Business Associate Breach in Healthcare: Incident Response and HIPAA Notification Obligations

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Business Associate Breach in Healthcare: Incident Response and HIPAA Notification Obligations

Kevin Henry

Incident Response

September 15, 2026

8 minutes read
Share this article
Business Associate Breach in Healthcare: Incident Response and HIPAA Notification Obligations

Definition of a Breach

Under HIPAA’s Breach Notification Rule, a breach is the acquisition, access, use, or disclosure of Protected Health Information (PHI) in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. The rule focuses on unsecured PHI—PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through technologies such as strong encryption.

There is a presumption that an impermissible use or disclosure is a breach unless you can demonstrate a low probability that the PHI has been compromised based on a documented risk assessment. That assessment must, at minimum, consider:

  • The nature and extent of the PHI involved (types of identifiers and likelihood of re-identification).
  • The unauthorized person who used the PHI or to whom the disclosure was made.
  • Whether the PHI was actually acquired or viewed.
  • The extent to which the risk to the PHI has been mitigated.

Secured vs. unsecured PHI

If PHI is properly encrypted or otherwise secured according to recognized guidance, an incident may not trigger notification duties because it does not involve unsecured PHI. However, you should still complete a brief breach investigation to confirm scope and controls.

Business Associate Notification Obligations

A Business Associate (BA) that discovers a breach of unsecured PHI must notify its Covered Entity (CE) without unreasonable delay and no later than 60 calendar days from discovery. “Discovery” occurs on the first day the breach is known to the BA, or would have been known by exercising reasonable diligence.

What the BA must provide

  • Identification of each affected individual, to the extent possible.
  • Available details the CE will need to complete notifications (e.g., brief incident description, date of breach and discovery, categories of PHI involved, and mitigation steps).
  • Ongoing updates as additional information is learned through the breach investigation.

Subcontractors and upstream reporting

BA subcontractors that handle PHI must report breaches to the BA, and the BA must in turn report to the CE. Contracts should clearly define timelines and required content, which may be shorter than HIPAA’s outer 60-day limit.

Immediate response actions

  • Contain and eradicate the incident; preserve logs and evidence for the breach investigation.
  • Initiate the risk assessment and document decision-making.
  • Coordinate with the CE on notification strategy, including any Media Notification if thresholds are met.

Covered Entity Notification Responsibilities

The Covered Entity is generally responsible for notifying affected individuals after a breach, even when a BA caused it. A BA may provide individual notifications on the CE’s behalf if the business associate agreement so specifies, but the CE remains ultimately accountable for compliance.

Who must be notified

  • Affected individuals: Notice must be sent in written form (first-class mail or email if the individual has agreed to electronic notice).
  • Media Notification: If a breach affects more than 500 residents of a single state or jurisdiction, the CE must notify prominent media outlets serving that area.
  • Secretary of HHS: Reporting requirements vary by the number of individuals affected (see Timing and Content of Notifications).

Coordinated incident management

CEs should direct the overall breach investigation, validate the BA’s findings, decide on notifications, and ensure consistent messaging across individual, media, and HHS reports.

Timing and Content of Notifications

Timing

  • BA to CE: Without unreasonable delay and in no case later than 60 calendar days after discovery.
  • CE to individuals: Without unreasonable delay and in no case later than 60 calendar days after discovery.
  • Media Notification: For breaches affecting more than 500 residents of a state or jurisdiction, within 60 calendar days after discovery.
  • CE to Secretary of HHS:
    • 500 or more individuals: Without unreasonable delay and in no case later than 60 calendar days after discovery.
    • Fewer than 500 individuals: Not later than 60 days after the end of the calendar year in which the breach was discovered (annual log submission).

Required content

Each individual and media notice must include, in plain language:

  • A brief description of what happened, including the date of the breach and the date of discovery, if known.
  • The types of PHI involved (for example, name, address, date of birth, medical record number, diagnosis, treatment information, or insurance details).
  • Steps individuals should take to protect themselves.
  • What the CE or BA is doing to investigate the breach, mitigate harm, and prevent future incidents.
  • Contact information for individuals to ask questions or learn more (toll-free number, email, or postal address).

Form and method

Notices must be sent by first-class mail to the individual’s last known address (or by email if the individual previously agreed). If contact information is insufficient for 10 or more individuals, substitute notice is required (for example, website posting or major print/broadcast media) and must include a toll-free number.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Exceptions to Breach Definition

HIPAA recognizes limited exceptions where an impermissible use or disclosure is not a “breach” and therefore does not require notification:

Workforce Member Exception (good-faith, within scope)

Unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of a CE or BA, if done in good faith, within the scope of authority, and without further impermissible use or disclosure.

Inadvertent disclosure to another authorized person

Disclosure by a person authorized to access PHI to another person authorized to access PHI within the same CE, BA, or organized health care arrangement, if the PHI is not further used or disclosed impermissibly.

Recipient could not reasonably retain the information

Disclosure of PHI where the CE or BA has a good-faith belief that the unauthorized recipient could not reasonably have retained the information (for example, sealed mail returned unopened).

Secured PHI safe harbor

Incidents involving properly encrypted or otherwise secured PHI are not breaches of unsecured PHI and do not trigger notification duties under the Breach Notification Rule.

Reporting to the Secretary of HHS

For breaches affecting 500 or more individuals, the CE must report to the Secretary of HHS without unreasonable delay and no later than 60 calendar days after discovery. HHS publicly posts such breaches on its breach portal. For breaches affecting fewer than 500 individuals, the CE must log the incident and submit it to HHS within 60 days after the end of the calendar year in which the breach was discovered.

While a BA may assist with drafting and data collection, the CE is responsible for ensuring that submissions are complete and timely, consistent with internal records and any individual or media notices.

Documentation and Compliance

Recordkeeping

  • Maintain written policies, procedures, risk assessments, breach investigation files, and copies of all notifications for at least six years.
  • Keep a central breach log that records discovery dates, decision rationales (including low probability of compromise analyses), and submission confirmations.

Contracts and governance

  • Ensure business associate agreements require prompt reporting, define notice content, allocate responsibilities, and flow down obligations to subcontractors.
  • Align incident response plans with the Breach Notification Rule and test them periodically.

Operational controls

  • Reduce risk by encrypting PHI at rest and in transit, enforcing least privilege, monitoring access, and training workforce members.
  • After each incident, document root causes and corrective actions, and update policies to prevent recurrence.

Effective preparation—clear contracts, mature incident response, and disciplined documentation—positions both Business Associates and Covered Entities to meet HIPAA’s timelines, deliver complete notifications, and protect individuals when a breach occurs.

FAQs

What are the notification deadlines for business associates after a breach?

A Business Associate must notify its Covered Entity without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI. Contracts may require a shorter timeframe, so review your agreement and act as soon as practicable.

What exceptions exempt a breach from notification?

Three key exceptions apply: the Workforce Member Exception (good-faith, within-scope access with no further impermissible use); inadvertent disclosure between two people authorized to access PHI within the same CE, BA, or organized arrangement; and disclosures where the unauthorized recipient could not reasonably have retained the information. Incidents involving properly secured (for example, encrypted) PHI also do not trigger notification.

Who is responsible for notifying affected individuals after a breach?

The Covered Entity is generally responsible for notifying affected individuals. A Business Associate may send notices on the CE’s behalf if the contract permits, but the CE remains ultimately accountable for compliance.

What information must be included in breach notifications?

Notices must explain what happened (including breach and discovery dates), identify the types of PHI involved, describe steps individuals should take to protect themselves, outline what the organization is doing to investigate, mitigate, and prevent future incidents, and provide contact information for questions.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles