How to Report a HIPAA Breach Through the HHS OCR Portal (Step-by-Step)

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Report a HIPAA Breach Through the HHS OCR Portal (Step-by-Step)

Kevin Henry

HIPAA

July 08, 2026

6 minutes read
Share this article
How to Report a HIPAA Breach Through the HHS OCR Portal (Step-by-Step)

When unsecured protected health information (PHI) is exposed, you must act quickly and precisely. This guide walks you through filing a HIPAA breach notification with the HHS Office for Civil Rights (OCR) using the OCR breach portal. It emphasizes covered entity compliance, clear documentation, and the practical steps that satisfy breach reporting requirements.

Follow the sequence below to prepare, enter accurate details, and obtain the breach confirmation number you’ll need for follow‑up and recordkeeping.

Access the OCR Breach Portal

Begin by navigating to the OCR breach portal. Use a modern browser and gather your materials before you start—this reduces errors and keeps your session efficient.

What to gather first

  • Legal name and address of the covered entity or business associate, plus any “doing business as” names.
  • Primary contact details: name, title, phone, and email for OCR correspondence.
  • Key dates: incident start/end (if known) and discovery date.
  • Preliminary counts of affected individuals and impacted states or jurisdictions.
  • Short narrative of what happened and how it was discovered.
  • Notes on whether law enforcement requested a delay of notifications.

Having this information on hand supports smooth data entry and helps you meet breach reporting requirements without rework.

Select Report Type

The portal will ask who is submitting and the size of the breach. Choose whether you are reporting as a covered entity or a business associate. Then indicate whether the incident involves 500 or more individuals, or fewer than 500.

This selection drives which fields appear and the timing expectations under HIPAA breach notification rules. Large breaches (500 or more) require prompt submission; smaller incidents are still reportable and must be documented accurately for compliance.

Identify involved parties

  • If you are a covered entity, list any business associate(s) involved.
  • If you are a business associate, identify the affected covered entity and provide their contact information.

Provide General Information

Enter organizational identifiers and contact details exactly as they appear in your official records. Consistency helps OCR match your report to any prior submissions or follow‑up inquiries.

Typical fields

  • Legal name of the covered entity and, if applicable, business associate name.
  • Mailing address, city, state, and ZIP code; primary phone number.
  • Website (if applicable) and any relevant identifiers (for example, NPI or EIN, if requested).
  • Primary contact’s name, title, phone, and email for all OCR communications.

Ensure the contact you list can answer questions quickly and coordinate internal responses; this is central to covered entity compliance.

Enter Breach Details

Next, document what happened. Be specific, factual, and concise—your goal is to clearly convey the nature and scope of the incident.

Core incident data

  • Dates: incident start and end (if known) and the discovery date.
  • Number of affected individuals (estimate if still under investigation).
  • States or jurisdictions where affected individuals reside.

Event characterization

  • Type of breach (for example, hacking/IT incident, theft, loss, unauthorized access/disclosure, improper disposal).
  • Location of the PHI (for example, email, paper records, desktop, laptop, mobile device, network server, cloud repository).
  • Data elements involved (for example, names, addresses, Social Security numbers, financial details, diagnoses, treatment information).
  • Security posture at the time (for example, encryption or other safeguards) and how the compromise occurred.

Narrative and constraints

  • Short narrative explaining how the breach was discovered, immediate containment steps, and current investigation status.
  • Whether law enforcement requested a temporary delay of notifications, including date parameters for the delay.

Clarity here speeds OCR’s understanding and aligns your submission with breach reporting requirements.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Describe Actions Taken

Use this section to show your mitigation and notification procedures. Describe what you did, when you did it, and how the actions reduce risk to affected individuals.

Mitigation and containment

  • Steps to secure systems or records (for example, password resets, device recovery, patching, disabling compromised accounts).
  • Forensics or third‑party assessments initiated to determine scope and root cause.
  • Remediation to prevent recurrence (for example, new technical controls, policy updates, staff training).

Notifications

  • Individual notifications: method (mail or permissible email), date(s) sent or planned, and a summary of content.
  • Media notice (if applicable for large breaches in a state or jurisdiction): timing and outlets used or planned.
  • Call center or credit monitoring services offered, including duration and enrollment method.

Tie each action to risk reduction for individuals. This strengthens your record of HIPAA breach notification and demonstrates a thoughtful response.

Complete Attestation

Before submission, you must complete the breach attestation. This e‑signature step confirms the accuracy of your report and that you are authorized to submit it on behalf of the organization.

  • Enter your name, title, organization, and the attestation date.
  • Affirm that the information provided is true, complete, and submitted in good faith.
  • Acknowledge your responsibility to update the report if new material facts emerge.

Attestation underscores accountability and supports covered entity compliance.

Review and Submit

Use the final review screen to verify all entries. Confirm names, dates, counts, and narratives, and ensure the contact information is correct for OCR follow‑up.

  • Correct any validation errors flagged by the portal.
  • Ensure the narrative clearly states the cause, scope, and current status of mitigation.
  • Confirm that “500 or more” versus “fewer than 500” selection matches your best current count.

After you submit, the portal will display a breach confirmation number. Save or print this number immediately; you will use it to reference the case, supplement details, or respond to OCR inquiries. Retain a complete copy of your submission for your records.

Done well, your submission documents what happened, how you mitigated harm, and the concrete steps you are taking to prevent recurrence—key elements of a compliant, transparent response.

FAQs.

What information is required for a HIPAA breach report?

You will need the reporting organization’s legal name and address; a primary contact’s name, title, phone, and email; incident dates (start/end, if known, and discovery); a good‑faith estimate of affected individuals and their states; the breach type and where the PHI resided; the kinds of PHI involved; a concise narrative of what occurred; steps taken for containment and mitigation; notification status; and whether law enforcement requested any delay. Identify any business associates involved and describe their roles.

How soon must a breach affecting 500 or more individuals be reported?

Report to HHS via the OCR breach portal without unreasonable delay and no later than 60 calendar days from the date of discovery. Individual notifications must also be provided without unreasonable delay and in no case later than 60 days, and media notice is required for incidents affecting 500 or more residents of a single state or jurisdiction. Timely action is central to breach reporting requirements and covered entity compliance.

What steps should be taken after submitting a breach report?

Continue mitigation, complete all individual notifications, and document returned or failed notices. Monitor systems, close remediation items, and update policies, technical controls, and workforce training. Keep the breach confirmation number handy for supplements or OCR questions, and submit updates if your investigation changes the incident scope, affected counts, or timelines. Maintain a comprehensive record to demonstrate ongoing compliance and continuous improvement.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles