HIPAA Breach Notification Checklist for Covered Entities: Required Steps, Timelines, and Notifications

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Breach Notification Checklist for Covered Entities: Required Steps, Timelines, and Notifications

Kevin Henry

Data Breaches

August 14, 2026

7 minutes read
Share this article
HIPAA Breach Notification Checklist for Covered Entities: Required Steps, Timelines, and Notifications

Definition of Breach

A HIPAA breach is the acquisition, access, use, or disclosure of Protected Health Information (PHI) in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. The rule presumes a breach of unsecured PHI unless you demonstrate a low probability that the PHI has been compromised.

Scope and Trigger

  • Applies to PHI in any form (paper, verbal, electronic/ePHI).
  • Triggered by impermissible disclosure or use outside minimum necessary or without a valid authorization.
  • “Discovery” occurs the day the breach is known, or by exercising reasonable diligence should have been known, to your organization.

Burden of Proof

You must document either: (1) notifications were provided as required, or (2) the incident did not constitute a breach (e.g., due to an exception or a documented low-probability finding).

Exceptions to Breach Definition

The following incidents are not breaches, provided no further impermissible use or disclosure occurs:

  • Unintentional acquisition, access, or use of PHI by a workforce member or person acting under your authority, in good faith and within scope of authority.
  • Inadvertent disclosure from one person authorized to access PHI to another person authorized to access PHI within the same covered entity or business associate.
  • Disclosure where you have a good-faith belief the unauthorized person to whom the disclosure was made would not reasonably have been able to retain the information.

Conducting Risk Assessments

Perform and document a risk assessment for every incident involving unsecured PHI to determine whether there is a low probability that the PHI has been compromised. Use clear Risk Assessment Criteria and keep records for at least six years.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

The Four Required Factors

  • Nature and extent of PHI involved (identifiers exposed, sensitivity, risk of financial or reputational harm).
  • The unauthorized person who used the PHI or to whom the disclosure was made (e.g., another HIPAA-regulated entity vs. a layperson).
  • Whether the PHI was actually acquired or viewed (as opposed to just potentially accessible).
  • The extent to which the risk has been mitigated (e.g., satisfactory return or destruction, binding confidentiality assurances).

Practical Steps

  • Secure the incident scene, preserve logs, and identify all systems and records affected.
  • Map data elements, affected individuals, and exposure window; verify what was actually accessed or exfiltrated.
  • Score the four factors, document rationale, and determine if notification is required.
  • Record Breach Reporting Timelines and assign owners to each notification task.

Individual Notification Requirements

Timelines

  • Notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery.
  • Law enforcement delay: you may delay if a law enforcement official states that notice would impede an investigation or threaten national security (oral requests permit a limited delay; written statements control the delay period).

Method and Form

  • Written notice by first-class mail to the individual’s last known address; electronic notice permitted if the individual agreed to receive e-communications.
  • Use clear, plain language tailored to the audience; provide language access as appropriate.
  • Urgent situations: provide additional notice by telephone or other means as needed.

Required Content

  • Brief description of what happened, including dates of breach and discovery.
  • Description of the types of information involved (e.g., names, Social Security numbers, diagnoses).
  • Steps individuals should take to protect themselves (e.g., credit monitoring, password changes, fraud alerts).
  • What you are doing to investigate, mitigate harm, and prevent recurrence.
  • Contact methods for questions (toll-free number, email, postal address, and website as applicable).

Substitute Individual Notice Procedures

Use substitute notice when contact information is insufficient or out of date.

Fewer Than 10 Individuals

  • Provide substitute notice by an alternative form such as telephone, email, or other reasonable means.

10 or More Individuals

  • Provide substitute notice via a conspicuous website posting for at least 90 days or through major print/broadcast media in the affected geographic area.
  • Include a toll-free number active for at least 90 days for individuals to determine if they were affected.

Media Notification Requirements

  • If a breach involves 500 or more residents of a single state or jurisdiction, notify prominent media outlets serving that area without unreasonable delay and no later than 60 calendar days after discovery.
  • Media notice supplements, but does not replace, individual notice and must include the same core content.

Reporting to the Secretary of Health and Human Services

Breach Reporting Timelines

  • 500 or more individuals: report to HHS without unreasonable delay and no later than 60 calendar days after discovery.
  • Fewer than 500 individuals: log the breach and report to HHS no later than 60 days after the end of the calendar year in which the breach was discovered.

What to Submit

  • Covered entity information, breach dates, number of affected individuals, breach location and type, mitigation steps, and media/substitute notice details where applicable.
  • Maintain submission confirmations and all supporting documentation for at least six years.

Business Associate Notification

Business Associate Obligations include notifying the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery, unless your agreement requires a shorter period.

Required Details from the Business Associate

  • Identification of each affected individual (to the extent possible) and the scope of information involved.
  • Brief description of what happened, dates, and discovery date.
  • Known or suspected unauthorized recipients and whether PHI was actually acquired or viewed.
  • Mitigation steps taken and any recommended protective actions for individuals.

Coordination Tips

Encryption Safe Harbor Practices

Incidents involving PHI that has been rendered “secured” are not reportable breaches. Unsecured PHI is PHI that is not encrypted or destroyed in accordance with HHS guidance.

How to Achieve Safe Harbor

  • Encryption in transit and at rest using strong, industry-recognized, FIPS-validated cryptographic modules.
  • Full-disk encryption for laptops and mobile devices; key management, rotation, and separation of duties.
  • Secure destruction of media and paper (e.g., shredding, pulping, degaussing, or cryptographic erasure) so PHI is unreadable and cannot be reconstructed.
  • Policies, access controls, and continuous monitoring to prevent impermissible disclosure and to evidence compliance.

Conclusion

Use this HIPAA Breach Notification Checklist to rapidly assess incidents, apply Risk Assessment Criteria, meet all Breach Reporting Timelines, and deliver precise notices. By hardening systems with encryption safe harbor controls and clarifying Business Associate Obligations, you reduce risk, accelerate response, and protect individuals’ privacy.

FAQs.

What constitutes a HIPAA breach for covered entities?

A breach occurs when there is an impermissible use or disclosure of unsecured PHI that compromises its security or privacy. Unless an exception applies or a documented assessment shows a low probability of compromise, you must treat the incident as a breach and follow the notification requirements.

How soon must individuals be notified after a breach?

You must notify affected individuals without unreasonable delay and no later than 60 calendar days after the breach is discovered. Start counting on the discovery date—when you knew, or by reasonable diligence should have known, that a breach occurred.

When is substitute notice required?

Use substitute notice when you lack sufficient or current contact information for affected individuals. If fewer than 10 are unreachable, use an alternative method such as telephone or email. If 10 or more are unreachable, post a conspicuous website notice for at least 90 days or notify through major media in the affected area and provide a toll-free number active for at least 90 days.

What are the encryption safe harbor provisions?

If PHI is encrypted or destroyed in line with HHS guidance (e.g., strong, FIPS-validated encryption for ePHI; secure destruction for paper/media), it is considered secured. When secured PHI is lost or stolen but remains unreadable or indecipherable to unauthorized individuals, breach notification is generally not required.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles