The HIPAA Breach Notification Rule, at 45 CFR 164.400 through 164.414, requires covered entities and business associates to notify affected individuals, and in many cases HHS and the media, following a breach of unsecured protected health information. Not every impermissible use or disclosure of PHI counts as a reportable breach; the rule includes a structured risk assessment for determining that, along with fixed deadlines and thresholds that change based on how many people are affected.
What Counts as a Breach
Under 45 CFR 164.402, a breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule, that compromises the security or privacy of the information. "Unsecured" PHI means PHI that has not been rendered unusable, unreadable, or indecipherable through a technology or methodology specified by HHS, most commonly encryption meeting the applicable standard. PHI that is properly encrypted to that standard generally falls outside the rule's notification requirements even if it is accessed or disclosed improperly, because it is not considered "unsecured."
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless the covered entity or business associate demonstrates, through the risk assessment described below, that there is a low probability the information was compromised.
The Four Factor Risk Assessment
Section 164.402 requires covered entities to evaluate at least four factors to determine the probability that PHI has been compromised:
| Factor | What It Evaluates |
|---|---|
| Nature and extent of the PHI involved | The types of identifiers included and the likelihood of re-identification, including whether particularly sensitive data such as diagnosis or treatment detail was exposed |
| Unauthorized person who used or received the PHI | Whether the recipient has an independent obligation to protect the information, such as another HIPAA covered entity, which can lower risk |
| Whether the PHI was actually acquired or viewed | Forensic or access-log evidence of whether the information was actually opened or viewed, not just theoretically accessible |
| Extent to which the risk has been mitigated | Steps taken after the incident, such as obtaining assurances of destruction or confirming a device was recovered and wiped |
If, after weighing these factors, the entity concludes there is a low probability the PHI was compromised, the incident does not have to be treated as a reportable breach, but the entity should document that risk assessment and its conclusion, since HHS can request it during an investigation.
The 60 Day Notification Clock
Once a breach is discovered, covered entities must notify affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery, under 45 CFR 164.404. A breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to the covered entity, not the day forensic investigation concludes. This means the clock generally starts earlier than organizations expect, and internal investigation time counts against the 60 day window rather than pausing it.
Business associates that experience a breach have their own notification obligation, and must notify the covered entity without unreasonable delay and no later than 60 days after discovery, under 45 CFR 164.410. The covered entity's own 60 day clock to notify individuals typically still runs from when the covered entity itself discovers the breach, which is generally treated as no later than when the business associate notifies it, so delays passed down the chain do not extend the covered entity's ultimate deadline.
The 500 Individual Threshold
The number of individuals affected changes both the timeline and the audience for notification, under 45 CFR 164.408 for reports to HHS and 45 CFR 164.406 for media notice:
- Breaches affecting 500 or more individuals must be reported to HHS at the same time notice is given to individuals, under 45 CFR 164.408(b). Separately, under 45 CFR 164.406, a breach involving more than 500 residents of a single state or jurisdiction must also be reported to prominent media outlets serving that area.
- Breaches affecting fewer than 500 individuals can be logged internally and reported to HHS collectively, no later than 60 days after the end of the calendar year in which they were discovered.
Both categories still require notifying the affected individuals within the same 60 day window from discovery; the 500 threshold only changes when and how HHS and the media are told, not whether individuals are notified.
The HHS Breach Portal
HHS maintains an online breach reporting portal, commonly referred to informally as the "wall of shame," where covered entities submit required breach reports electronically. Breaches affecting 500 or more individuals are entered into the portal at the time of notification and become part of a public list that HHS maintains of larger breaches under investigation or resolved. Breaches affecting fewer than 500 individuals are also submitted through the same portal, but on the annual, collective basis described above rather than individually at the time of discovery.
