HIPAA breach notification title card
UI Design Illustration

60 Days to HIPAA Breach Notification: U.S. Compliance Officer Playbook

Computer & Technology Tips

The moment you confirm a HIPAA breach, three clocks start running: notify affected individuals, notify the HHS Secretary through the OCR breach-reporting portal, and notify the media if the breach hits more than 500 residents of a state. All three obligations share the same outer boundary: without unreasonable delay, and no later than 60 calendar days after discovery. If you’re claiming the low-probability exception instead of notifying, that determination needs a documented risk assessment on file, and any business associate involved must notify you promptly enough that you can still hit your own deadline.


TL;DR:

  • If a breach involves more than 500 residents of a single state, media notice is required within 60 days of discovery, with documentation proving publication.
  • Organizations must conduct a documented risk assessment to justify low-probability claims, considering the nature of PHI, access, and mitigation, or face mandatory notification.
  • Notification deadlines are tied to the discovery date, not the incident date, with the law requiring notices to be sent “without unreasonable delay,” ideally in less than 60 days.
  • Business associates must notify the covered entity within 60 days of their own breach discovery, often requiring shorter contractual deadlines to ensure timely reporting.
  • Maintaining thorough, organized records of breach details, risk assessments, and notices is essential for compliance during OCR audits years after an incident.

tekrescue
Strengthen Your HIPAA Security
tekRESCUE helps healthcare providers protect sensitive data with HIPAA-focused compliance, cybersecurity, and ongoing technology support.

Explore tekRESCUE

Table of Contents

What Counts as a HIPAA Breach and When You Can Skip Notification

Every impermissible use or disclosure of unsecured protected health information is presumed to be a breach the moment it happens. That presumption is the default position under the Breach Notification Rule, and it shifts the burden onto you, the covered entity, to prove otherwise. You don’t get to decide informally that an incident “probably wasn’t a big deal.” You have to demonstrate it, in writing, through a structured risk assessment.

That risk assessment weighs four factors specified in the rule:

  • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
  • The identity of the unauthorized person who accessed or received the information.
  • Whether the PHI was actually acquired or viewed, versus merely exposed without evidence of access.
  • The extent to which the risk has been mitigated, such as through a signed confidentiality agreement or confirmed destruction.

Fall short on any factor and you likely cannot claim low probability of compromise, which means notification obligations kick in by default.

There’s a separate escape hatch worth knowing: safe harbor. If the PHI was encrypted to National Institute of Standards and Technology standards, or destroyed according to NIST SP 800-88 media-sanitization guidelines, the information is not considered “unsecured,” and the incident isn’t a reportable breach at all. This is why encryption at rest and in transit isn’t just a best practice, it’s the single fastest way to make a stolen laptop a non-event instead of a 60-day scramble.

Pro Tip: Keep your encryption key management documentation separate from your breach files. If an auditor ever asks how you know a device was encrypted at the time of loss, “we think so” is not an answer. A dated key inventory is.

To make a low-probability determination defensible, your file needs: the date and description of the incident, each factor’s analysis in writing, the identity or role of the unauthorized recipient when known, any evidence (or absence of evidence) of actual viewing, and the specific mitigation steps taken and when. Skip the documentation and you’ve made a decision that looks, to an OCR investigator later, exactly like an unreported breach.

How Do You Send a Compliant Individual Breach Notice?

Individual notice has to contain specific elements under 45 CFR §164.404, and OCR is not shy about citing entities that leave one out. The required elements are:

  • A brief description of what happened, including the date of the breach and the date of discovery, if known.
  • The types of unsecured PHI involved (Social Security numbers, diagnosis codes, financial account numbers, and similar categories).
  • Steps individuals should take to protect themselves from potential harm.
  • A description of what the covered entity is doing to investigate, mitigate harm, and prevent further breaches.
  • Contact procedures for individuals to ask questions, including a toll-free number, email address, website, or postal address.

Many breach notices land in the OCR portal every year across covered entities of various sizes, and the volume itself tells you something: individual notice failures are common enough that OCR built a whole questionnaire around verifying you got the content right, not just the timing.

Delivery method matters as much as content. First-class mail to the last known address is the default. Email is acceptable only if the individual has already agreed to receive electronic notices from you. Telephone or other urgent means can supplement written notice when there’s a possibility of imminent misuse, such as when Social Security numbers are already circulating. None of these methods substitute for the written notice. They add to it.

Plain language isn’t optional decoration. Write the notice at a level a worried patient can understand on a first read, not a level a malpractice attorney would admire. Skip regulatory citations in the body copy. Say “we discovered on March 3, 2026, that an unauthorized person accessed a database containing your name, date of birth, and diagnosis codes,” not “an unauthorized disclosure event was identified affecting protected health information categories.”

When contact information is insufficient or out of date for ten or more individuals, substitute notice takes over: either a conspicuous posting on your homepage for 90 days, or notice in major print or broadcast media in the area where those individuals likely reside, plus a toll-free number that stays active for at least 90 days. Keep a dated screenshot of the homepage posting and a log of every call the toll-free line receives. That documentation is what proves substitute notice actually happened, rather than existing only in your recollection months later.

When Must You Report a Breach to HHS?

The threshold for reporting to the Secretary is the affected-individual count, and it determines your timeline as much as your discovery date does.

  1. 500 or more individuals affected. Report through the OCR breach-reporting portal without unreasonable delay, and no later than 60 calendar days after discovery. This mirrors your individual notice deadline exactly, so both should be moving in parallel, not sequentially.
  2. Fewer than 500 individuals affected. Report by 60 days after the end of the calendar year in which the breach was discovered. You are allowed, and often better served, to report earlier rather than waiting for the annual batch.
  3. Uncertain count at the time of filing. Submit your best documented estimate through the portal, then amend the report once forensic work confirms the actual number. Guessing low to avoid the 500-threshold reporting track, and later discovering the real number crossed it, creates its own separate compliance problem.

Business associates may submit the report on your behalf if you’ve authorized that in writing, but the legal obligation to report stays with you as the covered entity. File a separate notice for each distinct breach; don’t bundle unrelated incidents into a single portal submission to save time. The portal will ask for breach and discovery dates, an approximate individual count, the type of PHI involved, safeguards that were in place beforehand, and an attestation confirming the accuracy of what you submitted.

Media Notice: What Triggers It and How Substitute Notice Works

If a breach affects more than 500 residents of a single state or jurisdiction, you owe that state’s media a notice in addition to individual and HHS notices. This is the trigger people miss most often, because it’s based on residency concentration within a state, not your total national breach count. A breach touching 600 individuals spread evenly across ten states may not trigger media notice anywhere, while one touching 550 residents concentrated in Texas does.

Media notice content largely mirrors individual notice: a description of what happened, the PHI types involved, protective steps individuals can take, your mitigation efforts, and contact information. Send it to prominent media outlets serving the affected geographic area, not just a single press release distributed nationally and hoped for the best.

Substitute notice comes into play on the individual side when contact information is insufficient or outdated for ten or more people, and it has two acceptable forms:

  • A conspicuous posting on your website’s homepage, left up for 90 consecutive days.
  • Notice in major print or broadcast media reasonably likely to reach the affected individuals.

Either form must include a toll-free phone number that stays active for at least 90 days, so people who see the notice can call and confirm whether they’re personally affected. Document exactly where the homepage posting appeared, the exact dates it ran, and proof the phone line was staffed and functional the entire 90-day window. A compliance officer who can produce a dated screenshot and a call log six months later is in a far better position than one relying on memory during an OCR inquiry.

When Is a Breach Officially “Discovered” Under HIPAA?

Discovery date isn’t the day you personally found out. It’s the first day the breach was known, or would have been known through reasonable diligence, by any workforce member, officer, or agent of your organization. If a night-shift IT technician noticed suspicious login activity on a Tuesday but didn’t escalate it until the following Monday, your discovery date is Tuesday, not Monday. That gap can quietly eat a week of your 60-day window before compliance even opens the file.

Here’s how to keep discovery-to-notification moving without letting the deadline sneak up on you:

  1. Set an internal escalation SLA of 24 to 48 hours for any suspected PHI exposure, regardless of how minor it initially looks.
  2. Start the risk assessment the same week, not after forensics fully wraps up. You can revise findings later; you can’t recover lost calendar days.
  3. Notify in waves if needed. HIPAA allows partial and multiple mailings as your affected-individual list gets confirmed, so don’t hold the entire notification hostage waiting for a perfect final count.
  4. Don’t treat 60 days as a target. It’s a ceiling. If you can reasonably notify in 20 days, do it in 20.

