Auditen
Home / Frameworks / HIPAA / The Breach Notification Rule
HIPAA · 164.400–414

The Breach Notification Rule

The Breach Notification Rule requires HIPAA-covered entities and their business associates to notify affected individuals, the Secretary of Health and Human Services (HHS), and in some cases the media, following a breach of unsecured protected health information (PHI). It establishes the criteria for determining whether an incident constitutes a reportable breach and sets strict timelines for these notifications.

What it means

In practice, this rule assumes that any unauthorized acquisition, access, use, or disclosure of PHI is a breach unless the organization can demonstrate there is a low probability that the PHI has been compromised based on a multi-factor risk assessment. This applies to both malicious attacks (like ransomware) and accidental disclosures (like emailing records to the wrong person).

The scope extends beyond just "hacking." It includes physical theft of devices, improper disposal of records, and internal unauthorized access by employees. If PHI is encrypted according to HHS standards, it is generally considered "secured," and its loss may not trigger these notification requirements.

Timing is critical. Notifications must be provided without unreasonable delay and no later than 60 calendar days after the discovery of the breach. For breaches affecting 500 or more individuals, notifications to the Secretary and the media must occur within this same window; for smaller breaches, reporting to HHS can happen annually.

How to meet it

Evidence an auditor asks for

  • The written Breach Notification Policy and Incident Response Plan.
  • Documentation of risk assessments conducted for past security incidents, showing the logic used to decide if notification was required.
  • Copies of actual notifications sent to individuals, the HHS portal records, and media releases (if applicable).
  • A master incident log detailing discovery dates, investigation timelines, and final resolutions.
  • Training logs proving that staff have been educated on breach reporting procedures.

Common pitfalls

  • Failing to document "non-events." Organizations often forget to record why they decided a specific incident was *not* a reportable breach, leaving them with no evidence for auditors.
  • Miscalculating the discovery date. The 60-day clock starts when the breach is first known (or should have been known), not when the investigation is completed.
  • Relying on encryption as a blanket exemption without verifying that the decryption keys were not also compromised during the incident.