13.3 Individual Notification Requirements: Content, Timelines (60-Day Clock), and Substitute Notice

Key Takeaways

  • Under 45 CFR § 164.404(b), covered entities must provide written notification to each individual whose unsecured PHI has been or is reasonably believed to have been breached without unreasonable delay and in no case later than sixty (60) calendar days after discovery of the breach.
  • Under 45 CFR § 164.404(a)(2), a breach is deemed discovered on the first day on which it is known to any workforce member or agent (other than the person committing the breach), or by exercising reasonable diligence would have been known, establishing that internal investigative delays cannot toll the 60-day statutory clock.
  • The individual notification must contain five mandatory statutory elements under 45 CFR § 164.404(c): (1) brief description of the incident and dates; (2) description of the types of unsecured PHI involved; (3) recommended mitigation steps for individuals; (4) actions taken by the entity to investigate and remediate; and (5) contact procedures, including a toll-free telephone number.
  • Under 45 CFR § 164.412, notification may be temporarily delayed upon law enforcement request: a formal written statement specifying the duration governs, while an oral statement permits a delay of no more than thirty (30) calendar days unless converted to writing.
  • When contact information is insufficient, 45 CFR § 164.404(d)(2) mandates substitute notice: for fewer than 10 individuals, an alternative written or telephone notice is permitted; for 10 or more individuals, conspicuous notification on the entity's website home page for 90 days (or major print/broadcast media) with an active toll-free telephone number is legally required.
Last updated: September 2026

Individual Notification Requirements: Content, Timelines, and Substitute Notice

Once a covered entity determines that an impermissible use or disclosure of unsecured protected health information has occurred, and the statutory presumption of breach cannot be rebutted under the four-factor risk assessment, the organization must immediately activate its statutory breach response protocol. The primary and most critical operational mandate under the Breach Notification Rule is individual notification, codified at 45 CFR § 164.404.

For the AHIMA CHPS candidate, individual notification is a heavily tested domain. Exam questions routinely evaluate a candidate's mastery of the statutory "clock," the precise definition of the "date of discovery," the five legally required content elements of the breach letter, postal versus electronic delivery mechanisms, temporary law enforcement delay exceptions, and the bifurcated substitute notice framework when patient contact information is incomplete.


The Statutory Timeline: The 60-Day Clock and "Unreasonable Delay"

Under 45 CFR § 164.404(b), the timing requirement for individual notification is stated with unambiguous statutory precision:

"Except as provided in § 164.412 [law enforcement delay], a covered entity shall provide the notification required by paragraph (a) of this section without unreasonable delay and in no case later than 60 calendar days after discovery of a breach."

1. The "Without Unreasonable Delay" Standard vs. The 60-Day Ceiling

A critical distinction tested on the CHPS exam is that 60 calendar days is an absolute outside ceiling, NOT a safe harbor. The primary statutory requirement is that notifications must be sent without unreasonable delay.

  • If a covered entity completes its internal investigation, identifies all 300 affected individuals, and compiles all postal addresses within 14 days of discovery, but intentionally holds the breach letters until Day 59 simply because leadership wants to delay public exposure, the covered entity has committed a statutory violation.
  • In multiple enforcement actions, HHS OCR has penalized covered entities for "unreasonable delay" even when notices were mailed on or before the 60th day, because the entity sat on completed information without an operational justification.

2. Defining the "Date of Discovery" (45 CFR § 164.404(a)(2))

The 60-calendar-day countdown does not begin when the covered entity completes its investigation, nor does it begin when the board of directors convenes or when external forensic counsel issues a final report. Under 45 CFR § 164.404(a)(2):

"A breach shall be treated as discovered by a covered entity on the first day on which such breach is known to the covered entity (including any person, other than the person committing the breach, who is a workforce member or agent of the covered entity), or by exercising reasonable diligence would have been known to the covered entity."

Key legal implications of this standard include:

  • Knowledge Imputed from Any Workforce Member: The moment any employee, nurse, medical assistant, or IT helpdesk technician (other than the wrongdoer) learns of an adverse event, knowledge of the breach is legally imputed to the covered entity. If a clinic receptionist learns on October 1 that a box of patient billing files is missing, but fails to notify the Privacy Officer until November 15, the statutory 60-day clock began on October 1.
  • The "Reasonable Diligence" Standard: Covered entities have an affirmative legal duty to maintain continuous monitoring, SIEM telemetry, and proactive auditing. If a rogue employee impermissibly exfiltrated patient charts continuously for two years, and the hospital failed to detect it because it never reviewed EHR audit logs, OCR will find that the hospital "by exercising reasonable diligence would have known" of the breach two years earlier, exposing the organization to severe willful neglect penalties.

Law Enforcement Delay (45 CFR § 164.412)

The only statutory provision under federal law that legally tolls or suspends the 60-calendar-day individual notification timeline is a formal request from law enforcement under 45 CFR § 164.412:

Law Enforcement Delay Framework (45 CFR § 164.412):

  ┌────────────────────────────────────────────────────────────────────────┐
  │ Law Enforcement Official Asserts Delay                                 │
  │ Official states notification would impede a criminal investigation    │
  │ or cause damage to national security                                   │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
               ┌──────────────────────┴──────────────────────┐
               │                                             │
               ▼                                             ▼
  ┌─────────────────────────┐                   ┌─────────────────────────┐
  │ Written Request         │                   │ Oral Request            │
  │ • Formal agency letter  │                   │ • Spoken request        │
  │ • Specifies exact time  │                   │ • Entity documents ID   │
  │ • Delay matches written │                   │ • Delay capped at       │
  │   specification         │                   │   30 CALENDAR DAYS      │
  └─────────────────────────┘                   └────────────┬────────────┘
                                                             │ (Must submit written
                                                             │  request within 30 days)
                                                             ▼
                                                ┌─────────────────────────┐
                                                │ If no written request   │
                                                │ received by Day 30:     │
                                                │ Must immediately notify │
                                                └─────────────────────────┘
  1. Written Request (§ 164.412(a)): If a law enforcement official (e.g., FBI, HHS-OIG, State Attorney General, or local police) submits a written statement stating that notification would impede a criminal investigation or cause damage to national security, and specifies the duration of the delay, the covered entity must delay notification for the exact time period specified by the official.
  2. Oral Request (§ 164.412(b)): If the law enforcement official makes the statement orally, the covered entity must:
    • Document the oral statement in writing, including the identity and agency of the official;
    • Delay notification for no longer than thirty (30) calendar days from the date of the oral statement;
    • If a written statement is not received within those 30 days, the covered entity must immediately proceed with breach notifications.

Mandatory Elements of Individual Breach Notice (45 CFR § 164.404(c))

Congress and HHS recognized that when patients receive breach letters, the notices are frequently written in obfuscated, legalistic jargon designed to minimize institutional embarrassment rather than inform victims. To ensure transparency, 45 CFR § 164.404(c) mandates that the individual notice be written in plain language and contain five mandatory elements:

Statutory ElementCitationStatutory MandatePractical Compliant Drafting Requirements
1. Incident Description & Dates45 CFR § 164.404(c)(1)(A)A brief description of what happenedMust include the date of the breach and the date of discovery, if known. Must plainly explain the nature of the cyber intrusion or physical loss
2. Types of Unsecured PHI Involved45 CFR § 164.404(c)(1)(B)A description of the types of unsecured PHI involvedMust specifically list whether full name, SSN, date of birth, home address, account number, diagnosis, disability code, or other clinical data elements were exposed
3. Steps Individuals Should Take45 CFR § 164.404(c)(1)(C)Steps individuals should take to protect themselvesConcrete recommendations: placing credit freezes, monitoring Explanation of Benefits (EOB) statements, enrolling in credit monitoring, contacting financial institutions
4. Entity Investigation & Remediation45 CFR § 164.404(c)(1)(D)What the covered entity is doing to investigate and mitigateExplains technical forensics, password resets, system patches, employee disciplinary actions, and new security safeguards implemented to prevent recurrence
5. Contact Procedures45 CFR § 164.404(c)(1)(E)Contact procedures for individuals to ask questionsMandatory: Must include a toll-free telephone number, an email address, a website, or a postal address where patients can obtain additional details

[!CRITICAL] Toll-Free Number Is Mandatory: On the CHPS exam, note that 45 CFR § 164.404(c)(1)(E) explicitly mandates that the contact procedures include a toll-free telephone number. Providing only a local hospital operator number, an email address, or a postal address without a toll-free number is a direct violation of federal notice content specifications.


Delivery Mechanisms: Written, Electronic, and Urgent Notice

Under 45 CFR § 164.404(d)(1), covered entities must execute individual notification through approved statutory communication channels:

  1. Written Notice by First-Class Mail: The default statutory delivery method is written notice sent by first-class mail to the individual at the last known postal address. Notice may be sent in a package with other communications (e.g., monthly billing statements) provided the breach notification is prominent and conspicuous.
  2. Electronic Notice by Email: Notice may be provided by electronic mail ONLY if the individual has previously agreed to receive electronic notices and such agreement has not been withdrawn pursuant to 45 CFR § 164.510. If the covered entity knows that the email bounced or failed delivery, it cannot rely on email and must immediately revert to first-class mail.
  3. Deceased Individuals: If the individual is deceased and the covered entity has contact information, written notice must be sent to the last known address of the next of kin or personal representative under 45 CFR § 164.404(d)(1)(iv).
  4. Urgent Notice (Imminent Misuse): If the covered entity determines that an incident requires urgency because of possible imminent misuse of unsecured PHI (e.g., active identity theft or live fraudulent debit card charges), the entity may provide telephone notice or other rapid means in addition to (but not in lieu of) written first-class mail.

Substitute Notice Requirements (45 CFR § 164.404(d)(2))

In healthcare, patients frequently move, change phone numbers, or provide incomplete demographic data. When a covered entity attempts to send written notice but discovers that it has insufficient or out-of-date contact information, it must provide substitute notice. The statutory framework bifurcates based on the number of individuals with insufficient contact details:

Substitute Notice Framework (45 CFR § 164.404(d)(2)):

                  Insufficient or Out-of-Date Contact Information
                                        │
               ┌────────────────────────┴────────────────────────┐
               │                                                 │
               ▼                                                 ▼
  ┌───────────────────────────┐                     ┌───────────────────────────┐
  │ Fewer than 10 Individuals │                     │ 10 or More Individuals    │
  │ (<10 patients)            │                     │ (≥10 patients)            │
  └─────────────┬─────────────┘                     └─────────────┬─────────────┘
                │                                                 │
                ▼                                                 ▼
  ┌───────────────────────────┐                     ┌───────────────────────────┐
  │ Individualized Alternate  │                     │ Conspicuous Public Notice │
  │ Notice:                   │                     │ Must provide EITHER:      │
  │ • Alternative written     │                     │ • Conspicuous notice on   │
  │   letter                  │                     │   website homepage for    │
  │ • Direct telephone call   │                     │   90 CONSECUTIVE DAYS     │
  │ • Other secure channel    │                     │ • Notice in major print / │
  │                           │                     │   broadcast media         │
  │                           │                     │ PLUS:                     │
  │                           │                     │ • Active toll-free number │
  │                           │                     │   for 90 days             │
  └───────────────────────────┘                     └───────────────────────────┘

1. Fewer Than 10 Individuals (<10 Patients) — § 164.404(d)(2)(i)

  • Threshold: The covered entity has insufficient contact information for fewer than 10 individuals.
  • Requirement: The entity may provide substitute notice through an alternative written notice, a telephone call, or other individualized means.
  • Operational Application: The privacy team can call the patient's alternative phone numbers on file, reach out to the emergency contact to obtain a current address, or send a secure portal message.