Pro Tip: Build your incident response plan around a “day one” trigger, not a “confirmed breach” trigger. Waiting for full forensic certainty before starting your compliance clock is exactly the pattern OCR settlements call out as an unreasonable delay.

OCR enforcement actions consistently show a pattern: ransomware incidents frequently produce large breach counts, and penalties escalate sharply when the entity’s risk analysis or its notification timeline was deficient, not just when the breach itself was severe.

What Do Business Associates Owe You After a Breach?

A business associate that discovers a breach involving your PHI must notify you without unreasonable delay and no later than 60 calendar days after its own discovery, per 45 CFR §164.410. That 60-day figure is a ceiling for the BA, not a floor, and it’s a separate clock from yours, which means a BA that waits until day 59 to tell you can leave you with almost no runway to meet your own 60-day deadline to individuals and HHS.

Business associate breach deadline comparison

This is exactly why your business associate agreements need to impose a shorter contractual deadline than the regulatory maximum. Many organizations write 10 to 15 calendar days into their BAAs for this reason, and treat that number as an operational service-level agreement, not a suggestion. Read your BAA the moment you learn a vendor had an incident. If the contract says 10 days and the vendor is already past that, you have a separate contractual issue on top of the breach itself.

When a business associate reports an incident, don’t take its investigation at face value. HHS guidance on the Change Healthcare incident makes clear that covered entities must still conduct their own notification analysis; a vendor’s conclusions don’t substitute for your own determination.

Require from every business associate involved in an incident:

  • The identities (or best available identifying information) of affected individuals.
  • Forensic findings describing exactly what data was accessed, viewed, or exfiltrated.
  • Specific mitigation and remediation steps already taken.
  • Written acknowledgment of when the BA itself discovered the incident, so your discovery-date clock is defensible.

Build vendor management around this reality before an incident happens, not during one. A risk assessment checklist that includes vendor breach-notification SLAs as a standing review item will save your compliance team weeks the day it actually matters.

What Records Do You Need for the HHS Breach Portal?

Your incident file has to survive a review that could happen years after the breach. At minimum, it should contain the discovery date and how you calculated it, your methodology for counting affected individuals, a plain description of the breach, every mitigation step taken and its date, and the dates each notice went out to individuals, HHS, and media if applicable.

The breach portal questionnaire itself previews what OCR expects you to have ready:

Portal field category What you need on hand
Breach and discovery dates Documented timeline with source of discovery
Approximate individuals affected Counting methodology, amendable estimate if uncertain
Type of PHI involved Specific categories, not a generic description
Safeguards in place before the breach Encryption status, access controls, prior risk assessments
Actions taken after discovery Containment, forensics engaged, mitigation steps
Attestation Signed confirmation of accuracy by an authorized official

For breaches affecting 500 or more individuals, understand that your submission becomes public. OCR posts these on its public breach portal and uses the data for congressional reporting, so the language you write into the “actions taken” field is effectively a public statement about your organization’s response. Draft it with that audience in mind, not just the OCR reviewer.

Hold onto the complete incident file for at least six years, matching the general HIPAA documentation retention requirement, and structure it so any compliance officer, not just the one who handled the incident, can reconstruct the full timeline on short notice.

Incident Response Checklist: What to Do in the First 72 Hours

The first three days after discovery set the tone for everything that follows, and the work has to happen on parallel tracks, not one after another.

  1. Contain immediately. Isolate affected systems, disable compromised credentials, and preserve logs and forensic evidence before anyone starts cleanup that could destroy it.
  2. Open the investigation and legal tracks simultaneously. Forensics determines scope while counsel and compliance start the breach determination and risk assessment in parallel, not after forensics finishes.
  3. Assign a communications owner. One person coordinates individual notices, the HHS portal submission, and media notice if the state-resident threshold applies, so messaging stays consistent across all three.
  4. Document the four-factor risk assessment as you go, not retroactively. Each factor gets its own dated entry with supporting evidence, whether you ultimately notify or claim the exception.
  5. Loop in your cyber insurer and outside counsel early. Many policies require notice within a specific window after discovery, and claims get denied when insurers weren’t told promptly.
  6. Build a notification assignment matrix. List who drafts each notice type, who approves it legally, and who dispatches it, with target dates working backward from day 60.

