The Breach Notification Rule
The Breach Notification Rule requires HIPAA-covered entities and their business associates to notify affected individuals, the Secretary of Health and Human Services (HHS), and in some cases the media, following a breach of unsecured protected health information (PHI). It establishes the criteria for determining whether an incident constitutes a reportable breach and sets strict timelines for these notifications.
What it means
In practice, this rule assumes that any unauthorized acquisition, access, use, or disclosure of PHI is a breach unless the organization can demonstrate there is a low probability that the PHI has been compromised based on a multi-factor risk assessment. This applies to both malicious attacks (like ransomware) and accidental disclosures (like emailing records to the wrong person).
The scope extends beyond just "hacking." It includes physical theft of devices, improper disposal of records, and internal unauthorized access by employees. If PHI is encrypted according to HHS standards, it is generally considered "secured," and its loss may not trigger these notification requirements.
Timing is critical. Notifications must be provided without unreasonable delay and no later than 60 calendar days after the discovery of the breach. For breaches affecting 500 or more individuals, notifications to the Secretary and the media must occur within this same window; for smaller breaches, reporting to HHS can happen annually.
How to meet it
- Develop a written Incident Response Plan (IRP) that specifically includes a workflow for HIPAA breach determination and notification.
- Implement a standardized risk assessment process based on the four HHS factors: the nature of PHI involved, the unauthorized person who used the PHI, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
- Create pre-approved notification templates for individuals that include the required elements (e.g., description of what happened, types of PHI involved, and steps individuals should take).
- Establish a centralized log to track all security incidents, including those determined not to be breaches, along with the justification for that decision.
- Configure system logging and alerting to ensure unauthorized access is detected promptly, triggering the "discovery" clock immediately.
- Train all employees on how to identify and report suspected breaches to the Privacy or Security Officer without delay.
Evidence an auditor asks for
- The written Breach Notification Policy and Incident Response Plan.
- Documentation of risk assessments conducted for past security incidents, showing the logic used to decide if notification was required.
- Copies of actual notifications sent to individuals, the HHS portal records, and media releases (if applicable).
- A master incident log detailing discovery dates, investigation timelines, and final resolutions.
- Training logs proving that staff have been educated on breach reporting procedures.
Common pitfalls
- Failing to document "non-events." Organizations often forget to record why they decided a specific incident was *not* a reportable breach, leaving them with no evidence for auditors.
- Miscalculating the discovery date. The 60-day clock starts when the breach is first known (or should have been known), not when the investigation is completed.
- Relying on encryption as a blanket exemption without verifying that the decryption keys were not also compromised during the incident.