2. Ten or More Individuals (≥10 Patients) — § 164.404(d)(2)(ii)

  • Threshold: The covered entity has insufficient or out-of-date contact information for 10 or more individuals.
  • Mandatory Public Notice: The covered entity must provide substitute notice through one of two public mechanisms:
    1. Conspicuous Website Posting: A prominent notice posted for at least ninety (90) consecutive calendar days on the home page of the covered entity's website. The posting must include a direct hyperlink that takes visitors immediately to the full breach notification text; OR
    2. Major Media Notice: Notice published in major print or broadcast media in geographic areas where the affected individuals likely reside.
  • Mandatory Active Toll-Free Number: Regardless of whether website or print media is selected, the substitute notice must include an active toll-free telephone number that remains operational for at least 90 days, allowing individuals to call and learn whether their unsecured PHI was included in the breach.

CHPS Exam Tips and Common Candidate Traps

[!TIP] Exam Tip: Website Posting Requires 10+ Missing Addresses A favorite trick on the CHPS exam is presenting a scenario where a hospital suffers a breach affecting 1,000 patients, but has valid mailing addresses for 995 patients and is missing addresses for only 5 patients. The question asks what substitute notice is required for those 5 patients. Candidates incorrectly select "website home page posting for 90 days." The correct answer is an alternative written notice or telephone call, because the threshold for public website posting is 10 or more individuals with insufficient contact info!

[!WARNING] Candidate Trap: Law Enforcement Oral Delay Is Capped at 30 Days Watch out for exam questions where a police detective orally instructs a privacy officer not to send breach letters until the police conclude their investigation. Remember: an oral request legally caps the delay at thirty (30) calendar days under 45 CFR § 164.412(b). If the detective does not provide a formal written request before Day 30 expires, the covered entity must immediately mail the individual notices!

[!CAUTION] Candidate Trap: Electronic Notice Requires Prior Consent An entity cannot simply blast out breach notification emails to all patients unless those specific patients previously executed an electronic communication agreement. If an entity sends breach notices via email to patients who never consented to electronic notice, the entity has failed to satisfy the delivery requirements of 45 CFR § 164.404(d)(1).

Loading diagram...
Individual Breach Notification Statutory Delivery and Substitute Notice Flow
Test Your Knowledge

A community hospital's IT security team detects an unencrypted database exfiltration on June 1 involving the clinical records of 1,500 cardiology patients. The hospital retains an external digital forensics firm, which completes its forensic investigation and submits its final technical report on July 20 (Day 50). The hospital's legal counsel and executive committee review the report, finalize the patient mailing list on August 10 (Day 71), and mail the individual breach notification letters on August 25 (Day 86). The hospital defends its timeline by arguing that the 60-day statutory clock did not begin until the external forensics firm formally completed its investigation and established certainty of breach scope. How will the HHS Office for Civil Rights evaluate this compliance timeline?

A
B
C
D
Test Your Knowledge

A specialized pediatric clinic suffers a burglary in which paper files containing clinical histories and Social Security numbers for 400 patients were stolen. The local police detective leading the criminal investigation meets with the clinic's Privacy Officer on Day 10 and orally requests that the clinic delay sending individual breach letters, stating that public letters will alert the suspects and destroy an active undercover sting operation. The detective promises to follow up with formal paperwork but never submits a written letter. By Day 45 following the oral meeting (Day 55 from breach discovery), the clinic still has not mailed the individual breach letters. How does 45 CFR § 164.412 govern this situation?

A
B
C
D
Test Your Knowledge

A multi-specialty health center mails individual breach notifications to 2,000 patients whose billing information was compromised. Within two weeks, the postal service returns 18 breach notification letters marked 'Undeliverable / Return to Sender / No Forwarding Address on File.' The health center's compliance team checks the electronic medical record and confirms that it has no alternative phone numbers, email addresses, or updated physical addresses for these 18 individuals. What action is legally mandated for these 18 individuals under 45 CFR § 164.404(d)(2)?

A
B
C
D