Pro Tip: Assign a single “clock owner” on day one, someone whose only job is tracking the 60-day countdown across all three notice types. Incident response teams get pulled into forensics and firefighting; deadlines slip when nobody owns the calendar specifically.

Understanding the full anatomy of a cyber incident before one happens to you is the difference between a checklist you execute calmly and one you’re improvising under pressure.

Building Your Notification Rollout: From Draft to Dispatch

Treat notification as a project with real deadlines, not a document you write once panic subsides. Draft individual notice language first, since it drives the content for both the HHS portal narrative and any media notice. Route the draft through legal review and executive sign-off before a single letter goes out. Rushed language that skips review tends to create ambiguity that draws follow-up complaints.

Build your mailing list in parallel with drafting, not after. Confirm which addresses are current, flag the ones that need substitute notice, and reconcile your counting methodology so the number you report to HHS matches the number of letters you actually send.

Sequence the dispatch: individual notices and the HHS portal submission should go out together whenever the 500-plus threshold applies, since both share the same 60-day deadline. Media notice, when triggered, should follow within the same window rather than being treated as a lower priority just because it involves fewer individual recipients.

Keep a dispatch log: date mailed, method used, and any notices returned as undeliverable, since those trigger your substitute notice obligation. Assign someone to own final QA on every notice before it leaves the building, checking that the required elements from §164.404 are all present and that no notice references the wrong incident date.

The mistake OCR settlements cite most often isn’t the breach itself. It’s what the organization did, or failed to do, in the 60 days after. Treating the deadline as a target instead of a ceiling is the single most common trap; entities that wait until day 58 to start drafting notices leave themselves no room for a mailing error or an incomplete address list.

Undercounting affected individuals to stay below the 500-person portal threshold is another recurring problem, whether intentional or the result of sloppy forensic scoping. If the real number crosses 500 after you’ve already filed under the smaller-breach track, you now have a second compliance gap layered onto the first.

Skipping the written risk assessment when claiming low probability of compromise is arguably the riskiest shortcut of all, because it leaves you defending a decision with nothing but your own recollection. Treating a business associate’s internal investigation as a substitute for your own notification analysis is a related error that HHS has specifically called out in Change Healthcare-related guidance.

Finally, ignoring state law is a gap many compliance teams don’t catch until it’s too late. HIPAA sets a federal floor, not a ceiling, and state attorneys general have independent enforcement authority under HITECH. A notification that satisfies HIPAA can still fall short of a stricter state deadline or content requirement.

What Should a Compliant Breach Notification Letter Include?

A compliant letter opens with a plain statement of what happened and when, written in the second person so it reads as communication to the actual person affected, not as a legal filing. Follow with the specific PHI types involved, since vague phrasing like “certain information” invites complaints and follow-up calls you could have avoided.

The middle of the letter covers protective steps: whether to place a fraud alert, monitor explanation-of-benefits statements, or watch for phishing attempts referencing their specific diagnosis or provider. Close with what you’re doing about it, in concrete terms, and a way to reach you: a toll-free number, an email address, and a mailing address.

A media notice follows the same skeleton but drops the personal address to the recipient and adds framing appropriate for a press release, still covering what happened, what data was involved, what you’re doing, and how affected residents can get more information. Both documents should go through the same legal review before dispatch, since the same factual claims appear in each and inconsistency between them is exactly the kind of detail an investigator notices.

Notifying Individuals With Disabilities or Limited English Proficiency

A notice that technically went out but that the recipient couldn’t read or understand doesn’t satisfy your obligation in any meaningful sense. For individuals with limited English proficiency, identify the languages most commonly spoken in your patient or client population ahead of time, not during an active breach, and have template language ready to translate quickly. Certified translation matters here, since a rushed machine translation of medical terminology can create confusion at exactly the moment clarity matters most.

