Short answer: The HIPAA Breach Notification Rule requires practices to notify affected patients within 60 days of discovering a breach of unsecured PHI, notify HHS (timing depends on the size of the breach), and, for breaches affecting 500 or more individuals in a state or jurisdiction, notify prominent media outlets as well. This is a distinct set of obligations from the Security Rule's general safeguard requirements — it specifically governs what you must do after something has already gone wrong.
Why this is its own rule, separate from Security and Privacy
Much of what's discussed about HIPAA compliance for small practices focuses on prevention: risk assessments, safeguards, training, policies. The Breach Notification Rule governs a different moment entirely — what you're legally required to do once a breach has actually happened. It has its own specific definitions, timelines, and thresholds, and treating it as an afterthought to your general security program is a common and risky gap.
What actually counts as a "breach"
A breach, under this rule, is generally an impermissible use or disclosure of unsecured PHI that compromises its security or privacy. Not every incident meets this bar — for example, PHI that was properly encrypted (meeting HHS's specific encryption standards) generally isn't considered "unsecured," and a disclosure to another part of the same covered entity in good faith may not qualify as a breach at all. Determining whether something actually counts as a reportable breach requires a documented risk assessment of the incident itself, not just a gut call.
The notification timeline, step by step
To affected individuals: within 60 days. Once you discover the breach, you generally have 60 calendar days to notify each affected patient directly, typically by first-class mail (or email if the patient has agreed to electronic notice).
To HHS: timing depends on breach size. For breaches affecting 500 or more individuals, HHS must be notified at the same time as affected individuals, within that same 60-day window. For breaches affecting fewer than 500 individuals, notification to HHS can be made annually, within 60 days after the end of the calendar year in which the breach was discovered — but it still needs to be tracked and reported, not skipped because it's a smaller incident.
To the media: only for large breaches. If a breach affects 500 or more residents of a single state or jurisdiction, you're also required to notify prominent media outlets serving that area, in addition to notifying affected individuals and HHS.
What the notification itself needs to include
A breach notification generally needs to describe what happened, what types of information were involved, steps individuals should take to protect themselves, what the practice is doing to investigate and mitigate the breach, and contact information for questions. Vague or incomplete notifications can create additional problems on top of the breach itself.
Why "discovery" matters as much as the breach itself
The 60-day clock starts at discovery, not at the moment the breach technically occurred — but discovery is interpreted fairly broadly, generally including when the breach reasonably should have been discovered with proper diligence, not just when someone happened to notice. This is part of why an ongoing, current risk assessment and monitoring program matters: a breach sitting undetected for months because nobody was watching doesn't reset or extend your notification clock in your favor.
How this connects to your broader compliance program
A written incident response plan — one of the core Security Rule documentation requirements — is what should actually walk your practice through these Breach Notification Rule timelines and requirements when something happens, rather than trying to research the rule for the first time in the middle of an active incident.