-operated systems, such as Pennsylvania's Event Reporting System or Maine's Reportable Events System. Staff responsible for compliance should confirm which provider type requirements apply and follow the specific instructions and thresholds set by their state authority.
Patient Safety and Quality Officers
Professionals overseeing patient safety may operate under state programs that enumerate specific reportable adverse health events, for example, Minnesota's list of 29 events across surgical, product or device, patient-protection, and care-management categories. These officers must map their incident-reporting processes to the enumerated categories and reporting requirements of their applicable state program.
HIPAA Privacy and Security Officers
HIPAA compliance professionals should recognize that "reportable events" in these state and research contexts is distinct from breach notification obligations under the HIPAA Breach Notification Rule enforced by HHS OCR. Where a HIPAA reporting obligation applies, that rule's own definitions, thresholds, and timelines govern, and state law or other frameworks may impose additional or overlapping requirements that should be verified separately.

Inside Reportable Events

Breach of Unsecured PHI
Under the HIPAA Breach Notification Rule, a reportable event generally centers on the acquisition, access, use, or disclosure of unsecured protected health information in a manner not permitted by the Privacy Rule, which is presumed to be a breach unless a low probability of compromise is demonstrated.
Risk Assessment Trigger
Whether an event is reportable typically depends on a documented risk assessment. Factors generally considered include the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated. These factors should be confirmed against the current regulatory text.
Secured vs. Unsecured PHI
The Breach Notification Rule generally applies to unsecured PHI. PHI rendered unusable, unreadable, or indecipherable through methods such as encryption or destruction meeting HHS-specified standards is typically considered secured, and its exposure may not constitute a reportable event. Readers should verify the applicable guidance.
Regulatory Exceptions
Certain events are generally excluded from the definition of a breach, such as unintentional good-faith acquisition by a workforce member, inadvertent disclosure between authorized persons within the same entity, and disclosures where the recipient could not reasonably have retained the information. These exceptions are defined in the regulation and should be confirmed against current text.
Notification Obligations
When an event is reportable, covered entities generally must notify affected individuals, HHS OCR, and in some cases the media, within timeframes set by the Breach Notification Rule. Business associates are typically obligated to notify the covered entity, with specific duties governed by the business associate agreement.
Scope Beyond HIPAA
Reportable events under HIPAA are distinct from reporting obligations that may arise under state breach notification laws, the HITECH Act, or contractual frameworks. State law or other requirements may impose additional or stricter notification duties beyond those in the HIPAA rules.

Common questions

Answers to the questions practitioners most commonly ask about Reportable Events.

Is every impermissible use or disclosure of PHI automatically a reportable breach?
No. An impermissible use or disclosure is generally presumed to be a breach under the Breach Notification Rule, but that presumption can be rebutted. A covered entity or business associate may demonstrate through a risk assessment that there is a low probability the PHI has been compromised, in which case the event may not require notification. In addition, certain regulatory exceptions may apply. The specific factors and exceptions should be confirmed against the current regulatory text.
Does achieving HITRUST certification mean my organization has satisfied its obligations for identifying and reporting reportable events?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. Obligations to identify, assess, and report reportable events flow from the HIPAA Breach Notification Rule as enforced by HHS OCR. HITRUST controls may support your processes, but they do not replace the legal analysis and notification duties required under HIPAA.
How should an organization go about determining whether an event rises to the level of a reportable event?
Organizations typically perform a documented risk assessment when an impermissible use or disclosure of PHI is identified. This generally involves evaluating factors such as the nature and extent of the PHI involved, who accessed or received it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated. The outcome of that assessment informs whether notification is required. Readers should verify the specific assessment factors and any applicable exceptions against the current regulation.
What role do business associates play in the reportable events process?
Business associates are generally obligated, typically through the business associate agreement, to identify and report reportable events to the covered entity. The specific timing and content of such reports are usually defined in the BAA and should align with the requirements of the Breach Notification Rule. Subcontractors of business associates may have parallel obligations flowing up through their own agreements. Organizations should ensure their agreements clearly define these reporting responsibilities.
What documentation should be retained when evaluating a potential reportable event?
Organizations should generally retain records of the risk assessment performed, including the factors considered and the basis for any conclusion that notification was or was not required. Where an exception is relied upon, documentation supporting that determination is typically advisable. Maintaining this documentation helps demonstrate the reasoning behind a decision if it is later reviewed. The applicable retention periods and documentation standards should be confirmed against current guidance.
Do state laws or other frameworks affect how reportable events must be handled beyond HIPAA?
Yes, potentially. State breach notification laws, the HITECH Act, and other frameworks may impose additional or more stringent requirements beyond the HIPAA Breach Notification Rule, including different definitions, thresholds, or timelines. HIPAA generally sets a federal baseline, but organizations should evaluate applicable state law and other obligations, which may require notification in circumstances or on timelines that differ from HIPAA. These additional requirements should be confirmed against current sources.

Common misconceptions

Any unauthorized access to PHI is automatically a reportable breach that must be reported to HHS OCR.
Not every impermissible use or disclosure is reportable. The Breach Notification Rule generally requires a documented risk assessment, and defined exceptions may apply. Additionally, exposure of properly secured PHI, such as PHI encrypted to HHS-specified standards, may not constitute a reportable breach.
A business associate that experiences an incident must directly notify affected individuals and HHS the same way a covered entity does.
Business associates are generally obligated to report incidents to the covered entity, with the specific timing and content of that notification governed by the business associate agreement. The covered entity typically bears the primary responsibility for individual and HHS notifications unless the agreement delegates otherwise.
Holding HITRUST certification means an organization has satisfied its HIPAA reportable-event obligations.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA compliance or discharge breach reporting duties, which arise under the HIPAA rules enforced by HHS OCR.

Best practices

Maintain a documented, consistent risk assessment process for evaluating whether an incident meets the reportable-event threshold, capturing the factors generally required by the Breach Notification Rule and the rationale for any determination that an event is not reportable.
Render PHI unusable, unreadable, or indecipherable where feasible using methods such as encryption or secure destruction that meet HHS-specified standards, since exposure of properly secured PHI may fall outside reportable-event obligations.
Define breach reporting responsibilities, timeframes, and notification content clearly in business associate agreements so that obligations flowing between covered entities, business associates, and subcontractors are unambiguous.
Track and comply with the notification timeframes set by the Breach Notification Rule, and verify current deadlines and requirements against the applicable regulatory text rather than relying on memory.
Check whether state breach notification laws, the HITECH Act, or contractual obligations impose additional or stricter reporting duties beyond HIPAA, and reconcile all applicable requirements.
Retain thorough documentation of each incident, the risk assessment, any applicable exceptions relied upon, and notifications made, to support accountability during an HHS OCR inquiry.