2.4 Responding to Unauthorized Access: Breach Notification Duties

Key Takeaways

  • HIPAA requires notice to affected individuals without unreasonable delay and no later than 60 calendar days after a breach of unsecured PHI is discovered (45 CFR § 164.404).

  • California Civil Code § 1798.82, as amended effective January 1, 2026, requires breach notices within 30 calendar days of discovery, subject to law-enforcement and scoping delays.

  • A breach affecting 500 or more individuals must be reported to HHS at the same time as individual notice under 45 CFR § 164.408.

  • A breach involving more than 500 residents of one state requires notice to prominent media outlets under 45 CFR § 164.406.

  • A California breach notice sent to more than 500 residents requires a sample copy to the Attorney General within 15 days under Civil Code § 1798.82(f).

Last updated: September 2026

Why this is a separate task

The outline gives unauthorized access its own task (T104) with two knowledge statements: the obligation to inform patients (K1041) and what the notice must contain (K1042). Common dental scenarios include a stolen laptop with the schedule on it, a phishing email that exposes a staff member's inbox, ransomware on the practice management server, a front-desk worker browsing a celebrity's chart, and records mailed to the wrong patient.

Step 1: Is it a breach?

Under HIPAA, a breach is an acquisition, access, use, or disclosure of PHI that the Privacy Rule does not permit and that compromises its security or privacy. An impermissible use is presumed to be a breach unless the office documents a low probability of compromise after considering four factors:

  1. The nature and extent of the PHI, including identifiers and sensitivity.
  2. Who received or used it.
  3. Whether it was actually acquired or viewed.
  4. How far the risk was mitigated, for example by getting written assurance of destruction.

Only unsecured PHI triggers notification. Data encrypted to HHS guidance, with the key not compromised, is not "unsecured." That is the practical reason to encrypt every laptop and backup drive.

HIPAA also excludes a few narrow situations, such as an unintentional access by a workforce member acting in good faith within their job that is not further disclosed.

Step 2: The deadlines

Who to notifyHIPAA ruleCalifornia rule
Affected patientsWithout unreasonable delay, no later than 60 calendar days after discovery (45 CFR § 164.404)Within 30 calendar days of discovery or notification, unless law enforcement asks for a delay or time is needed to determine the scope and restore the system (Civil Code § 1798.82(a)(2), effective January 1, 2026)
HHS500 or more individuals: at the same time as individual notice. Fewer than 500: keep a log and report within 60 days after the end of the calendar year (45 CFR § 164.408)—
MediaMore than 500 residents of one state or jurisdiction: prominent media outlets, within 60 days (45 CFR § 164.406)—
Attorney General—Notice to more than 500 California residents: submit a sample copy within 15 calendar days of notifying them (§ 1798.82(f))

A breach counts as discovered on the first day it is known to anyone in the workforce other than the person who caused it, or would have been known with reasonable diligence. The clock does not wait for the dentist to hear about it. When state and federal deadlines differ, meet the shorter one.

Step 3: What the notice must say (K1042)

HIPAA content (45 CFR § 164.404(c)), in plain language:

  • A brief description of what happened, including the date of the breach and the date of discovery, if known.
  • The types of unsecured PHI involved, such as name, Social Security number, date of birth, address, diagnosis, or account number.
  • Steps individuals should take to protect themselves.
  • What the office is doing to investigate, reduce harm, and prevent recurrence.
  • Contact information, including a toll-free number, email address, website, or postal address.

California format (§ 1798.82(d)): title the notice "Notice of Data Breach," use the headings What Happened?, What Information Was Involved?, What We Are Doing, What You Can Do, and For More Information, and use at least 10-point type. It must list the types of personal information, the date or estimated date of the breach, whether notice was delayed for law enforcement, and credit bureau contacts if Social Security, driver's license, or state ID numbers were exposed. If the office was the source of a breach that exposed those identifiers, the notice must include an offer of appropriate identity-theft prevention and mitigation services at no cost for at least 12 months. A HIPAA-covered entity that fully follows the HITECH content rules is deemed to meet California's content requirement, but not its other duties.

Individual notice goes by first-class mail, or by email if the patient agreed to electronic notice. Substitute notice is used when contact information is out of date.

Step 4: Internal follow-through

  • Contain the incident: disable accounts, retrieve misdirected mail, and change passwords.
  • Document the risk assessment, even when you conclude no notice is required.
  • Sanction workforce members who snooped, under the office's written policy.
  • Require business associates to report breaches to the office. California requires a business that maintains data it does not own to notify the owner immediately (§ 1798.82(b)).

Note

The ethical duty runs in parallel. The ADA Code's principle of veracity and the duty to protect confidentiality both point toward prompt, honest disclosure, not toward hoping nobody notices.

Test Your Knowledge

A dental office's unencrypted laptop containing 620 California patients' names, birth dates, and treatment notes is stolen from an employee's car. Which combination of notices is required?

A

Notices to the affected patients only, within 60 days

B

Notices to the affected patients, HHS at the same time as patient notice, prominent state media, and a sample copy to the California Attorney General

C

A log entry reported to HHS after the end of the calendar year, and no patient notice

D

No notices, because the thief probably wanted the hardware rather than the data

Test Your Knowledge

A receptionist finds out on June 1 that a coworker has been looking at patient charts out of curiosity. The dentist learns about it on June 20. From which date does the breach-notification clock run?

A

June 20, when the dentist learned of it

B

The date the office finishes its internal investigation

C

June 1, when a workforce member other than the person responsible knew of it

D

The date the office decides notification is required

Test Your Knowledge

Which element must a California breach notice under Civil Code § 1798.82 include?

A

The title "Notice of Data Breach" with the required headings, including what happened and what information was involved

B

The name of the employee responsible for the breach

C

A statement that the office is not liable for any resulting harm

D

The patients' full treatment plans so they can see what was exposed

Sections you finish are checked off in the contents.