HIPAA Breach Timeline for Notifying HHS: Deadlines and Reporting Requirements
HIPAA Breach Notification Timeline
The HIPAA Breach Notification Rule sets strict, calendar-day deadlines once a breach of unsecured protected health information is discovered. Covered entities must move quickly while documenting every step.
Key deadlines at a glance
- Affected individuals notification: without unreasonable delay and no later than 60 calendar days after discovery.
- Notification to HHS (500+ individuals affected): within 60 calendar days of discovery.
- Notification to HHS (<500 individuals affected): no later than 60 days after the end of the calendar year in which the breach was discovered (typically by March 1 of the following year).
- Business associate to covered entity: without unreasonable delay and no later than 60 days after the business associate discovers the breach.
Counting the days
The 60-day limit means calendar days, not business days. You do not wait for a complete investigation to begin notices; you must send timely initial notices and supplement them as more facts develop.
Permissible law enforcement delay
If a law enforcement official determines that notice would impede an investigation or cause damage to national security, notification may be delayed for the time specified by law enforcement.
Breach Discovery Definition
Discovery occurs on the first day the breach is known—or by exercising reasonable diligence would have been known—by a workforce member or agent other than the person who committed the incident. This definition prevents delays caused by internal handoffs.
Confirming a “breach” under the rule
Not every incident requires notification. Under the breach notification rule, you must conduct a risk assessment to determine whether there is a low probability that PHI has been compromised. Consider the nature and extent of the PHI, who received it, whether it was actually viewed or acquired, and the degree to which risks were mitigated.
Unsecured vs. secured PHI
Notification duties apply to breaches of unsecured protected health information—PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals (for example, via strong encryption or proper destruction methods). If PHI is properly secured, the notification requirements generally do not apply.
Notification to Individuals
Covered entities must send direct written notice to each affected individual without unreasonable delay and in no case later than 60 days after discovery. When individuals have agreed to electronic notice, email may be used; otherwise, use first-class mail.
Substitute notice
- Fewer than 10 individuals with outdated or insufficient contact information: use an alternative form of notice (e.g., phone, email, or another agreed method).
- Ten or more such individuals: post a conspicuous notice on the home page or provide notice in major print or broadcast media for at least 90 days, and include a toll‑free number active for the same period.
Urgent situations
When imminent misuse of PHI is suspected, you may provide telephone or other immediate notice in addition to the written affected individuals notification.
Media notice for large breaches
If a breach involves 500 or more residents of a single state or jurisdiction, provide notice to prominent media outlets serving that area without unreasonable delay and within 60 days of discovery.
Notification to HHS
HHS must be notified for all reportable breaches via the HHS breach portal. The timing depends on the number of affected individuals.
Breaches affecting 500 or more individuals
- Submit the breach report submission without unreasonable delay and no later than 60 calendar days after discovery.
- File a separate report for each incident; do not batch large breaches.
- Be prepared to update your submission as additional details are confirmed.
Breaches affecting fewer than 500 individuals
Log each incident throughout the year and submit them in a single annual filing no later than 60 days after the end of the calendar year in which they were discovered.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Annual Reporting for Small Breaches
For breaches impacting fewer than 500 individuals, maintain a contemporaneous log capturing discovery date, number of affected individuals, incident type, and mitigation steps. Submit the annual compilation to HHS by the 60th day after year‑end (typically by March 1 of the following year).
Practical tips
- Record incidents as they occur; do not wait until year‑end to reconstruct details.
- Track whether business associates were involved and retain their notices and timelines.
- Document decisions when your risk assessment determines an incident is not a reportable breach.
Content of Notification
Individual notices and HHS submissions must be clear, accurate, and actionable. Include the following elements:
Required elements for notices to individuals
- A brief description of what happened, including the breach date and the date of discovery, if known.
- The types of PHI involved (for example, name, date of birth, diagnosis, treatment information, Social Security number, or financial data).
- Steps individuals should take to protect themselves (e.g., placing fraud alerts, monitoring accounts, changing passwords).
- What your organization is doing to investigate, contain, and prevent a recurrence, including mitigation steps taken.
- Contact methods for questions or assistance: toll‑free phone number, email address, website, or postal address.
Core fields for HHS breach report submission
- Covered entity or business associate identity and contact information.
- Number of individuals affected and the states/jurisdictions involved.
- Dates of the breach and discovery, and the location/type of incident (e.g., hacking/IT incident, unauthorized access/disclosure, theft, loss, improper disposal).
- Whether a business associate was involved and its role.
- A description of the incident and mitigation steps, plus any law enforcement delay.
Reporting Method
Use the HHS breach portal to submit all reports. Prepare your facts first so you can file on time even if some details remain under investigation.
Step-by-step process
- Confirm reportability under the breach notification rule (risk assessment, unsecured PHI, and scope).
- Determine the reporting track: 500+ individuals (individual incident report within 60 days) or fewer than 500 (aggregate annual filing).
- Assemble required details, including contact points, counts, dates, incident narrative, and mitigation steps.
- Complete the online form in the HHS breach portal and submit. Retain the confirmation for your records.
- Update the submission as new information emerges; you do not need to delay filing while investigating.
Coordination with business associates
Business associates must notify the covered entity without unreasonable delay and within 60 days of their discovery. Your contracts should specify roles for drafting and issuing individual notices, media notices, and the HHS filing, but the covered entity remains ultimately responsible for compliance.
Conclusion
Act fast, document thoroughly, and file on time. Start the 60‑day clock at discovery, notify affected individuals promptly, and use the HHS breach portal for timely, accurate submissions. For small breaches, keep a year‑round log and submit the annual report within 60 days after year‑end.
FAQs
What is the deadline for notifying HHS of a HIPAA breach?
If a breach affects 500 or more individuals, you must notify HHS without unreasonable delay and no later than 60 calendar days after discovery. For breaches affecting fewer than 500 individuals, submit an annual report to HHS no later than 60 days after the end of the calendar year in which the breach was discovered (typically by March 1 of the following year).
When does the breach notification timeline start?
The timeline starts on the date of discovery—the first day the incident is known, or by reasonable diligence would have been known, to a workforce member or agent other than the person who committed the incident. From that day, the 60‑day clock begins.
How should entities report breaches affecting fewer than 500 individuals?
Maintain a log of each incident throughout the year and submit all such breaches to HHS in a single annual filing via the HHS breach portal no later than 60 days after the end of that calendar year.
What information must be included in the breach notification?
Provide a brief description of what happened (including breach and discovery dates), the types of PHI involved, recommended protective steps for individuals, what your organization is doing to investigate and mitigate the breach and prevent recurrence, and clear contact information. Your HHS submission should also include counts, locations, incident type, business associate involvement, and mitigation steps.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.