What is HIPAA Breach Notification Rule, and what should an ABA practice owner know before applying it? The HIPAA Breach Notification Rule requires specified notices after a breach of unsecured protected health information (PHI). An ABA owner should classify incidents promptly, preserve evidence, identify discovery, evaluate exceptions or four-factor risk, document decisions, and track separate federal, state, contract, and business-associate deadlines.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
The rule starts with a breach of unsecured PHI
The HHS Breach Notification Rule overview says HIPAA covered entities and business associates must provide specified notification following a breach of unsecured PHI. First determine the practice's HIPAA role and whether the information is PHI held in that regulated capacity.
Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable through a technology or method specified by HHS. The HHS guidance identifies qualifying encryption and destruction methods. Encryption status, implementation, and whether a key was compromised matter. This notification boundary does not replace broader Privacy and Security Rule duties.
An incident is classified before notice is chosen
Under 45 CFR 164.402, an acquisition, access, use, or disclosure of PHI that the Privacy Rule does not permit is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that PHI was compromised using at least four factors:
- the nature and extent of the PHI, including identifiers and reidentification likelihood.
- the unauthorized person who used the PHI or received the disclosure.
- whether the PHI was actually acquired or viewed.
- the extent to which risk to the PHI was mitigated.
The definition also contains three narrow exceptions: certain good-faith, in-scope workforce access with no further impermissible use; certain inadvertent disclosures between authorized people at the same regulated organization or organized health care arrangement; and a good-faith belief that the unauthorized recipient could not reasonably retain the information.
Record the permitted-use analysis, any exception, every factor considered, evidence, reviewer, conclusion, and approval. A regulated entity may instead proceed with notification. A security alert, documentation error, wrong output, or impermissible disclosure is not automatically a reportable breach.
Discovery starts clocks before the investigation ends
45 CFR 164.404 treats a breach as discovered on the first day it is known, or by reasonable diligence would have been known, to the covered entity. Knowledge of workforce members or agents is attributed as the regulation specifies, excluding the person committing the breach. Record the event date and discovery date separately.
| Recipient or action | HIPAA timing after discovery |
|---|---|
| Affected individuals | Without unreasonable delay and no later than 60 calendar days |
| HHS Secretary, 500 or more affected individuals | Without unreasonable delay and no later than 60 calendar days |
| HHS Secretary, fewer than 500 affected individuals | Log each breach and report within 60 days after the end of the calendar year in which it was discovered; earlier reporting is allowed |
| Media, more than 500 residents of one state or jurisdiction | Without unreasonable delay and no later than 60 calendar days |
| Business associate to covered entity | Without unreasonable delay and no later than 60 calendar days |
These are outer limits, not waiting periods. 45 CFR 164.406 governs media notice, 45 CFR 164.408 governs notice to HHS, and 45 CFR 164.410 governs business-associate notice. State, payer, licensing, insurance, and contract clocks may be shorter. Apply any law-enforcement delay under its specific rule.
Notices need defined content and recipients
Individual notice generally describes what happened, breach and discovery dates if known, types of PHI, protective steps, the entity's investigation and mitigation, and contact methods. The regulation also addresses written delivery and substitute notice when contact information is insufficient or outdated.
A covered entity remains responsible for required individual notice, although it may delegate delivery to a business associate. A business associate must provide the covered entity, to the extent possible, affected identities and available information needed for notice. Contractual allocation should preserve each party's legal duties and use a faster operational escalation than the federal outer limit.
The current HHS reporting page requires a separate Secretary notice for each breach incident. It distinguishes the 500-or-more and fewer-than-500 routes and permits later addenda when information changes.
Use one governed response record
Create an event record with detection, discovery, event period, systems, people, information types, security status, recipients, acquisition evidence, mitigation, affected-person method, decision owner, counsel route, deadlines, notices, corrective actions, and closure evidence.
A practical sequence is:
- protect safety, contain exposure, preserve logs, and keep the original evidence.
- determine entity and business-associate roles plus every applicable source.
- classify permission, unsecured PHI, exceptions, and compromise risk.
- identify affected individuals using a reproducible method and record uncertainty.
- choose and approve each notice path, content, delivery method, and deadline.
- validate delivery, submit required reports, track addenda, and test corrective action.
45 CFR 164.414 places the burden on the regulated entity to show required notices were made or why notification was unnecessary. Preserve that evidence and the applicable policies, training, and sanctions records.
A fictional disclosure keeps units separate
On June 2, a fictional ABA practice learns that an unencrypted spreadsheet was sent to the wrong vendor on May 30. It contains PHI for 14 clients. The vendor opened the attachment, reports no onward sharing, and confirms deletion on June 2.
The practice records June 2 as the discovery date and treats this as one event affecting 14 known individuals, not 14 incidents. It documents the PHI involved, recipient, actual acquisition, and mitigation. Deletion helps the fourth factor; it does not decide the assessment alone.
Identity mapping is 14 of 14, or 100%. Current contact information is verified for 13, so contact readiness is 13 of 14, or 92.9%. If the qualified decision owner cannot support a low-probability conclusion or elects to notify, the practice tracks 14 individual notice records and one fewer-than-500 HHS incident report. It separately checks state and contract duties.
Measure timeliness without hiding open events
Useful measures include reports classified by target divided by reports due; affected identities resolved divided by identities in the current impact estimate; individual notices delivered by target divided by notices due; HHS reports submitted by target divided by breach incidents due; and corrective actions validated by due date divided by actions due.
Define discovery, due date, event unit, affected-person method, exclusions, unresolved population, source, and owner. Report open events and oldest age. A low breach count can reflect strong controls, incomplete reporting, unresolved classifications, or a different exposure level, so pair counts with reporting and review evidence.
Related terms
Sources
- U.S. Department of Health and Human Services, Breach Notification Rule
- Electronic Code of Federal Regulations, 45 CFR 164.402, Definitions
- Electronic Code of Federal Regulations, 45 CFR 164.404, Notification to Individuals
- Electronic Code of Federal Regulations, 45 CFR 164.406, Notification to the Media
- Electronic Code of Federal Regulations, 45 CFR 164.408, Notification to the Secretary
- Electronic Code of Federal Regulations, 45 CFR 164.410, Notification by a Business Associate
- Electronic Code of Federal Regulations, 45 CFR 164.414, Administrative Requirements and Burden of Proof
- U.S. Department of Health and Human Services, Guidance to Render Unsecured PHI Unusable, Unreadable, or Indecipherable
- U.S. Department of Health and Human Services, Submitting Notice of a Breach to the Secretary
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni