Not every data mishap at a medical practice triggers a legal notification obligation — but figuring out which incidents do, and how fast the clock is running once they do, is where many practices get into trouble. The HIPAA Breach Notification Rule, enforced by the HHS Office for Civil Rights (OCR), sets specific deadlines for notifying patients, the federal government, and sometimes the media after an impermissible use or disclosure of unsecured protected health information (PHI). Understanding the mechanics of that rule — not just that it exists — is what separates a controlled incident response from a compounding compliance failure.
What Counts as a Reportable Breach: The Four-Factor Test
Under the rule, any impermissible use or disclosure of PHI is presumed to be a reportable breach unless the practice can demonstrate a low probability that the information was actually compromised. That demonstration isn't a judgment call — OCR requires a documented risk assessment covering at least four factors:
- The nature and extent of the PHI involved. A misdirected fax containing a patient's name and appointment time carries different risk than one containing diagnosis codes, Social Security numbers, or financial data. The more identifiable and sensitive the information, the higher the risk.
- Who received or used the information. PHI sent to another HIPAA-covered entity or business associate under a signed agreement is lower-risk than PHI sent to an unrelated party with no legal obligation to protect it.
- Whether the PHI was actually acquired or viewed. A laptop that was lost and recovered unopened, with forensic evidence showing no file access, presents a different risk profile than a laptop confirmed to have been accessed.
- The extent to which the risk has been mitigated. Steps like obtaining a signed confidentiality statement from the unintended recipient, remotely wiping a device, or confirming destruction of misdirected records can lower the assessed risk.
Only after working through all four factors — in writing, with a documented conclusion — can a practice determine that an incident falls below the reporting threshold. Skipping this step, or doing it informally, is itself a common audit finding.
The 60-Day Clock: When It Starts and What Triggers It
Once an incident is determined to be a reportable breach, the notification clock does not start when the compliance officer finishes the paperwork — it starts on the date the breach is known, or reasonably should have been known, by any workforce member or agent of the practice. That distinction matters: if a front-desk employee notices a problem on a Monday but doesn't escalate it until Friday, the clock still started Monday. "We didn't have all the facts yet" is explicitly not an acceptable reason to delay the initial notification under OCR guidance.
From that trigger date, covered entities generally have up to 60 calendar days to complete notification — but the rule's actual standard is "without unreasonable delay," and 60 days is a ceiling, not a target. A practice that sits on a known breach for 55 days while a workable notification could have gone out in 10 has still failed the "without unreasonable delay" standard even though it beat the deadline.
Who Must Be Notified — and It Depends on Scale
The notification obligations scale with how many individuals were affected, which is the detail most practices get wrong on their first incident:
| Breach affecting fewer than 500 individuals | Breach affecting 500 or more individuals | |
|---|---|---|
| Affected individuals | Written notice within 60 days of discovery | Written notice within 60 days of discovery |
| HHS notification | Logged and submitted annually, no later than 60 days after the end of the calendar year in which the breach was discovered | Submitted within 60 days of discovery — posted to HHS's public breach portal |
| Media notification | Not required | Required if the breach affects more than 500 residents of a single state or jurisdiction |
The 500-person threshold isn't just a paperwork distinction. Breaches that clear it are posted to HHS's public breach-reporting portal — commonly referred to as the "Wall of Shame" — where they remain visible to patients, competitors, and plaintiffs' attorneys alike. A practice that stays below 500 still has to report, just on a delayed, batched annual basis rather than immediately and publicly.
Substitute notice rules add another wrinkle: if a practice can't reach 10 or more affected individuals through the contact information on file, it must post a conspicuous notice on its website or through a major media outlet, along with a toll-free number kept active for at least 90 days. Practices that haven't kept patient contact information current often discover this requirement only after they need to use it.
Why This Belongs in Incident Response Planning, Not Just a Binder
The four-factor test and the notification timeline both assume a practice already has a way to detect an incident, assign someone to run the risk assessment, and produce a defensible written record — all before day 60 arrives. In practice, that means an incident response plan needs a named point of contact, a template for the risk-assessment documentation, and pre-identified resources for the parts a small practice usually can't handle alone: forensic review of what was actually accessed, drafting notification letters that meet the content requirements, and in larger incidents, coordinating with legal counsel or a breach-response vendor before the public HHS filing goes in.
This is squarely the kind of connection that a neutral, statewide health-IT resource like the Arizona Health Interoperability Council exists to make — matching Arizona practices with qualified vendors for incident response support, documentation review, and the broader security groundwork (like a current risk assessment) that makes a fast, defensible response possible in the first place. None of this substitutes for legal advice on a specific incident, but knowing the mechanics of the rule before an incident happens is what keeps a practice from improvising under deadline pressure.
The Bottom Line
The HIPAA Breach Notification Rule isn't a single deadline — it's a chain of decisions: whether the four-factor test rebuts the presumption of breach, when the clock actually started, how many individuals are affected, and which combination of individual, HHS, and media notifications that scale requires. Practices that treat the risk assessment as a genuine documented process, rather than an afterthought, are the ones that meet the "without unreasonable delay" standard instead of merely beating the 60-day ceiling.