Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Steps That Must Be Taken After a Breach

Understanding HIPAA Breach Notification Requirements

When your organization suffers a HIPAA Breach affecting 500 individuals or more there are numerous steps that must be taken as soon as possible once the breach has been discovered, but no later than 60 calendar days after the discovery of the breach.

TL;DR – HIPAA Breach Notification Steps:

  • Timeline: Must notify within 60 calendar days of breach discovery
  • Definition: Impermissible use/disclosure compromising PHI security or privacy
  • Individual Notice: Written notice by mail or email (if agreed to electronically)
  • Media Notice: Required for breaches affecting 500+ residents in a state
  • HHS Notice: Submit breach report form electronically to HHS Secretary
  • Business Associates: Must notify Covered Entity within 60 days of discovery

What Constitutes a HIPAA Breach

Definition of a Breach: an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of Protected Health Information (PHI). Covered Entities and Business Associates must only provide the required notifications if the breach involved unsecured PHI.

Breach Notification Requirements

Individual Notice

Covered Entities must notify affected individuals following the discovery of a breach of unsecured PHI. Covered Entities must provide this individual notice in written form by first-class mail, or alternatively, by e-mail if the affected individual has agreed to receive such notices electronically. If the Covered Entity has insufficient or out-of-date contact information for 10 or more individuals, the Covered Entity must provide substitute individual notice by either posting the notice on the home page of its web site for at least 90 days or by providing the notice in major print or broadcast media where the affected individuals likely reside.

Media Notice

Covered Entities that experience a breach affecting more than 500 residents of a State or jurisdiction are, in addition to notifying the affected individuals, required to provide notice to prominent media outlets serving the State or jurisdiction. Covered Entities will likely provide this notification in the form of a press release to appropriate media outlets serving the affected area.

Notice to the Secretary

In addition to notifying affected individuals and the media (where appropriate), Covered Entities must notify the Secretary of breaches of unsecured protected health information. Covered entities will notify the Secretary by visiting the HHS web site and filling out and electronically submitting a breach report form.

Notification by a Business Associate

If a breach of unsecured PHI occurs at or by a Business Associate, the Business Associate must notify the Covered Entity following the discovery of the breach. A Business Associate must provide notice to the Covered Entity without unreasonable delay and no later than 60 days from the discovery of the breach.

Submit a Breach Notification to the HHS Secretary

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.