{"@context":"https://schema.org","@type":"Article","headline":"HIPAA Breach Notification Rule","description":"Learn how ABA practices classify suspected HIPAA breaches, document four-factor risk, identify discovery, and track individual, HHS, media, and vendor notices.","url":"https://finnihealth.com/resources/glossary/hipaa-breach-notification-rule","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"HIPAA Breach Notification Rule","item":"https://finnihealth.com/resources/glossary/hipaa-breach-notification-rule"}]}}
Glossary term

HIPAA Breach Notification Rule

Learn how ABA practices classify suspected HIPAA breaches, document four-factor risk, identify discovery, and track individual, HHS, media, and vendor notices.

6
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
ยท View sources
Also called

Breach Notification Rule HIPAA breach rule

What is HIPAA Breach Notification Rule, and what should an ABA practice owner know before applying it? The HIPAA Breach Notification Rule requires specified notices after a breach of unsecured protected health information (PHI). An ABA owner should classify incidents promptly, preserve evidence, identify discovery, evaluate exceptions or four-factor risk, document decisions, and track separate federal, state, contract, and business-associate deadlines.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

The rule starts with a breach of unsecured PHI

The HHS Breach Notification Rule overview says HIPAA covered entities and business associates must provide specified notification following a breach of unsecured PHI. First determine the practice's HIPAA role and whether the information is PHI held in that regulated capacity.

Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable through a technology or method specified by HHS. The HHS guidance identifies qualifying encryption and destruction methods. Encryption status, implementation, and whether a key was compromised matter. This notification boundary does not replace broader Privacy and Security Rule duties.

An incident is classified before notice is chosen

Under 45 CFR 164.402, an acquisition, access, use, or disclosure of PHI that the Privacy Rule does not permit is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that PHI was compromised using at least four factors:

  1. the nature and extent of the PHI, including identifiers and reidentification likelihood.
  2. the unauthorized person who used the PHI or received the disclosure.
  3. whether the PHI was actually acquired or viewed.
  4. the extent to which risk to the PHI was mitigated.

The definition also contains three narrow exceptions: certain good-faith, in-scope workforce access with no further impermissible use; certain inadvertent disclosures between authorized people at the same regulated organization or organized health care arrangement; and a good-faith belief that the unauthorized recipient could not reasonably retain the information.

Record the permitted-use analysis, any exception, every factor considered, evidence, reviewer, conclusion, and approval. A regulated entity may instead proceed with notification. A security alert, documentation error, wrong output, or impermissible disclosure is not automatically a reportable breach.

Discovery starts clocks before the investigation ends

45 CFR 164.404 treats a breach as discovered on the first day it is known, or by reasonable diligence would have been known, to the covered entity. Knowledge of workforce members or agents is attributed as the regulation specifies, excluding the person committing the breach. Record the event date and discovery date separately.

Recipient or actionHIPAA timing after discovery
Affected individualsWithout unreasonable delay and no later than 60 calendar days
HHS Secretary, 500 or more affected individualsWithout unreasonable delay and no later than 60 calendar days
HHS Secretary, fewer than 500 affected individualsLog each breach and report within 60 days after the end of the calendar year in which it was discovered; earlier reporting is allowed
Media, more than 500 residents of one state or jurisdictionWithout unreasonable delay and no later than 60 calendar days
Business associate to covered entityWithout unreasonable delay and no later than 60 calendar days

These are outer limits, not waiting periods. 45 CFR 164.406 governs media notice, 45 CFR 164.408 governs notice to HHS, and 45 CFR 164.410 governs business-associate notice. State, payer, licensing, insurance, and contract clocks may be shorter. Apply any law-enforcement delay under its specific rule.

Notices need defined content and recipients

Individual notice generally describes what happened, breach and discovery dates if known, types of PHI, protective steps, the entity's investigation and mitigation, and contact methods. The regulation also addresses written delivery and substitute notice when contact information is insufficient or outdated.

A covered entity remains responsible for required individual notice, although it may delegate delivery to a business associate. A business associate must provide the covered entity, to the extent possible, affected identities and available information needed for notice. Contractual allocation should preserve each party's legal duties and use a faster operational escalation than the federal outer limit.

The current HHS reporting page requires a separate Secretary notice for each breach incident. It distinguishes the 500-or-more and fewer-than-500 routes and permits later addenda when information changes.

Use one governed response record

Create an event record with detection, discovery, event period, systems, people, information types, security status, recipients, acquisition evidence, mitigation, affected-person method, decision owner, counsel route, deadlines, notices, corrective actions, and closure evidence.

A practical sequence is:

  1. protect safety, contain exposure, preserve logs, and keep the original evidence.
  2. determine entity and business-associate roles plus every applicable source.
  3. classify permission, unsecured PHI, exceptions, and compromise risk.
  4. identify affected individuals using a reproducible method and record uncertainty.
  5. choose and approve each notice path, content, delivery method, and deadline.
  6. validate delivery, submit required reports, track addenda, and test corrective action.

45 CFR 164.414 places the burden on the regulated entity to show required notices were made or why notification was unnecessary. Preserve that evidence and the applicable policies, training, and sanctions records.

A fictional disclosure keeps units separate

On June 2, a fictional ABA practice learns that an unencrypted spreadsheet was sent to the wrong vendor on May 30. It contains PHI for 14 clients. The vendor opened the attachment, reports no onward sharing, and confirms deletion on June 2.

The practice records June 2 as the discovery date and treats this as one event affecting 14 known individuals, not 14 incidents. It documents the PHI involved, recipient, actual acquisition, and mitigation. Deletion helps the fourth factor; it does not decide the assessment alone.

Identity mapping is 14 of 14, or 100%. Current contact information is verified for 13, so contact readiness is 13 of 14, or 92.9%. If the qualified decision owner cannot support a low-probability conclusion or elects to notify, the practice tracks 14 individual notice records and one fewer-than-500 HHS incident report. It separately checks state and contract duties.

Measure timeliness without hiding open events

Useful measures include reports classified by target divided by reports due; affected identities resolved divided by identities in the current impact estimate; individual notices delivered by target divided by notices due; HHS reports submitted by target divided by breach incidents due; and corrective actions validated by due date divided by actions due.

Define discovery, due date, event unit, affected-person method, exclusions, unresolved population, source, and owner. Report open events and oldest age. A low breach count can reflect strong controls, incomplete reporting, unresolved classifications, or a different exposure level, so pair counts with reporting and review evidence.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni