Kentucky Hospital Breach Notification Rules After a Business Associate Cyber Incident

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Kentucky Hospital Breach Notification Rules After a Business Associate Cyber Incident

Kevin Henry

Data Breaches

August 04, 2026

7 minutes read
Share this article
Kentucky Hospital Breach Notification Rules After a Business Associate Cyber Incident

Federal Breach Notification Requirements

Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414), you must notify affected individuals after a breach of Unsecured Protected Health Information (PHI) “without unreasonable delay” and no later than 60 calendar days from discovery. For breaches affecting 500 or more individuals, you must also notify the Secretary of HHS within 60 days; for fewer than 500, maintain a log and submit it to HHS within 60 days after the end of the calendar year. If 500+ residents of a single state or jurisdiction are affected, you must notify prominent media outlets serving that area. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))

“Unsecured” PHI is PHI not rendered unusable, unreadable, or indecipherable through HHS-specified methods (e.g., destruction or NIST-consistent encryption). Properly encrypted or destroyed PHI falls under a safe harbor and is not subject to breach notification. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.402?utm_source=openai))

HIPAA recognizes limited exceptions (e.g., certain good‑faith, unintentional disclosures) and presumes an impermissible use/disclosure is a breach unless you demonstrate a low probability of compromise via a documented risk assessment. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2024-title45-vol2/pdf/CFR-2024-title45-vol2-sec164-404.pdf?utm_source=openai))

Business Associate Breach Reporting Obligations

After a cyber incident, a Business Associate (BA) must notify the Covered Entity (CE) “without unreasonable delay” and no later than 60 calendar days from discovery. That notice must identify each affected individual (to the extent known) and include all information the CE needs to complete individual notices, providing updates as additional details become available. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-sec164-410.pdf?utm_source=openai))

Most BA requirements should be hard‑wired into your Business Associate Agreement (BAA), including incident reporting timeframes, cooperation duties, data to be shared, and allocation of notification tasks. HIPAA permits a BA to submit a breach report to HHS on the CE’s behalf where delegated. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html?utm_source=openai))

Kentucky State Cybersecurity Notification Laws

Private‑sector data breach law (KRS 365.732)

Kentucky requires “information holders” to notify residents of breaches of unencrypted, unredacted computerized personal information in the most expedient time possible and without unreasonable delay, subject to law‑enforcement holds and scoping/remediation needs. Substitute notice is allowed if costs exceed $250,000, affected persons exceed 500,000, or contact data is insufficient; notify nationwide consumer reporting agencies if 1,000+ residents are notified. HIPAA‑regulated entities are expressly exempt from this statute. ([apps.legislature.ky.gov](https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43326))

Public agencies (KRS 61.931–61.934)

Public agencies (including certain state or local government‑operated hospitals) face stricter timelines: within 72 hours of determination or notification of a security breach, they must notify specified state authorities and begin a prompt investigation. If misuse occurred or is likely, they must notify those authorities again within 48 hours after concluding the investigation and notify affected individuals within 35 days; if 1,000+ will be notified, additional pre‑notice steps apply. ([apps.legislature.ky.gov](https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43577))

Insurance Data Security Law (KRS 304.3‑750 to 304.3‑768)

If your hospital or affiliate is an insurance “licensee,” a cybersecurity event involving Nonpublic Information may trigger a separate Cybersecurity Event Notification to the Kentucky Department of Insurance within three business days of determining an event occurred, with detailed follow‑up per regulation. This duty is independent of HIPAA and hinges on the statute’s definitions and thresholds. ([apps.legislature.ky.gov](https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=53296&utm_source=openai))

Covered Entities' Notification Responsibilities

Even when a breach originates at a BA, the hospital as Covered Entity (CE) is responsible for: (1) individual notices; (2) HHS Secretary reporting (timing depends on the number of affected individuals); and (3) media notice if 500+ residents of a state or jurisdiction are impacted. Your BAA can authorize the BA to perform some tasks, but accountability for HIPAA compliance remains with the CE. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html?utm_source=openai))

For incidents that also implicate state laws (e.g., payroll data under KRS 365.732 or a public‑agency hospital under KRS 61.933) or the Insurance Data Security Law for licensees, align your HIPAA notifications with any required Kentucky notifications to avoid conflicting timelines and content. ([apps.legislature.ky.gov](https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=43326))

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Breach Risk Assessment Procedures

