2.4 Responding to Unauthorized Access: Breach Notification Duties
Key Takeaways
HIPAA requires notice to affected individuals without unreasonable delay and no later than 60 calendar days after a breach of unsecured PHI is discovered (45 CFR § 164.404).
California Civil Code § 1798.82, as amended effective January 1, 2026, requires breach notices within 30 calendar days of discovery, subject to law-enforcement and scoping delays.
A breach affecting 500 or more individuals must be reported to HHS at the same time as individual notice under 45 CFR § 164.408.
A breach involving more than 500 residents of one state requires notice to prominent media outlets under 45 CFR § 164.406.
A California breach notice sent to more than 500 residents requires a sample copy to the Attorney General within 15 days under Civil Code § 1798.82(f).
Why this is a separate task
The outline gives unauthorized access its own task (T104) with two knowledge statements: the obligation to inform patients (K1041) and what the notice must contain (K1042). Common dental scenarios include a stolen laptop with the schedule on it, a phishing email that exposes a staff member's inbox, ransomware on the practice management server, a front-desk worker browsing a celebrity's chart, and records mailed to the wrong patient.
Step 1: Is it a breach?
Under HIPAA, a breach is an acquisition, access, use, or disclosure of PHI that the Privacy Rule does not permit and that compromises its security or privacy. An impermissible use is presumed to be a breach unless the office documents a low probability of compromise after considering four factors:
- The nature and extent of the PHI, including identifiers and sensitivity.
- Who received or used it.
- Whether it was actually acquired or viewed.
- How far the risk was mitigated, for example by getting written assurance of destruction.
Only unsecured PHI triggers notification. Data encrypted to HHS guidance, with the key not compromised, is not "unsecured." That is the practical reason to encrypt every laptop and backup drive.
HIPAA also excludes a few narrow situations, such as an unintentional access by a workforce member acting in good faith within their job that is not further disclosed.
Step 2: The deadlines
| Who to notify | HIPAA rule | California rule |
|---|---|---|
| Affected patients | Without unreasonable delay, no later than 60 calendar days after discovery (45 CFR § 164.404) | Within 30 calendar days of discovery or notification, unless law enforcement asks for a delay or time is needed to determine the scope and restore the system (Civil Code § 1798.82(a)(2), effective January 1, 2026) |
| HHS | 500 or more individuals: at the same time as individual notice. Fewer than 500: keep a log and report within 60 days after the end of the calendar year (45 CFR § 164.408) | — |
| Media | More than 500 residents of one state or jurisdiction: prominent media outlets, within 60 days (45 CFR § 164.406) | — |
| Attorney General | — | Notice to more than 500 California residents: submit a sample copy within 15 calendar days of notifying them (§ 1798.82(f)) |
A breach counts as discovered on the first day it is known to anyone in the workforce other than the person who caused it, or would have been known with reasonable diligence. The clock does not wait for the dentist to hear about it. When state and federal deadlines differ, meet the shorter one.
Step 3: What the notice must say (K1042)
HIPAA content (45 CFR § 164.404(c)), in plain language:
- A brief description of what happened, including the date of the breach and the date of discovery, if known.
- The types of unsecured PHI involved, such as name, Social Security number, date of birth, address, diagnosis, or account number.
- Steps individuals should take to protect themselves.
- What the office is doing to investigate, reduce harm, and prevent recurrence.
- Contact information, including a toll-free number, email address, website, or postal address.
California format (§ 1798.82(d)): title the notice "Notice of Data Breach," use the headings What Happened?, What Information Was Involved?, What We Are Doing, What You Can Do, and For More Information, and use at least 10-point type. It must list the types of personal information, the date or estimated date of the breach, whether notice was delayed for law enforcement, and credit bureau contacts if Social Security, driver's license, or state ID numbers were exposed. If the office was the source of a breach that exposed those identifiers, the notice must include an offer of appropriate identity-theft prevention and mitigation services at no cost for at least 12 months. A HIPAA-covered entity that fully follows the HITECH content rules is deemed to meet California's content requirement, but not its other duties.
Individual notice goes by first-class mail, or by email if the patient agreed to electronic notice. Substitute notice is used when contact information is out of date.
Step 4: Internal follow-through
- Contain the incident: disable accounts, retrieve misdirected mail, and change passwords.
- Document the risk assessment, even when you conclude no notice is required.
- Sanction workforce members who snooped, under the office's written policy.
- Require business associates to report breaches to the office. California requires a business that maintains data it does not own to notify the owner immediately (§ 1798.82(b)).
Note
The ethical duty runs in parallel. The ADA Code's principle of veracity and the duty to protect confidentiality both point toward prompt, honest disclosure, not toward hoping nobody notices.
A dental office's unencrypted laptop containing 620 California patients' names, birth dates, and treatment notes is stolen from an employee's car. Which combination of notices is required?
Notices to the affected patients only, within 60 days
Notices to the affected patients, HHS at the same time as patient notice, prominent state media, and a sample copy to the California Attorney General
A log entry reported to HHS after the end of the calendar year, and no patient notice
No notices, because the thief probably wanted the hardware rather than the data
A receptionist finds out on June 1 that a coworker has been looking at patient charts out of curiosity. The dentist learns about it on June 20. From which date does the breach-notification clock run?
June 20, when the dentist learned of it
The date the office finishes its internal investigation
June 1, when a workforce member other than the person responsible knew of it
The date the office decides notification is required
Which element must a California breach notice under Civil Code § 1798.82 include?
The title "Notice of Data Breach" with the required headings, including what happened and what information was involved
The name of the employee responsible for the breach
A statement that the office is not liable for any resulting harm
The patients' full treatment plans so they can see what was exposed
Sections you finish are checked off in the contents.