Skip to main content
[email protected]
Menu
Language
Appearance

HIPAA Breach Notification Rule: What Arizona Medical Practices Must Do After a Breach

ATAzHeC Technology Council
August 15, 2026
5min read
WhatsAppEmail

A misdirected fax, a stolen laptop, a phishing email that lands in the wrong inbox — for a small Arizona medical practice, any one of these can trigger federal notification obligations under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414). The rule was strengthened by the HITECH Act and applies to every covered entity handling unsecured protected health information (PHI), regardless of practice size. Most practices only encounter it once — during an actual incident, under time pressure — which is exactly when mistakes get made. This guide breaks down who must be notified, how fast, and how the law decides whether an incident even rises to the level of a reportable breach.

What Counts as a "Breach" in the First Place

Not every impermissible use or disclosure of PHI is automatically a breach. Under 45 CFR §164.402, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate, through a documented risk assessment, that there is a low probability the PHI was actually compromised. That distinction matters: it means every incident — from a records clerk emailing the wrong patient to a ransomware event — requires a documented analysis, not a gut-feel judgment call. Skipping that documentation is itself a compliance gap, even if the underlying incident turns out to be low-risk.

Who Must Be Notified, and Within What Timeframe

The Breach Notification Rule creates several separate notification obligations, and small practices often only remember the first one:

RecipientTriggerTimeframe
Affected individualsAny confirmed breach of their unsecured PHIWithout unreasonable delay, no later than 60 calendar days after discovery
HHS Secretary (500+ affected)Breach affects 500 or more individualsWithout unreasonable delay, no later than 60 days after discovery
HHS Secretary (under 500 affected)Smaller breaches, logged and reported togetherNo later than 60 days after the end of the calendar year in which the breach occurred
Prominent media outletsBreach affects 500+ residents of a single state or jurisdictionNo later than 60 days after discovery
The covered entity, from a business associateBreach occurs at or by a business associateWithout unreasonable delay, no later than 60 days after the business associate’s discovery

A detail that trips up many practices: the 60-day clock starts running the moment the incident is discovered, not once an investigation confirms exactly what happened or how many records were involved. Waiting to notify until every detail is nailed down is one of the more common ways a practice turns a manageable incident into a regulatory problem.

The Four-Factor Risk Assessment

When an impermissible disclosure happens, the practice must document a risk assessment covering at least these four factors before it can conclude notification isn’t required:

  1. Nature and extent of the PHI involved. More sensitive data — Social Security numbers, financial details, mental health or HIV-related records — and information that makes re-identification easier both push the risk higher.
  2. Who received or used the information. A disclosure to another authorized person inside the same covered entity, with no further use, generally carries lower risk than a disclosure to an outside party.
  3. Whether the PHI was actually acquired or viewed. A misdirected fax retrieved before it was read is a materially different situation than one that sat in an open mailbox for a week.
  4. How thoroughly the risk was mitigated. Retrieving or deleting the misdirected data, obtaining written assurances it wasn’t used further, disabling a compromised account, or patching the vulnerability that caused the exposure all count toward mitigation.

If, after weighing all four factors, the practice cannot demonstrate a low probability of compromise, the presumption of a reportable breach stands and notification is required. That written risk assessment — not a verbal conclusion from whoever handled the incident — is what a regulator will ask to see first.

Business Associates Complicate the Chain

Most small practices don’t handle billing, IT, or medical records storage entirely in-house — they rely on business associates: a billing service, a managed-IT provider, a cloud EHR vendor, a transcription company. When a breach originates at a business associate rather than the practice itself, the business associate is responsible for notifying the covered entity, and that notification has to happen without unreasonable delay and no later than 60 days after the business associate discovers it. The practice is still ultimately accountable to patients and to HHS — which is why the Business Associate Agreement with every vendor should spell out exactly how fast that upstream notification has to happen, not just that it will.

Preparing Before an Incident, Not During One

The practices that handle a breach cleanly are almost always the ones that had already worked out, in advance, who does what: who documents the four-factor assessment, who drafts patient letters, who has the vendor contacts on file for forensics or legal counsel if the incident is serious enough to need them. That groundwork is also where a documented HIPAA Security Risk Assessment earns its keep — the same risk-assessment discipline required after a breach is far easier to execute quickly when the practice already runs one annually and knows its own systems, vendors, and data flows cold.

This is the kind of connective work AzHeC — the Arizona Health Interoperability Council — exists to support. Arizona’s health-IT landscape has a long history of neutral, statewide coordination rather than any single vendor pushing its own product, and that’s the posture AzHeC continues today: matching Arizona medical practices with vetted vendors for HIPAA Security Risk Assessments, breach-response planning, and the broader compliance and health-IT operations work that sits alongside it. None of this is legal advice, and no practice should treat a written guide as a substitute for counsel once an actual incident is underway — but knowing the rule’s mechanics, and having a qualified vendor relationship already in place, is what turns a 60-day deadline from a scramble into a checklist.

AT

Written by

AzHeC Technology Council

Join Our Community

Connect with like-minded readers, share your thoughts, and engage in meaningful discussions.

Explore More Articles

Discover our extensive library of health research and evidence-based insights.

Comments

0

Sign in to join the discussion

Share your thoughts and engage with the community

No comments yet

Sign in to be the first to comment!