A misdirected fax, a stolen laptop, a phishing email that lands in the wrong inbox — for a small Arizona medical practice, any one of these can trigger federal notification obligations under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414). The rule was strengthened by the HITECH Act and applies to every covered entity handling unsecured protected health information (PHI), regardless of practice size. Most practices only encounter it once — during an actual incident, under time pressure — which is exactly when mistakes get made. This guide breaks down who must be notified, how fast, and how the law decides whether an incident even rises to the level of a reportable breach.
What Counts as a "Breach" in the First Place
Not every impermissible use or disclosure of PHI is automatically a breach. Under 45 CFR §164.402, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate, through a documented risk assessment, that there is a low probability the PHI was actually compromised. That distinction matters: it means every incident — from a records clerk emailing the wrong patient to a ransomware event — requires a documented analysis, not a gut-feel judgment call. Skipping that documentation is itself a compliance gap, even if the underlying incident turns out to be low-risk.
Who Must Be Notified, and Within What Timeframe
The Breach Notification Rule creates several separate notification obligations, and small practices often only remember the first one:
| Recipient | Trigger | Timeframe |
|---|---|---|
| Affected individuals | Any confirmed breach of their unsecured PHI | Without unreasonable delay, no later than 60 calendar days after discovery |
| HHS Secretary (500+ affected) | Breach affects 500 or more individuals | Without unreasonable delay, no later than 60 days after discovery |
| HHS Secretary (under 500 affected) | Smaller breaches, logged and reported together | No later than 60 days after the end of the calendar year in which the breach occurred |
| Prominent media outlets | Breach affects 500+ residents of a single state or jurisdiction | No later than 60 days after discovery |
| The covered entity, from a business associate | Breach occurs at or by a business associate | Without unreasonable delay, no later than 60 days after the business associate’s discovery |
A detail that trips up many practices: the 60-day clock starts running the moment the incident is discovered, not once an investigation confirms exactly what happened or how many records were involved. Waiting to notify until every detail is nailed down is one of the more common ways a practice turns a manageable incident into a regulatory problem.
The Four-Factor Risk Assessment
When an impermissible disclosure happens, the practice must document a risk assessment covering at least these four factors before it can conclude notification isn’t required:
- Nature and extent of the PHI involved. More sensitive data — Social Security numbers, financial details, mental health or HIV-related records — and information that makes re-identification easier both push the risk higher.
- Who received or used the information. A disclosure to another authorized person inside the same covered entity, with no further use, generally carries lower risk than a disclosure to an outside party.
- Whether the PHI was actually acquired or viewed. A misdirected fax retrieved before it was read is a materially different situation than one that sat in an open mailbox for a week.
- How thoroughly the risk was mitigated. Retrieving or deleting the misdirected data, obtaining written assurances it wasn’t used further, disabling a compromised account, or patching the vulnerability that caused the exposure all count toward mitigation.
If, after weighing all four factors, the practice cannot demonstrate a low probability of compromise, the presumption of a reportable breach stands and notification is required. That written risk assessment — not a verbal conclusion from whoever handled the incident — is what a regulator will ask to see first.
Business Associates Complicate the Chain
Most small practices don’t handle billing, IT, or medical records storage entirely in-house — they rely on business associates: a billing service, a managed-IT provider, a cloud EHR vendor, a transcription company. When a breach originates at a business associate rather than the practice itself, the business associate is responsible for notifying the covered entity, and that notification has to happen without unreasonable delay and no later than 60 days after the business associate discovers it. The practice is still ultimately accountable to patients and to HHS — which is why the Business Associate Agreement with every vendor should spell out exactly how fast that upstream notification has to happen, not just that it will.
Preparing Before an Incident, Not During One
The practices that handle a breach cleanly are almost always the ones that had already worked out, in advance, who does what: who documents the four-factor assessment, who drafts patient letters, who has the vendor contacts on file for forensics or legal counsel if the incident is serious enough to need them. That groundwork is also where a documented HIPAA Security Risk Assessment earns its keep — the same risk-assessment discipline required after a breach is far easier to execute quickly when the practice already runs one annually and knows its own systems, vendors, and data flows cold.
This is the kind of connective work AzHeC — the Arizona Health Interoperability Council — exists to support. Arizona’s health-IT landscape has a long history of neutral, statewide coordination rather than any single vendor pushing its own product, and that’s the posture AzHeC continues today: matching Arizona medical practices with vetted vendors for HIPAA Security Risk Assessments, breach-response planning, and the broader compliance and health-IT operations work that sits alongside it. None of this is legal advice, and no practice should treat a written guide as a substitute for counsel once an actual incident is underway — but knowing the rule’s mechanics, and having a qualified vendor relationship already in place, is what turns a 60-day deadline from a scramble into a checklist.