Cybersecurity and HIPAA

Top 10 HIPAA Breach Notification Requirements

A patient record exposed by mistake can trigger more than a private email. HIPAA uses different notice rules based on the data involved, the number of people affected, and where they live. We’ve listed the 10 requirements that healthcare leaders, nursing homes, home health teams, and their IT partners need to check first.

The goal is simple: find the facts fast, document the decision, and send each notice before its deadline.

1. Advatek

Advatek is a cybersecurity compliance and managed IT provider for regulated organizations. We’re best suited to small and mid-sized healthcare groups that need one team to manage security monitoring, compliance work, staff training, and technology planning.

Screenshot of the Advatek website

Our role in a breach is operational. We can help preserve logs, review access, identify affected systems, and map the event to the right HIPAA notice path. We also help clients build policies before an incident occurs, so staff know who must act when an alert appears.

Advatek has more than 20 years of experience in managed IT and compliance support. We also help organizations assess AI tools before those tools touch patient data. The caveat is important: an IT provider can support the process, but the covered entity remains responsible for its legal decisions and notices.

For a healthcare business, this brings breach response and managed IT services together.

2. HIPAA Breach Definition, Identify What Counts as an Impermissible Disclosure

HIPAA data breach notification requirements start with a key question: did someone acquire, access, use, or disclose PHI in a way HIPAA does not permit?

Illustration for HIPAA Breach Definition

An impermissible disclosure is not automatically a reportable breach. The organization must check whether an exception applies or whether it can show a low probability that the PHI was compromised. Applicable HIPAA requirements provide the governing framework.

Examples include an employee sending a patient file to the wrong person, a stolen laptop, or a vendor exposing records through a weak account. A good-faith mistake within a worker’s role may fall under an exception if the recipient could not retain the information. That conclusion needs facts, not a guess.

We recommend opening the incident response policy as soon as an unauthorized access event appears. Record what happened, who saw the data, and what the team did next.

3. Unsecured PHI, Distinguish Protected Data From Properly Secured Data

Unsecured PHI is health information that has not been made unusable, unreadable, or indecipherable to unauthorized people through an accepted technology or method.

Illustration for Unsecured PHI

For electronic records, encryption is the main example. It should protect data at rest, such as files on a drive, and data in transit, such as a message sent outside the organization. Paper records cannot be encrypted, so secure disposal matters instead. A paper chart left in a public bin may remain unsecured even if the electronic record system is well protected.

HIPAA’s Security Rule safeguards do not automatically remove the breach notice duty. A firewall or password may be useful, but they do not necessarily make exposed PHI unreadable. We need to confirm what protection was active when the event occurred.

That review should include email, backups, laptops, cloud storage, and printed records. The right question is not “Did we have security?” It is “Could an unauthorized person use the exposed information?”

4. Individual Notice, Meet the 60-Day Notification Deadline

Covered entities must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovering a reportable breach.

Illustration for Individual Notice

HIPAA data breach notification requirements generally call for first-class mail. Email may be used when the person has agreed to electronic communication. The notice should explain what happened, what PHI was involved, what the organization has done, and what steps the person can take.

If contact details are missing for fewer than 10 people, the organization may use substitute methods such as phone contact or another written notice. When contact information is missing for 10 or more people, substitute notice can require a website posting or notice through major media for at least 90 days.

Do not wait for every forensic detail if the facts already support notice. We can help teams build a letter template with approved plain-language sections, then update the details as the investigation develops.

Keep proof of delivery, returned mail, email records, and the final notice text. Those records show when the organization acted.

5. HHS Secretary Notice, Apply the 500-Person Reporting Threshold

Breaches affecting 500 or more people require notice to the HHS Secretary without unreasonable delay and no later than 60 days after discovery.

Illustration for HHS Secretary Notice

The report goes through HHS’s breach reporting process. Count affected people carefully. A single incident may involve several locations, covered entities, or states, and the count must match the records behind the notice.

Breaches affecting fewer than 500 people still require reporting. The usual timing is within 60 days after the end of the calendar year in which the breach was discovered. That later filing date does not remove the duty to notify affected individuals within 60 days.

Business associates have a separate duty to notify the covered entity about a breach. Their contract may set a shorter deadline, so the organization should not assume it has the full federal window to coordinate.

Key Takeaway: A smaller breach may have a later HHS filing date, but individual notices still follow the 60-day rule.

6. Media Notice, Understand When Large Breaches Require Public Reporting

Media notice is required when a breach affects more than 500 residents of one state or jurisdiction.

Illustration for Media Notice

The covered entity must notify prominent media outlets serving that area within 60 days of discovering the breach. This notice does not replace direct notice to each affected person. It is an added duty.

The state-by-state distribution can determine whether a breach triggers media notice. HHS reporting may still be required because the total is 500 or more.

A website press release alone does not satisfy the media rule. The organization must contact suitable prominent outlets in the affected state or jurisdiction. The regulatory explanation of media notice also makes clear that media notice is not the same as posting a release on the organization’s own site.

7. Risk Assessment, Document Whether Compromise Is Low Probability

A risk assessment determines whether an impermissible use or disclosure is likely to have compromised PHI. HIPAA data breach notification requirements presume a breach unless the organization can support a low-probability conclusion.

Illustration for Risk Assessment

At minimum, review four points:

  • The type of PHI involved and how easily a person could be identified.
  • The unauthorized person who received or accessed the information.
  • Whether the PHI was actually viewed or acquired, rather than merely available.
  • How well the organization reduced or ended the risk.

Consider a misdirected message that reached another healthcare provider, where the recipient confirmed deletion. That may be different from a public website exposure that search engines cached. The facts matter.

Save the incident time line, system logs, interview notes, recipient statements, data sample, and final decision. If the team decides notice is not required, document why. A short conclusion with no evidence is weak during an audit.

We can help healthcare leaders add this review to a broader HIPAA compliance checklist so the same process is used every time.

8. Breach Response Plan, Investigate, Mitigate, and Trigger Notifications

A breach response plan turns an alert into a controlled investigation. It should tell staff who leads, who preserves evidence, who approves notices, and who speaks with affected people.

Illustration for Breach Response Plan

Start by containing the event. Isolate affected equipment when safe, preserve forensic evidence, change exposed credentials, and restrict access that is no longer needed. Do not wipe a device before qualified investigators preserve the evidence.

Then confirm the scope. Review access logs and backups. Identify the PHI involved. Count affected people and check their contact details. If a service provider had access, confirm what it did and whether it corrected the weakness.

Response point Record to keep Decision it supports
Containment System actions and credential changes Whether further access continued
Investigation Logs, interviews, and forensic findings What happened and who was affected
Risk review Four-factor assessment Whether the event is reportable
Notification Letters, filings, and delivery proof Whether each duty met its deadline

Healthcare billing systems can also sit inside this chain. A practice reviewing ambulatory surgery center billing software cost per claim should ask how the billing platform handles PHI access, vendor duties, and incident handoffs.

Businesses should use data breach response guidance to secure systems, preserve evidence, review service-provider access, and document the investigation. HIPAA teams can apply those response habits while following HIPAA-specific notice rules.

9. Notification Content and State Rules, Cover Letters, Templates, and Added Duties

Each individual notice should explain the breach in plain language. Include the discovery date, the general type of PHI involved, the steps taken to investigate and reduce harm, and the actions people can take.

Illustration for Notification Content and State Rules

Do not include details that could increase risk or interfere with law enforcement work. A notice should help the recipient decide what to do next, such as watching accounts or changing credentials when those steps fit the exposed data.

State breach laws may add duties beyond HIPAA. Deadlines, required wording, attorney general notices, and consumer protection rules can differ. A healthcare organization should review the state where affected residents live, not only where the clinic operates.

Business associate agreements should also spell out who drafts notices, who submits reports, and who answers patient questions. That prevents a vendor and covered entity from each assuming the other has acted.

10. Cloud and AI Workflows, Extend Compliance Controls to Emerging Technology

Cloud and AI workflows can place PHI in new systems, prompts, logs, and backup stores. The same HIPAA data breach notification requirements apply when an unauthorized person gains access through those systems.

Illustration for Cloud and AI Workflows

An AI tool’s data handling, storage, access, log retention, and contract support should be reviewed before approval. A tool that summarizes patient notes may still expose PHI through a prompt history or admin account.

Cloud use also changes the investigation. Teams may need audit logs from the provider, identity records from a single sign-on system, and retention data from several services. Without those records, the organization may struggle to identify the affected people or prove that data was deleted.

We can manage these controls through managed IT services, access reviews, patch management, and security monitoring. Professional oversight matters because a quick AI rollout can create data paths that staff cannot see or control.

Pro Tip: Keep an approved list of AI and cloud tools, then review every new tool before staff enter PHI into it.

FAQ

What is the HIPAA breach notification deadline?

The HIPAA breach notification deadline is 60 calendar days after discovery for notice to affected individuals. The organization must act without unreasonable delay. The same 60-day limit applies to HHS reporting for breaches affecting 500 or more people and to media notice when that duty applies.

Who must be notified after a HIPAA breach?

After a reportable HIPAA breach, the covered entity must notify affected individuals. It may also need to notify the HHS Secretary and prominent media outlets. A business associate must notify the covered entity when the breach occurs in its systems or through its work.

What counts as unsecured PHI?

Unsecured PHI is information that has not been made unusable, unreadable, or indecipherable to unauthorized people through an accepted method. Unencrypted electronic records are a common example. Paper PHI and improperly disposed records can also be unsecured because encryption cannot protect paper.

Is every HIPAA violation a reportable breach?

Every HIPAA violation is not automatically a reportable breach. The organization must check the exceptions and complete a documented risk assessment when needed. It must review the data involved, the unauthorized recipient, whether the data was viewed, and the steps taken to reduce the risk.

Do business associates have to report HIPAA breaches?

Business associates must notify the covered entity when they discover a breach involving the covered entity’s PHI. The business associate agreement may require faster notice than federal law. The covered entity usually coordinates individual, HHS, and media notices, but the contract should state each party’s role clearly.

Conclusion

We recommend treating every suspected PHI exposure as a documented incident until the facts support another conclusion. Start by checking your 60-day clock, your business associate agreements, and your four-factor risk assessment process. If those pieces are unclear, Advatek can help map your response plan to the right notice duties and add managed security controls that support day-to-day compliance.

Download Franchise Information Report

Want to learn more about opening your own franchise? Fill out this form to get started:

    By pressing Submit, you agree that Advatek, Inc. may contact you by phone, email and/or text message about your inquiry, which may be automated. You don't need to consent as a condition of any purchase, and you can revoke consent at any time. Message and data rates may apply. You also agree to Advatek, Inc.’s Privacy Policy.