What Is the HIPAA Reporting Deadline for Breaches Affecting Fewer Than 500 People?
Overview of HIPAA Breach Notification Rule
The HIPAA Breach Notification Rule requires you—if you are a covered entity or a business associate—to notify affected individuals, and in many cases the Secretary of Health and Human Services, after a breach of unsecured protected health information (PHI). Your obligations hinge on how many people are affected and when the incident is discovered.
For breaches affecting fewer than 500 individuals, you must provide individual notices without unreasonable delay and within the 60-day reporting deadline measured from the incident discovery date. Reporting to the Secretary follows a different timetable: calendar year reporting, submitted after year-end, as detailed below.
Who must comply
- Covered entities: health plans, healthcare providers, and healthcare clearinghouses.
- Business associates: vendors and subcontractors that create, receive, maintain, or transmit PHI on behalf of a covered entity.
What triggers notification
A reportable breach is an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, unless a documented risk assessment shows a low probability of compromise. If PHI is properly encrypted or destroyed per recognized methods, it is not “unsecured,” and the Breach Notification Rule may not apply.
Definition of Breaches Affecting Fewer Than 500 Individuals
A “breach affecting fewer than 500 individuals” is a single breach event in which the number of affected persons is 1–499. Count every individual whose unsecured PHI was compromised in that incident, across your organization and locations, and treat each separate incident independently for reporting purposes.
Key terms you should document
- Unsecured PHI: PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons (for example, PHI not encrypted to an accepted standard).
- Incident discovery date: the first day the breach is known—or would have been known with reasonable diligence—by you or any of your workforce members or agents, other than the person committing the breach.
- Affected individuals: unique persons whose PHI was compromised; do not double-count the same person for the same incident.
Reporting Requirements and Timelines
At-a-glance timeline
- Individuals: notify without unreasonable delay and no later than 60 calendar days after the incident discovery date.
- Secretary of Health and Human Services (HHS): for breaches affecting fewer than 500 individuals, report no later than 60 days after the end of the calendar year in which the breach was discovered (i.e., calendar year reporting).
- Media notice: not required for breaches under 500 individuals.
- Business associate to covered entity: notify the covered entity without unreasonable delay and within 60 calendar days of discovery, providing all available details.
Practical examples
- If you discover a breach on July 10, 2026, you must notify affected individuals by September 8, 2026 (60 calendar days). Your HHS submission is due no later than 60 days after December 31, 2026—typically March 1, 2027.
- If you discover a breach on December 5, 2026, individuals must still be notified by February 3, 2027, and your HHS submission is due by around March 1, 2027.
What must individual notices include
Your written notice (mail or email if the individual has agreed) should describe what happened, the types of PHI involved, the steps you took to mitigate harm, what affected individuals can do, and how they can contact you for more information.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Steps to Report a Breach to HHS
- Confirm reportability. Perform and document the Breach Notification Rule risk assessment. If the probability of compromise is not low, treat the incident as a reportable breach.
- Record the incident discovery date. This anchors all deadlines, including the 60-day reporting deadline to individuals and the year-end timetable to HHS.
- Assemble required details. Capture dates of breach and discovery, number of affected individuals, type and location of PHI, how the breach occurred (e.g., unauthorized access, theft, hacking/IT incident, improper disposal), mitigation actions, and your point of contact.
- Maintain a breach log. Track all breaches affecting fewer than 500 individuals during the year to streamline calendar year reporting.
- Submit to HHS via the online breach reporting portal. Select the option for “breaches affecting fewer than 500 individuals” and complete a separate submission for each incident discovered that year. Save confirmations for your records.
- Retain documentation for at least six years. Keep your risk assessment, notices, portal confirmations, and related correspondence to support breach reporting compliance.
Consequences of Missing Reporting Deadlines
Late or incomplete notices can trigger investigations by HHS’s Office for Civil Rights (OCR). Outcomes may include corrective action plans, monitoring, and civil monetary penalties that scale based on culpability and ongoing noncompliance.
Delays can also increase exposure under contracts, invite state enforcement, strain patient trust, and raise costs for remediation. Each late notice to an affected person may constitute a separate violation, compounding potential penalties.
Best Practices for Compliance
- Establish an incident response plan that defines how you determine the incident discovery date and who is accountable for decisions and submissions.
- Use calendar controls: log small breaches as they occur and schedule your HHS submission window early in January to avoid last‑minute issues.
- Encrypt PHI at rest and in transit, apply access controls and MFA, and minimize PHI where possible to reduce the likelihood of reportable breaches.
- Train workforce members on recognizing, escalating, and documenting incidents quickly; run tabletop exercises to validate timing and handoffs.
- Manage business associates: confirm contractual notice timelines, required data elements, and points of contact for swift coordination.
- Document everything: risk assessments, decision rationales, notices, and portal receipts to demonstrate breach reporting compliance.
Resources for Covered Entities
- HHS OCR Breach Notification Rule guidance and FAQs for interpretive support.
- HHS online breach reporting portal for submitting notices to the Secretary of Health and Human Services.
- Notification templates for individuals, call scripts, and tracking logs to standardize responses.
- NIST cybersecurity and encryption publications to align technical safeguards.
- State attorney general resources to reconcile HIPAA with state breach laws and timelines.
- External advisors—privacy counsel and compliance consultants—for complex or multi-state incidents.
Conclusion
For breaches affecting fewer than 500 individuals, HIPAA requires prompt individual notification within 60 calendar days of discovery and calendar year reporting to the Secretary of Health and Human Services no later than 60 days after year‑end. If you document discovery dates, log incidents as they happen, and submit early, you will stay ahead of deadlines and strengthen overall breach reporting compliance.
FAQs
What is the reporting deadline for breaches affecting fewer than 500 people?
You must report the breach to the Secretary of Health and Human Services no later than 60 days after the end of the calendar year in which you discovered the breach. For example, if you discovered the incident on August 5, 2026, your HHS report is due by around March 1, 2027. Individual notices are still due within 60 calendar days of discovery.
How do covered entities report small breaches to HHS?
Use HHS’s online breach reporting portal and choose the option for breaches affecting fewer than 500 individuals. Submit a separate entry for each incident discovered during the year, complete all required fields, and save the confirmation for your records.
What are the penalties for late breach reporting?
OCR may open an investigation, require a corrective action plan, and impose civil monetary penalties. Late notification to individuals and late reporting to HHS are each violations, and penalties scale with the level of negligence and duration of noncompliance.
When does the reporting clock start for breaches under HIPAA?
The 60-day clock for notifying individuals starts on the incident discovery date—the first day the breach is known or should reasonably have been known to you or your workforce or agents. For HHS reporting of small breaches, the clock is tied to calendar year reporting: you must submit within 60 days after the end of the year in which you discovered the breach.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.