A HIPAA breach doesn’t start a single countdown — it starts several, and they don’t all run on the same clock. The HIPAA Breach Notification Rule (45 CFR 164.400-414) sets a hard 60-day outer limit for notifying affected individuals, but the size of the breach also determines whether a practice owes notice to the U.S. Department of Health and Human Services (HHS) immediately, to the media, or simply to an internal log that gets reported once a year. Understanding which tier applies — and when the clock actually starts — is the difference between a compliant response and a missed deadline that turns a routine incident into an enforcement action.
The Clock Starts on Discovery, Not Confirmation
The single most misunderstood part of the HIPAA breach notification rule is when the 60-day period actually begins. It is not the day a forensic investigation confirms exactly what happened, and it is not the day legal counsel signs off on a breach determination. The clock starts on the day the breach is known — or reasonably should have been known — to anyone in the organization. A staff member who notices a misdirected fax containing patient records, or an office manager who spots an unfamiliar login on the practice management system, starts the clock the moment that observation is made, whether or not it gets escalated right away. Practices that wait for full certainty before treating an incident as a breach are often already weeks into a deadline they haven’t started tracking.
This is also why an impermissible use or disclosure of protected health information (PHI) is presumed to be a reportable breach by default. The burden is on the practice to demonstrate, through a documented risk assessment, that there is a low probability the PHI was actually compromised. Absent that documentation, the presumption stands and the notification clock is running.
Three Tiers, Three Different Obligations
Once a breach of unsecured PHI is confirmed, the notification requirements branch based entirely on how many individuals were affected. The table below summarizes the three tiers.
| Who Must Be Notified | Trigger | Deadline |
|---|---|---|
| Affected individuals | Any breach of unsecured PHI, regardless of size | Without unreasonable delay, no later than 60 calendar days after discovery |
| HHS Secretary (large breach) | 500 or more individuals affected | Without unreasonable delay, no later than 60 calendar days after discovery |
| Prominent media outlets | 500 or more residents of a single state or jurisdiction affected | Without unreasonable delay, no later than 60 days after discovery, alongside individual notices |
| HHS Secretary (small breach log) | Fewer than 500 individuals affected | Annually, within 60 days after the end of the calendar year in which the breach was discovered |
The individual-notification requirement never changes: every affected person gets a written notice, typically by first-class mail or email if they’ve agreed to electronic notice, describing what happened, what types of information were involved, what they should do to protect themselves, and what the practice is doing in response. What changes above 500 affected individuals is the audience beyond those individuals — HHS gets notified immediately rather than logged for later, and the breach becomes publicly listed on the HHS breach portal. A breach affecting 500 or more residents of a single state also requires proactive outreach to media outlets serving that area, generally in the form of a press release carrying the same core information as the individual notices.
The Annual Reporting Deadline Is a Trap for Small Practices
Most breaches at a small or mid-size medical practice fall under the 500-person threshold — a lost laptop, a billing error that exposes a handful of records, an email sent to the wrong recipient. For these smaller incidents, HIPAA allows the practice to maintain an internal breach log and report the entries to HHS once a year, within 60 days after the end of the calendar year in which each breach was discovered. Breaches discovered during a given calendar year, for example, must be reported by roughly March 1 of the following year.
The trap is procedural, not calendrical. The annual deadline covers reporting to HHS — it does not extend the 60-day deadline for notifying the affected individuals themselves, and each qualifying small breach still has to be logged and reported separately through the OCR electronic breach reporting portal rather than bundled into a single summary entry. Practices that treat "annual reporting" as license to slow-walk the entire response frequently discover, well after the fact, that they blew the individual-notice deadline while waiting for the calendar year to close.
Business Associates Have Their Own 60-Day Clock
When a breach originates with a vendor handling PHI on the practice’s behalf — a billing service, a cloud EHR host, an answering service — that business associate is required to notify the covered entity without unreasonable delay and no later than 60 days from its own discovery of the breach. In practice, this means a practice’s actual window to notify its patients can be compressed if a vendor takes weeks to loop the practice in. Business associate agreements should specify a notification timeline meaningfully shorter than the full 60 days, precisely so the practice retains enough runway to meet its own individual-notification deadline once the vendor’s notice arrives.
Where This Fits Into a Practice’s Broader Compliance Posture
Breach notification is a downstream obligation — it only gets triggered because something upstream, usually a gap identified or missed in a HIPAA Security Risk Assessment, allowed unsecured PHI to be exposed in the first place. Practices that treat notification timelines as their only compliance concern tend to be the same practices without a current risk assessment, a documented incident response plan, or a business associate agreement that actually specifies vendor notification windows. The notification rule is what happens after prevention has already failed; the more durable fix is pairing incident-response readiness with the risk assessment and vendor vetting work that reduces how often the clock starts running in the first place.
Conclusion
The HIPAA breach notification rule doesn’t leave much room for interpretation once a breach is confirmed — the 60-day deadline for individual notice is fixed, the 500-person threshold determines whether HHS and the media get immediate notice or an annual log entry, and business associates carry their own parallel clock. What trips up practices is rarely the rule itself; it’s the discovery-date ambiguity and the false sense of slack the annual-reporting option creates. A practice that documents its risk assessments, pins down vendor notification timelines in writing, and treats the discovery date as day one rather than the day forensics wraps up is the practice that meets every deadline in this framework instead of learning about one of them the hard way.