Notification by Substitute Method
If a covered entity does not have current contact information for one or more affected individuals, or if the standard written notice is undeliverable, 45 CFR 164.404(d) allows substitute notice. For fewer than 10 individuals with insufficient contact information, substitute notice can be provided through an alternative form of written notice, telephone, or another method reasonably calculated to reach the individual. For 10 or more individuals with insufficient or out-of-date contact information, substitute notice must include either a conspicuous posting on the covered entity's website home page for at least 90 days, or conspicuous notice in major print or broadcast media in the geographic areas where the affected individuals likely reside, along with a toll-free number active for at least 90 days that individuals can call to learn whether their information was involved.
What Individual Notices Must Contain
Under 45 CFR 164.404(c), the notice to affected individuals must be written in plain language and include, at minimum, a brief description of what happened, including the date of the breach and the date of discovery if known; a description of the types of unsecured PHI involved; steps individuals should take to protect themselves; a description of what the covered entity is doing to investigate, mitigate harm, and prevent recurrence; and contact procedures for individuals to ask questions, including a toll-free number, email, website, or postal address.
How This Connects to Text-Based Patient Communication
Text messaging platforms handling PHI are part of the environment covered by the breach notification rule, meaning an impermissible disclosure through a texting channel, such as a message sent to the wrong number containing clinical detail, is evaluated under the same four factor test described above. Building compliant texting workflows in the first place reduces this exposure; a practical starting checklist is in HIPAA SMS compliance checklist.
Organizations should also understand how texting compares to other communication channels in terms of where breach risk tends to concentrate, covered in HIPAA compliant phone services, and how a properly configured platform reduces the likelihood of a reportable event in the first place; see HIPAA compliant text messaging.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
What is the HIPAA Breach Notification Rule?
It is the set of requirements at 45 CFR 164.400 through 164.414 that obligate covered entities and business associates to notify affected individuals, and in some cases HHS and the media, following a breach of unsecured protected health information. It includes a risk assessment process, notification deadlines, and thresholds based on the number of people affected.
How long do you have to report a HIPAA breach?
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach, under 45 CFR 164.404. For breaches affecting 500 or more individuals, HHS must be notified at that same time, and media notice is separately required when more than 500 residents of a single state or jurisdiction are involved.
What is the four factor risk assessment?
It is the analysis required under 45 CFR 164.402 to determine whether an impermissible use or disclosure of PHI is a reportable breach. It weighs the nature and extent of the PHI involved, who received or used it, whether it was actually acquired or viewed, and the extent to which the resulting risk has been mitigated.
What happens when a breach affects 500 or more people?
Under 45 CFR 164.408(b), breaches affecting 500 or more individuals must be reported to HHS at the same time individuals are notified. Under 45 CFR 164.406, a breach involving more than 500 residents of a single state or jurisdiction also requires notice to prominent media outlets serving that area. Breaches affecting fewer than 500 people are logged and reported to HHS annually.
Is encrypted PHI subject to breach notification?
Generally no. PHI that has been rendered unusable, unreadable, or indecipherable using an HHS-specified method, most commonly encryption meeting the applicable standard, is considered "secured" rather than "unsecured," and the breach notification rule applies specifically to unsecured PHI.
What is the HHS breach portal?
It is the online system HHS uses for covered entities to submit required breach reports. Breaches affecting 500 or more individuals are posted there and become part of a public list HHS maintains. Smaller breaches are also reported through the portal, but on an annual, collective basis rather than at the time of discovery.
Does a business associate have its own breach notification duty?
Yes. Under 45 CFR 164.410, a business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days after discovery. The covered entity then remains responsible for notifying affected individuals within its own 60 day window.
What must be included in a breach notification letter to patients?
Under 45 CFR 164.404(c), the notice must be in plain language and include a description of what happened and when, the types of PHI involved, steps individuals should take to protect themselves, what the organization is doing in response, and contact information for questions, including a toll-free number or equivalent.
Reduce breach exposure in patient texting
The best way to manage breach notification obligations is to reduce the chance of an impermissible disclosure in the first place. FRANSiS supports compliance for healthcare texting, with a signed BAA included for covered entities and business associates. Contact us to review your current texting workflow for exposure points.


