9.3 Mandatory Breach Notification Timelines, HHS Reporting & Media Notices
Key Takeaways
- Individual breach notification under 45 CFR § 164.404 must be executed without unreasonable delay and in no case later than 60 calendar days from the date of discovery.
- The statutory 'Date of Discovery' is triggered on the first day the incident is known (or through reasonable diligence would have been known) to ANY employee or agent of the entity, not when the Privacy Officer is briefed.
- Breaches affecting 500 or more individuals require simultaneous notification to HHS OCR and prominent media outlets in the relevant jurisdiction within 60 calendar days of discovery.
- Breaches affecting fewer than 500 individuals must be reported electronically to the HHS OCR portal within 60 calendar days following the close of the calendar year (March 1 / Feb 29).
- Business Associates must notify the Covered Entity of a breach without unreasonable delay and no later than 60 calendar days from discovery under § 164.410, though BAAs frequently negotiate shorter 24 to 72-hour reporting windows.
Mandatory Breach Notification Timelines, HHS Reporting & Media Notices
Once a covered entity or business associate determines that an impermissible acquisition, access, use, or disclosure of unsecured Protected Health Information (PHI) constitutes a breach—either because the presumption of breach could not be rebutted or because a four-factor risk assessment demonstrated a compromise of the data—the organization must execute the formal notification mandates established under 45 CFR Part 164, Subpart D.
The Breach Notification Rule establishes rigid, non-negotiable statutory timelines, mandatory content specifications, public media notice triggers, and federal electronic reporting protocols. Compliance officers must navigate these overlapping requirements with precision, as administrative delays or defective notices represent independent violations subject to severe Civil Monetary Penalties.
1. Statutory Timing and the Legal Definition of "Date of Discovery"
The central compliance benchmark governing all breach notification obligations is the Date of Discovery. Under 45 CFR § 164.404(a)(2), a breach is treated as discovered:
"As of the first day on which such breach is known to the covered entity (including any person, other than the person committing the breach, who is an employee, officer, or other agent of the covered entity), or by exercising reasonable diligence would have been known to the covered entity."
+-----------------------------------------------------------------------------+
| THE 60-CALENDAR-DAY STATUTORY NOTIFICATION TIMELINE |
| |
| [BREACH OCCURS] |
| (e.g., Unencrypted laptop stolen from employee vehicle on Jan 1) |
| | |
| v |
| [DATE OF DISCOVERY (CLOCK STARTS)] |
| (e.g., Employee reports theft to IT helpdesk on Jan 3) |
| *Note: Clock starts Jan 3, NOT when Privacy Officer is notified on Jan 15!|
| | |
| +----------------------------------------------------------------+ |
| | | |
| v v |
| [INDIVIDUAL NOTIFICATIONS] [HHS OCR REPORTING] |
| • Written notice via 1st Class Mail • >= 500: Within 60 Cal. |
| • "Without unreasonable delay" Days (with Indiv. Notice) |
| • NO LATER than 60 CALENDAR DAYS • < 500: Within 60 Days of |
| from Date of Discovery Calendar Year End |
| | |
| v |
| [MEDIA NOTIFICATION (If MORE THAN 500 residents of a single State/Jurisdiction)] |
| • Press release to prominent media outlets within 60 Calendar Days |
+-----------------------------------------------------------------------------+
[!WARNING] The "Reasonable Diligence" and Agency Trap: Under federal law, notice to any employee or agent (other than the wrongdoer) constitutes legal notice to the covered entity. If an employee reports a phishing incident to the IT helpdesk on March 1, but the IT department does not alert the Privacy Officer until April 15, the 60-calendar-day statutory clock began on March 1. Waiting 60 days from April 15 results in an immediate violation of federal law for untimely notice.
2. Individual Breach Notification (§ 164.404) & Mandatory Notice Content
Under 45 CFR § 164.404, covered entities must notify each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach.
A. Delivery Methods
- Written Notice via First-Class Mail: Must be sent to the individual's last known home address.
- Electronic Notice via Email: Permissible only if the individual has previously agreed to receive electronic notices and has not withdrawn that agreement.
- Deceased Individuals (§ 164.404(d)(1)): If the covered entity knows the individual is deceased, written notice must be sent to the next of kin or personal representative if the address is known.
B. Mandatory Elements of the Individual Notice Letter (§ 164.404(c))
Federal regulations dictate that the breach notification letter must be written in plain language and contain five mandatory core components:
+-----------------------------------------------------------------------------+
| 5 MANDATORY ELEMENTS OF INDIVIDUAL BREACH NOTICE |
| [45 CFR § 164.404(c)] |
| |
| 1. BRIEF DESCRIPTION OF THE INCIDENT |
| - What happened, including the date of the breach and date of discovery|
| |
| 2. DESCRIPTION OF TYPES OF PHI INVOLVED |
| - Specific data elements exposed (e.g., full name, SSN, DOB, home |
| address, diagnosis codes, clinical notes, financial/claims data) |
| |
| 3. STEPS INDIVIDUALS SHOULD TAKE TO PROTECT THEMSELVES |
| - Mitigation advice (e.g., placing fraud alerts, credit monitoring, |
| monitoring Explanation of Benefits (EOB), changing passwords) |
| |
| 4. COVERED ENTITY'S INVESTIGATION & REMEDIATION ACTIONS |
| - What the entity is doing to investigate, mitigate harm, and prevent |
| future occurrences (e.g., enhanced encryption, policy retraining) |
| |
| 5. CONTACT PROCEDURES FOR INDIVIDUAL INQUIRIES |
| - Toll-free telephone number, email address, website, or postal address|
| where individuals can obtain additional information |
+-----------------------------------------------------------------------------+
3. Substitute Notice Procedures (§ 164.404(d)(2))
When a covered entity possesses insufficient or out-of-date contact information for affected individuals, it must provide substitute notice based on defined threshold numbers:
+-----------------------------------------------------------------------------+
| SUBSTITUTE NOTICE THRESHOLDS & WORKFLOWS |
| [45 CFR § 164.404(d)(2)] |
| |
| +------------------------------------+ +----------------------------+ |
| | FEWER THAN 10 INDIVIDUALS | | 10 OR MORE INDIVIDUALS | |
| | [<10 Out-of-Date Addresses] | | [>=10 Out-of-Date Addresses| |
| +------------------------------------+ +----------------------------+ |
| | • Alternative written notice, | | • Conspicuous 90-DAY notice| |
| | telephone call, secure email, or | | posted on WEBSITE HOME- | |
| | other direct communication. | | PAGE, OR major print/TV. | |
| | • Can be individual outreach. | | • Must include active | |
| | | | TOLL-FREE PHONE NUMBER | |
| | | | active for >= 90 days. | |
| +------------------------------------+ +----------------------------+ |
+-----------------------------------------------------------------------------+
Website Posting Specifications (≥10 Individuals)
- The notice must be posted conspicuously on the home page of the covered entity's website for a minimum of 90 consecutive calendar days, or via a prominent hyperlink on the home page that leads directly to the notice.
- The hyperlink must be displayed in a prominent font and color that immediately draws the attention of visitors.
- A toll-free telephone number must remain active for at least 90 days, staffed with personnel trained to answer inquiries.
4. Media Notification Mandate for Large Breaches (§ 164.406)
Under 45 CFR § 164.406, if a breach of unsecured PHI affects more than 500 residents of a single State or jurisdiction, the covered entity must issue a formal press release to prominent media outlets serving that State or jurisdiction.
+-----------------------------------------------------------------------------+
| MEDIA NOTIFICATION PARAMETERS (45 CFR § 164.406) |
| |
| • APPLICABILITY THRESHOLD: > 500 residents of a single State / Territory. |
| • TIMING: Without unreasonable delay and NO LATER THAN 60 CALENDAR DAYS |
| from the Date of Discovery. |
| • TARGET MEDIA: Prominent broadcast television, major regional newspapers, |
| and leading digital news outlets in the affected geographical area. |
| • CONTENT: Must include the exact same 5 core elements required in the |
| individual notice letter under § 164.404(c). |
+-----------------------------------------------------------------------------+
[!IMPORTANT] Jurisdictional Distribution Distinction: If a breach affects 600 total individuals, but they are distributed across multiple states (e.g., 200 in Texas, 200 in Oklahoma, and 200 in Louisiana), media notification under § 164.406 is not required, because the breach did not affect more than 500 residents of any single State. However, individual notice and large-breach HHS OCR reporting are still mandatory.
5. HHS OCR Notification Rules: Large Breaches vs. Annual Log (§ 164.408)
Covered entities must notify the Secretary of HHS of all breaches of unsecured PHI via the secure electronic reporting portal on the HHS Office for Civil Rights (OCR) website.
| Breach Scope | Statutory Reporting Deadline | Regulatory Protocol & OCR Action |
|---|---|---|
| Large Breaches<br>(≥ 500 Individuals) | Simultaneously with Individual Notice<br>(Without unreasonable delay and in no case later than 60 calendar days from discovery). | • Submitted electronically via the HHS OCR portal.<br>• Breaches are publicly posted on the HHS OCR Breach Portal (commonly known in the industry as the "Wall of Shame").<br>• Triggers an automatic, formal compliance investigation by OCR regional investigators. |
| Small Breaches<br>(< 500 Individuals) | Within 60 calendar days of the end of the calendar year<br>(March 1 of the following year, or Feb 29 in leap years). | • Maintained in internal electronic incident log throughout the year.<br>• Batch-submitted electronically via the OCR portal.<br>• Each small breach must be reported as a separate electronic entry detailing date, data types, and mitigation. |
+-----------------------------------------------------------------------------+
| HHS OCR ELECTRONIC REPORTING ARCHITECTURE |
| |
| +------------------------------------+ +----------------------------+ |
| | BREACHES AFFECTING >= 500 PATIENTS | | BREACHES AFFECTING < 500 | |
| +------------------------------------+ +----------------------------+ |
| | • Submit to HHS within 60 DAYS | | • Maintain internal log | |
| | • Listed on OCR Public Portal | | • Submit within 60 days of | |
| | ("Wall of Shame") | | calendar year end | |
| | • Direct OCR investigation initiated| | (Deadline: March 1) | |
| +------------------------------------+ +----------------------------+ |
+-----------------------------------------------------------------------------+
6. Business Associate Breach Reporting Obligations (§ 164.410)
Under 45 CFR § 164.410, a Business Associate (BA) that discovers a breach of unsecured PHI must notify the Covered Entity without unreasonable delay and in no case later than 60 calendar days from the date of discovery.
Operational BAA Realities vs. Statutory Defaults
- Statutory Mandate: The BA must provide the CE with the identities of each affected individual whose PHI was breached and all available information required for the CE to draft individual notices.
- Contractual BAA Negotiations: While the HIPAA statutory maximum is 60 calendar days, standard Business Associate Agreements almost universally negotiate significantly shorter notification windows—typically 24 hours, 48 hours, 5 business days, or 10 calendar days—to allow the Covered Entity sufficient time to investigate and execute individual and media notices before its own 60-day deadline expires.
7. Law Enforcement Delay Provisions (§ 164.412)
Under 45 CFR § 164.412, if a law enforcement official states to a covered entity or business associate that breach notification would impede a criminal investigation or cause damage to national security, the entity must temporarily delay notifications.
+-----------------------------------------------------------------------------+
| LAW ENFORCEMENT DELAY PROTOCOLS (45 CFR § 164.412) |
| |
| +------------------------------------+ +----------------------------+ |
| | WRITTEN STATEMENT FROM LAW ENFORC. | | ORAL STATEMENT FROM POLICE | |
| +------------------------------------+ +----------------------------+ |
| | • Official submits formal written | | • Official provides verbal | |
| | request specifying time delay | | statement of impediment | |
| | • Entity MUST delay notice for the | | • Entity documents officer | |
| | EXACT DURATION specified by the | | badge #, agency, date | |
| | law enforcement official | | • Delay capped at MAX 30 | |
| | | | DAYS unless written stmt | |
| +------------------------------------+ +----------------------------+ |
+-----------------------------------------------------------------------------+
8. Real-World Compliance Scenario & Officer Trap
+-----------------------------------------------------------------------------+
| REAL-WORLD SCENARIO: THE PHISHING SERVER BREACH |
| |
| SCENARIO: On October 1, a medical group's IT department detects an |
| unauthorized actor exfiltrating a database containing 1,500 patient names,|
| dates of birth, and clinical diagnosis codes. |
| |
| TIMELINE CHRONOLOGY: |
| • Oct 1: Date of Discovery by IT helpdesk. |
| • Oct 25: Forensic analysis confirms data exfiltration. |
| • Nov 15: Privacy Officer finalizes individual notice letters. |
| • Nov 28 (Day 58): Individual notices mailed via first-class mail; |
| notice submitted to HHS OCR electronic portal; media release issued. |
| |
| COMPLIANCE OFFICER TRAP: Believing that because 1,500 patients were |
| affected, media notice must be issued nationwide. |
| Media notification under § 164.406 is required ONLY in States or |
| jurisdictions where MORE THAN 500 residents were affected. If the 1,500 |
| patients reside in a single state, media notice is mandatory in that |
| state. If they reside across 4 states with no single state exceeding 500, |
| media notice is not required under federal law. |
+-----------------------------------------------------------------------------+
Under 45 CFR § 164.404(a)(2), when is a healthcare data breach legally considered to be 'discovered' by a covered entity?
A hospital experiences a ransomware attack that compromises the unsecured protected health information of 450 patients on August 10. According to 45 CFR § 164.408, what is the covered entity's statutory deadline for reporting this incident electronically to the Secretary of HHS?
A covered entity discovers a data breach affecting 1,200 individuals. When attempting to mail individual notice letters, the postal service returns 14 letters as undeliverable due to out-of-date addresses. How must the covered entity satisfy its substitute notice obligations under 45 CFR § 164.404(d)(2)?