For individuals with disabilities, accessible formats aren’t optional extras. Large-print versions, screen-reader-compatible electronic notices, and telephone notification for individuals who are blind or have low vision all fall under your general obligation to communicate effectively. If your organization already maintains a Section 504 or ADA communication-accessibility plan, extend it explicitly to cover breach notification rather than treating notification as a separate process that falls outside it.

Accessible breach notification formats illustration

Document which accommodations you provided and to whom, the same way you document standard mailings. If a substitute notice runs in print media only, that format excludes people with visual impairments, so pair it with a toll-free number staffed by someone able to relay the same information verbally on request.

Author Perspective: What Actually Separates a Clean Response From an Enforcement Action

Most organizations treat breach notification as a legal task handed to counsel after the technical cleanup is done. That sequencing is the mistake. The strongest responses run legal, forensic, and communications work at the same time, from day one, because the 60-day clock doesn’t pause for any of them individually.

The pattern in enforcement cases isn’t sophistication of the attack. It’s delay, thin documentation, and BAAs nobody read until it was too late. Fix those three things and you’ve addressed the actual operational risk, regardless of how the breach itself happened.

— Randy Bryan

Get Breach Response and HIPAA Compliance Support From tekrescue

tekrescue is the alternative to piecing together your breach response from a legal team, a separate IT vendor, and a compliance consultant who’ve never worked together before. When the 60-day clock is running, that gap between teams is exactly where notices slip past deadline. tekrescue’s incident response team handles containment and evidence preservation directly, while its HIPAA compliance work builds the documentation trail your risk assessment needs to hold up under review.

That means faster containment when systems need to be isolated, a defensible file when you’re deciding whether the low-probability exception applies, and support meeting the “without unreasonable delay” standard instead of watching day 60 arrive with notices half-drafted. tekrescue’s cybersecurity services also cover the risk assessments that keep the next incident from becoming a breach at all.

If you’re managing a live incident or want your notification workflow reviewed before you need it, consider talking to a service provider to review your specific timeline and documentation gaps.

Sources

Keep these close during any active breach, since you’ll reference them repeatedly:

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

What Are the HIPAA Breach Notification Requirements?

You must notify each affected individual, notify the HHS Secretary through the OCR breach portal, and notify prominent media outlets if more than 500 residents of a state are affected. All three notices must go out without unreasonable delay and no later than 60 calendar days after discovery, and individual notices must include the specific elements listed in 45 CFR §164.404.

How Soon After a HIPAA Breach Must People Be Notified?

No later than 60 calendar days after discovery, though the actual legal standard is “without unreasonable delay,” meaning you should notify sooner whenever you reasonably can. Discovery date is the day the breach was known, or would have been known through reasonable diligence, not the day you personally confirmed it.

Who Must Be Notified About a HIPAA Confidentiality Breach?

Affected individuals always get notice, and the HHS Secretary gets notice through the portal based on the 500-person threshold and timing rules. Media notice is required only when the breach affects more than 500 residents of a single state or jurisdiction, and business associates must notify the covered entity under 45 CFR §164.410 whenever they discover the breach first.

What Happens if a Covered Entity Misses the 60-Day Deadline?

Missing the deadline exposes the organization to OCR enforcement, and settlements have specifically cited delayed notification as an aggravating factor separate from the breach itself. It can also trigger separate liability under state breach-notification laws, since HIPAA sets a federal floor that some states exceed with their own stricter deadlines.

Does a Business Associate Have Its Own Notification Deadline?

Yes. A business associate must notify the covered entity without unreasonable delay and no later than 60 days after its own discovery of the breach, under 45 CFR §164.410. Many business associate agreements set a shorter contractual deadline than 60 days, and that contractual deadline functions as a hard operational limit even though the regulation allows more time.

Previous Post
PHI vs PII: Classify Data Before It Becomes a HIPAA Breach

Related Posts

Decorative PHI versus PII title card

PHI vs PII: Classify Data Before It Becomes a HIPAA Breach

SEO content planning title card

Publish in 6–8 Weeks: SEO Content Plan for Small Teams

Headless CMS architectural title card

Headless CMS for 3+ Channels: Benefits and 4 Tradeoffs Devs and IT Must Plan