US Federal Law United States

HIPAA Breach Response Playbook: Clocks, Assessments, Notices

Running a HIPAA breach: the four-factor risk assessment, 60-day individual notice, HHS and media notification, business associate timelines, and the documentation OCR checks.

Regulation

HIPAA Breach Notification Rule, 45 CFR 164.400-414; HITECH Act; state breach notification laws overlay

Max Penalty

Late or absent notification is independently penalized (OCR has settled with entities solely over untimely notice); underlying safeguard failures compound exposure

Enforcing Authority

HHS Office for Civil Rights (OCR); state attorneys general

Official Source

www.hhs.gov

Executive Summary

  • Under 45 CFR 164.402, an impermissible use or disclosure of unsecured PHI is presumed a breach unless a documented four-factor risk assessment demonstrates a low probability that PHI was compromised.
  • Individual notice is due without unreasonable delay and no later than 60 calendar days from discovery; breaches of 500+ individuals also require contemporaneous HHS notice and media notice in affected states, while smaller breaches go to HHS in an annual log.
  • Discovery is imputed: the clock starts when any workforce member (other than the breaching person) knew or should have known, and a business associate's discovery can start the covered entity's clock depending on agency status.
  • Encryption to NIST standards is the safe harbor: properly secured PHI is outside the rule entirely, making pre-breach encryption the single highest-value control.
  • OCR penalizes notification failures independently of the underlying incident, and state AGs plus state breach laws add parallel, sometimes faster, obligations.

Breach response under HIPAA is a documentation race run on someone else’s clock. Discovery is imputed to your most junior employee’s inbox, the 60-day outer limit is the ceiling rather than the target, and every judgment call, the discovery date, the four factors, the individual count, must survive OCR review in writing, months later, with hindsight against you. Teams that pre-build the machinery (assessment template, notice letters, HHS portal access, BAA reporting deadlines mapped) run breaches; teams that improvise get run by them. And the quietest fact in the rule remains the loudest advice: encrypted PHI is not breachable PHI.

TriggerImpermissible use/disclosure of unsecured PHI (presumed breach)
EscapeDocumented 4-factor low-probability assessment
Individuals≤60 days from discovery
HHSContemporaneous (500+) or annual log (<500)
Media500+ per state
Safe harborNIST-standard encryption

Running the playbook

Pre-position the artifacts. Assessment template, notice drafts, HHS portal credentials, media contact plan, and a state-law clock matrix; the compliance roadmap sequences where these fit.

Compress vendor reporting contractually. The regulation gives business associates 60 days; your BAAs should give them days, not weeks, so their delay does not consume your clock.

Close incidents with a written no-breach memo. Every security incident that ends ‘no notification’ needs the four-factor analysis in the file, silence without paper is indistinguishable from concealment.

Feed root cause back into the risk analysis. OCR reads the breach against your risk assessment; a breach through an unassessed vector is the aggravating pattern in current enforcement.

Website trackers on patient portals have driven a wave of breach reports: find out what your pages disclose with a free scan.

Frequently Asked Questions

How does the four-factor risk assessment work?

After an impermissible acquisition, access, use, or disclosure of unsecured PHI, notification is required unless you document a low probability of compromise across all four factors: (1) the nature and extent of the PHI, identifiers and likelihood of re-identification (an SSN or diagnosis weighs heavier than a name alone); (2) the unauthorized person who received or accessed it (a fellow covered entity under HIPAA duties weighs lighter than an unknown attacker); (3) whether PHI was actually acquired or viewed, forensics matters here; (4) mitigation, such as recovered devices or signed attestations of destruction. The assessment is optional: you may skip it and notify. What you may not do is decide 'low risk' without a written analysis, that document is the first thing OCR requests.

What are the exact notification clocks and contents?

Individuals: written notice by first-class mail (or email if agreed) without unreasonable delay, outer limit 60 calendar days from discovery, containing what happened, PHI involved, steps individuals should take, what you are doing, and contact information; substitute notice (website posting or media) applies when contact information is insufficient for 10+ people. HHS: through the portal, contemporaneous with individual notice for 500+ breaches, or within 60 days after calendar year-end for smaller ones. Media: for 500+ residents of a state, notice to prominent media outlets there. Business associates: notify the covered entity without unreasonable delay, outer limit 60 days, though BAAs commonly compress this to 5-10 business days. State laws overlay shorter clocks and AG notices; run both matrices.

When does the clock actually start?

At discovery, which is the first day the breach is known, or by reasonable diligence would have been known, to any workforce member or agent other than the person who committed the breach. This imputed-knowledge standard means a help-desk ticket describing odd mailbox rules, an unexplained EDR alert closed without review, or a patient complaint about a misdirected letter can each start the clock long before leadership hears about the incident. Two operational consequences: train front-line staff to escalate suspected PHI incidents immediately, and document the discovery-date analysis in the breach file, OCR probes it, and 'when the CISO was told' is not the standard.

What does the encryption safe harbor actually require?

The rule applies only to unsecured PHI, PHI not rendered unusable, unreadable, or indecipherable per HHS guidance, which specifies NIST-consistent encryption (for data at rest, consistent with SP 800-111; in transit, TLS/VPN per SP 800-52/77/113) and proper destruction for media. If a stolen laptop's drive was encrypted to standard and the key was not compromised, the loss is not a notifiable breach at all: no assessment, no letters, no HHS entry. This is the strongest ROI argument in the rule, full-disk encryption on portable devices retires the single most common historical breach category (lost and stolen hardware) entirely. Document the encryption state per device class so the safe-harbor claim is provable on the worst day.

What belongs in the breach file OCR will review?

The incident timeline with the discovery-date analysis; forensic findings; the four-factor assessment (or the decision to notify without one); copies of individual, HHS, media, and substitute notices with dates; the affected-individual count methodology; business associate reports and BAA deadline compliance; mitigation and sanctions applied; and the root-cause remediation plan, which OCR reads against your risk analysis to see whether the breached vector was a known, unremediated risk. Retention is six years. OCR has settled over notification timeliness alone (Presence Health, $475,000, for notices sent months late), so the file must prove not just that you notified but when each clock started and ended.

Regulatory Crosswalk

State breach lawsGDPR Article 33NIST SP 800-61

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.