HIPAA Breach Notification Rule

The HIPAA Breach Notification Rule (45 CFR 164.400 through 164.414) sets out what a covered entity or business associate must do after protected health information has been acquired, accessed, used, or disclosed without authorization. It defines when an incident counts as a breach, who must be told, and how quickly. The rule is procedural, and firms usually fail it on timing and documentation rather than on intent.

The Presumption and the Four-Factor Assessment

An impermissible use or disclosure of protected health information is presumed to be a breach. The burden sits with the organization to demonstrate a low probability that the information was compromised, through a documented risk assessment covering four factors:

  • The nature and extent of the information involved, including identifiers and the likelihood of re-identification
  • The unauthorized person who used the information or to whom it was disclosed
  • Whether the information was actually acquired or viewed, as opposed to merely exposed
  • The extent to which the risk has been mitigated

All four must be considered and the conclusion written down. An undocumented determination that an incident was not a breach is indistinguishable, during an investigation, from never having assessed it.

Notification Deadlines and Thresholds

Three separate obligations run on different clocks:

  • Affected individuals — without unreasonable delay and no later than 60 calendar days from discovery of the breach.
  • The Secretary of Health and Human Services — for breaches involving 500 or more individuals, contemporaneously with individual notice and no later than 60 days. For breaches involving fewer than 500, in an annual log submitted within 60 days of the end of the calendar year.
  • Prominent media serving the state or jurisdiction — where a breach affects more than 500 residents of that state or jurisdiction, within the same 60-day window.

Discovery is the trigger, and a breach is treated as discovered on the first day it is known, or would have been known through reasonable diligence. Knowledge of any workforce member other than the person who caused the breach is imputed to the organization.

The Encryption Safe Harbor

The rule applies to unsecured protected health information. Information rendered unusable, unreadable, or indecipherable to unauthorized persons — through encryption meeting the specified standard, or through proper destruction — falls outside the notification obligation entirely.

This is the single highest-leverage control available. A lost laptop holding encrypted data with the key held separately is an incident to document; the same laptop unencrypted is a reportable breach with individual notice, a federal filing, and in larger cases a press notification.

Business Associate Obligations

A business associate must notify the covered entity, without unreasonable delay and no later than 60 days from discovery, and identify each affected individual to the extent known. The covered entity retains the obligation to notify individuals, which is why the timing terms in a business associate agreement matter.

A business associate agreement that simply restates the 60-day statutory limit leaves the covered entity no working time. Agreements drafted with this in mind shorten the inbound notice period substantially, so the covered entity has a usable window rather than a deadline that has already expired.

Where Firms Most Often Fall Short

  • No written four-factor assessment. The call was made informally and never recorded, so there is nothing to produce later.
  • Clock started late. Discovery is dated from escalation to management rather than from when any workforce member knew.
  • No data inventory. Most of the 60 days is spent determining which records were touched and whose information they held.
  • Unencrypted endpoints and backups. The safe harbor is forfeited for want of a control that is now routine.
  • Business associate agreements with statutory-limit notice terms, leaving no margin to act.

Why the HIPAA Breach Notification Rule Matters for Investment & Professional Firms

Many DFW firms encounter this rule without considering themselves healthcare organizations. Law firms handling medical records in litigation, CPA firms serving medical and dental practices, benefits consultants, and advisory firms administering health plan data all take on business associate obligations. The practical requirements — encryption, logging that can answer what was accessed, a data inventory, an incident response plan that has actually been exercised, and business associate agreements with workable notice periods — are the same controls that satisfy Regulation S-P and the FTC Safeguards Rule. DKBinnovative has built these programs for compliance-intensive firms in Frisco, Plano, Irving, and Las Colinas since 2004, with Microsoft 365 and Azure configured so the questions a breach assessment asks can actually be answered from the logs.

Related DKBinnovative Resources

External references: 45 CFR Part 164 Subpart D (Breach Notification) · NIST Cybersecurity Framework

Sales & Support
(888) 352-4832