HIPAA presumes a breach unless you demonstrate a low probability of compromise based on four factors: (1) the nature and extent of PHI involved; (2) the unauthorized person who used/received it; (3) whether PHI was actually acquired or viewed; and (4) the extent to which risks were mitigated. Document your analysis and rationale. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2024-title45-vol2/pdf/CFR-2024-title45-vol2-sec164-404.pdf?utm_source=openai))

Encryption at HHS‑specified levels can place incidents outside “Unsecured PHI,” eliminating the need for breach notification. For ransomware, evaluate whether ePHI was only encrypted or also exfiltrated/viewed, and whether strong backups and containment reduced risk. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/guidance/index.html?utm_source=openai))

Notification Content and Media Requirements

What to include

  • A clear description of what happened (including breach and discovery dates, if known) and the types of Unsecured PHI involved. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.404?utm_source=openai))
  • Steps individuals should take to protect themselves. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.404?utm_source=openai))
  • What you are doing to investigate, mitigate harm, and prevent future breaches. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-part164.pdf?utm_source=openai))
  • How to reach you (toll‑free number, email, website, or postal address). ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-part164.pdf?utm_source=openai))

How to deliver notice

Provide written notice by first‑class mail or email (if the individual agreed). If you have insufficient or out‑of‑date contact information for 10 or more individuals, provide substitute notice via your website home page (for at least 90 days) or major print/broadcast media where affected individuals likely reside, plus a toll‑free number. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html?utm_source=openai))

Media notice triggers

HIPAA requires media notice when a breach involves 500+ residents of a single state or jurisdiction. Separately, Kentucky’s general breach law allows substitute notice to major statewide media if statutory cost/scale thresholds are met, and public agencies must use local/regional and, if widespread, statewide media as part of their individual‑notice process. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.406?utm_source=openai))

Documentation and Administrative Compliance

Maintain written policies, procedures, risk analyses, risk assessments, and breach‑response documentation for at least six years; HIPAA places the burden of proof on you to show required notices were made or that no breach occurred. Perform periodic evaluations and keep decision logs supporting your low‑probability determinations. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.530?utm_source=openai))

Train your workforce on privacy/security policies and breach workflows, and apply appropriate sanctions for policy violations. Security awareness and training, plus a sanctions policy, are required administrative safeguards under the HIPAA Security Rule. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.308?utm_source=openai))

FAQs.

What are the notification timelines for Kentucky hospitals after a business associate breach?

Under HIPAA, the BA must notify the hospital “without unreasonable delay” and no later than 60 days after discovery; the hospital must notify affected individuals within 60 days of discovery, notify HHS within 60 days if 500+ individuals are affected (or annually if fewer), and notify media if 500+ residents of a state/jurisdiction are impacted. If other Kentucky laws apply (e.g., KRS 365.732 for non‑PHI or KRS 61.933 for public‑agency hospitals) or if the hospital is an insurance licensee (KRS 304.3‑760), additional timelines—such as three business days to the DOI or 72‑hour/35‑day public‑agency deadlines—may apply. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-sec164-410.pdf?utm_source=openai))

Who must notify whom following a cyber incident involving protected health information?

The BA notifies the Covered Entity; the hospital (CE) notifies affected individuals whose protected health information was involved, HHS, and, if applicable, the media. A BA may submit a breach report to HHS on the CE’s behalf if delegated by the BAA. If the hospital (or an affiliate) is a Kentucky insurance licensee and Nonpublic Information is implicated, it must also notify the Department of Insurance within three business days of determining a qualifying cybersecurity event. ([govinfo.gov](https://www.govinfo.gov/content/pkg/CFR-2025-title45-vol2/pdf/CFR-2025-title45-vol2-sec164-410.pdf?utm_source=openai))

What information must be included in a breach notification?

Provide a plain‑language description of what happened (with breach and discovery dates, if known); the types of Unsecured PHI involved; steps individuals should take; what you are doing to investigate, mitigate harm, and prevent future incidents; and clear contact methods (toll‑free number, email, website, or mailing address). ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.404?utm_source=openai))

When is media notification required under Kentucky law?

HIPAA requires notice to prominent media outlets when 500+ residents of a single state or jurisdiction are affected. Separately, Kentucky’s general breach statute permits substitute notice to major statewide media if cost/scale thresholds are met, and public agencies must use local/regional—and if widespread, statewide—media as part of their notification to individuals. ([law.cornell.edu](https://www.law.cornell.edu/cfr/text/45/164.406?utm_source=openai))

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles