HIPAA 500+ Breach Reporting: HHS OCR Portal Guide and Incident Response Timeline

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA 500+ Breach Reporting: HHS OCR Portal Guide and Incident Response Timeline

Kevin Henry

Incident Response

September 19, 2026

9 minutes read
Share this article
HIPAA 500+ Breach Reporting: HHS OCR Portal Guide and Incident Response Timeline

Breach Notification Rule Overview

HIPAA’s Breach Notification Rule requires covered entities and business associates to notify affected individuals, HHS, and in some cases the media, when Unsecured Protected Health Information is compromised. “Unsecured” means the PHI was not rendered unusable, unreadable, or indecipherable through strong encryption or secure destruction. Establishing Breach Notification Rule Compliance starts with determining whether an incident meets the definition of a breach and whether an exception applies.

When an incident involves PHI, you must perform a documented risk assessment to evaluate the likelihood that the PHI was compromised. The assessment should consider four factors: the nature and extent of PHI involved; the unauthorized person who used or received the PHI; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated. This Risk Assessment Documentation anchors your decisions, timelines, and notifications.

Exceptions are narrow (for example, unintentional access by a workforce member acting in good faith within scope, inadvertent disclosure between authorized persons within the same entity, or a good-faith belief the recipient could not retain the information). If no exception applies and the risk assessment indicates a more-than-low probability of compromise, you must proceed with notifications under the Covered Entity Reporting Obligations or coordinate under Business Associate Notification Requirements, as applicable.

Reporting Requirements for 500+ Individuals

For a single breach affecting 500 or more individuals, a covered entity must provide: (1) written notice to each affected individual without unreasonable delay and no later than 60 calendar days after discovery; (2) notice to HHS within the same 60-day window; and (3) notice to prominent media outlets when 500 or more residents of a single state or jurisdiction are affected. These steps are in addition to any state breach laws that may impose parallel or shorter deadlines.

Individual notices must be clear and conspicuous, sent by first-class mail (or email if the individual agreed to electronic notice), and explain what happened, what information was involved, steps individuals should take, what you are doing to mitigate harm and prevent recurrence, and how to contact you. If contact information is insufficient for 10 or more individuals, provide substitute notice via website posting and/or media, and maintain a toll-free number for at least 90 days.

Even if a Business Associate caused the incident, the covered entity remains responsible for ensuring Breach Notification Rule Compliance for the 500+ event unless the business associate agreement assigns certain tasks (such as mailing letters) to the BA. Align responsibilities early to avoid delays.

Electronic Submission Via HHS Breach Portal

The HHS OCR Breach Portal (often called the “OCR breach reporting portal”) is the electronic system for notifying HHS of breaches. For 500+ events, you must submit electronically without unreasonable delay and within 60 days of discovery. Treat the portal submission as an official filing: prepare accurate details, designate a knowledgeable point of contact, and retain your confirmation for your records.

Step-by-step submission

  • Prepare: Compile your Incident Response Timeline, Risk Assessment Documentation, description of what happened, dates of breach and discovery, number of individuals affected, states of residence, types of PHI involved, and mitigation steps.
  • Identify parties: Specify whether you are the covered entity or a business associate reporting on behalf of one, and list any involved business associates or subcontractors.
  • Enter breach specifics: Select breach category (for example, hacking/IT incident, theft, loss, unauthorized access/disclosure, improper disposal) and the location of the PHI (for example, network server, email, paper, laptop, EMR).
  • Provide contacts: Enter the name, title, phone, and email of the person authorized to respond to OCR inquiries, and the public contact methods you provided to affected individuals.
  • Attach materials: Upload sample notification letters, press releases (if applicable), and key supporting exhibits (for example, risk assessment summary, forensic executive report).
  • Review and certify: Confirm accuracy, submit, and save the confirmation number. If facts change (for example, count adjustments), submit an addendum to update the record.

Required Information for Breach Reporting

The portal will ask for specific data elements. Gather them before you start to avoid timeouts and rework. Typical fields include:

  • Covered entity details: legal name, type (provider, health plan, clearinghouse), address, and NAICS/NPI if applicable.
  • Breach details: type of breach, location of PHI, date of breach, date of discovery, brief narrative of what happened, and whether law enforcement requested a temporary delay of notifications.
  • Impact metrics: number of individuals affected and states of residence; whether minors are included; whether the count is an estimate or confirmed.
  • PHI specifics: categories of data involved (for example, names, addresses, dates of birth, Social Security numbers, financial or account data, diagnoses, treatment information, prescription data, images).
  • Mitigation and safeguards: steps taken to contain and reduce harm, security measures in place at the time (for example, encryption, access controls), and improvements implemented post-incident.
  • Business associate involvement: identity of any BA or subcontractor and their role.
  • Notifications: dates individual notices were sent, media notice (if required), substitute notice, and methods used (mail, email, web posting).
  • Contacts: dedicated phone number, email, and postal address for questions from individuals and OCR.

Complete, consistent entries reduce follow-up questions and support swift resolution. If your counts or facts evolve as remediation proceeds, update the HHS OCR Breach Portal to maintain an accurate public record.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Incident Response Documentation

Thorough documentation underpins defensible Breach Notification Rule Compliance and speeds regulatory review. Maintain a cohesive file from discovery through closure that shows actions, decisions, and timing.

  • Incident Response Timeline: discovery date/time, containment steps, investigation milestones, decision points, notification dates, and closure.
  • Risk Assessment Documentation: four-factor analysis, rationale, encryption status, scope of Unsecured Protected Health Information, and mitigation effectiveness.
  • Forensic and security records: executive summary of forensic findings, relevant logs, access reviews, data mapping, and evidence of eradication and recovery.
  • Notifications pack: sample individual letter, media release (if applicable), FAQ/call scripts, proof of mailing or email delivery, and substitute notice artifacts.
  • Governance artifacts: approvals, counsel input, leadership briefings, sanctions (if any), updated policies, workforce training evidence, and BAA reviews.
  • Vendor coordination: communications with business associates/subcontractors, data reconciliation, and attestations.

Retain documentation for at least six years, consistent with HIPAA’s record retention requirements for policies, procedures, and actions taken.

Reporting Deadlines and Timelines

The 60-day clock starts on the date the breach is discovered or should reasonably have been discovered through due diligence. For 500+ incidents, submit individual notices, the HHS report, and any required media notice without unreasonable delay and in no case later than 60 calendar days after discovery.

If a law enforcement official states that notification would impede an investigation, you may delay notifications for the time specified. Document any oral or written delay request carefully in your Incident Response Timeline.

Practical incident response timeline

  • Day 0: Discover, contain, preserve evidence, open incident ticket, notify privacy/security leadership.
  • Days 1–3: Scoping and triage, confirm whether PHI is involved and whether it was unsecured, engage forensics and legal counsel.
  • Days 4–10: Complete preliminary risk assessment, begin identity and address reconciliation, draft notification content and call scripts.
  • Days 11–25: Finalize counts, coordinate with business associates, stand up call center, prepare HHS OCR Breach Portal submission package.
  • Days 26–45: Send individual notices, prepare media notice if 500+ residents in a state/jurisdiction are affected, refine addendum data.
  • By Day ≤60: Submit HHS report and any media notice; document completion; file all Risk Assessment Documentation and approvals.

For breaches involving fewer than 500 individuals, you still report to HHS, but you may aggregate and file no later than 60 days after the end of the calendar year in which the breaches occurred.

Business Associate Breach Reporting Obligations

Business associates must notify the covered entity of a breach of Unsecured Protected Health Information without unreasonable delay and no later than 60 calendar days after discovery. The notice must include the identification of each affected individual to the extent possible and all information the covered entity needs to meet its notification duties.

Subcontractors report up the chain to the business associate, which in turn reports to the covered entity. Your business associate agreement should set tighter internal timelines (for example, 5–15 days to provide preliminary notice and rolling updates) and specify cooperation requirements for data reconciliation, notification drafting, and portal support.

While a BA may be tasked with operational steps (like printing and mailing letters), the covered entity remains accountable for overall Breach Notification Rule Compliance and for ensuring that HHS and, when applicable, the media are notified within required timeframes.

Summary

Effective HIPAA 500+ breach reporting blends precise facts, disciplined timing, and complete documentation. Prepare your Incident Response Timeline early, use the HHS OCR Breach Portal to submit accurate details, coordinate closely with business associates, and maintain robust records to demonstrate compliance and continuous improvement.

FAQs

What information must be reported in a 500+ breach notification?

Report what happened (including breach and discovery dates), the types of PHI involved, how many individuals were affected and in which states, whether a business associate was involved, the mitigation and corrective actions taken, and how people can contact you. Attach sample notices and key Risk Assessment Documentation to support the submission.

When must a covered entity submit a breach report to HHS?

For a breach affecting 500 or more individuals, submit electronically via the HHS OCR Breach Portal without unreasonable delay and no later than 60 calendar days after discovery. For breaches affecting fewer than 500, submit annually within 60 days after the end of the calendar year.

How do business associates report a breach to covered entities?

Business associates must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, providing the identities of affected individuals (if known) and all details the covered entity needs to complete individual, HHS, and media notifications. BAAs often require earlier preliminary notice and ongoing updates.

What documentation is required to support breach reporting?

Maintain an end-to-end Incident Response Timeline, the four-factor Risk Assessment Documentation, forensic summaries and logs, sample individual and media notices, proof of mailing or substitute notice, mitigation steps, governance approvals, training or sanctions, and vendor/BA communications. Keep these records for at least six years.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles