HIPAA Breach Notification: Employer and Plan Responsibilities
When an incident involving protected health information may become a reportable breach and how notification duties are organized.
From incident to breach analysis
An impermissible acquisition, access, use, or disclosure of unsecured protected health information is generally presumed to be a breach unless an exception applies or a documented risk assessment demonstrates a low probability that the information was compromised.
Core response steps
- Contain the incident and preserve evidence.
- Identify the covered entity, business associate, plan, systems, and individuals involved.
- Document the required risk assessment and any applicable exception.
- Apply contractual business-associate reporting duties.
- If notification is required, prepare notices to affected individuals and HHS; media notice may also apply for breaches affecting more than 500 residents of a state or jurisdiction.
- Document corrective actions and retain the response record.
Timing
Required individual notices generally must be provided without unreasonable delay and no later than 60 calendar days after discovery. HHS timing depends in part on whether the breach affects 500 or more individuals.
Primary sources
This resource is provided for general educational purposes and does not constitute legal, tax, benefits, safety, or other professional advice. Requirements and individual circumstances vary. Confirm current rules with authoritative sources and qualified advisors.
Back to Resources