Notice of Breach of Unsecured Protected Health Information (PHI)

If unsecured PHI is breached, HIPAA requires notice to affected individuals, to HHS, and, for large breaches, to prominent media outlets.

What Notifications required under HITECH/HIPAA when unsecured PHI is breached.
Who Covered entities (including employer-sponsored health plans) and business associates. A BA that discovers a breach must notify the covered entity.
When Individuals and HHS (500+): without unreasonable delay and no later than 60 days after discovery. HHS (under 500): within 60 days after the end of the calendar year. Media: same 60-day window when 500+ residents of a state or jurisdiction are affected.
Risk Significant civil monetary penalties (tiered by culpability), potential criminal penalties, corrective action plans, and reputational harm.
60
Days from discovery

Individuals, HHS (for 500+), and media must be notified without unreasonable delay and no later than 60 days after discovery.

500
Threshold for prompt HHS and media

When 500 or more individuals (or 500+ residents of a state) are affected, prompt HHS reporting and a media notice are required.

Recipient Deadline Notes
Affected individuals Without unreasonable delay; no later than 60 days after discovery Clock starts at discovery, not at completion of the investigation.
HHS, 500 or more individuals affected Without unreasonable delay; no later than 60 days after discovery Submit electronically via the HHS breach portal.
HHS, fewer than 500 individuals affected Within 60 days after the end of the calendar year in which breaches occurred Report smaller breaches in aggregate on the annual log submission.
Media, 500+ residents of a state or jurisdiction affected Without unreasonable delay; no later than 60 days after discovery Notify prominent media outlets serving the affected state or jurisdiction.
Business associate to covered entity Without unreasonable delay; no later than 60 days after BA discovery BA must provide identities of affected individuals (if known) and details to enable CE notifications. BAA may specify a shorter window.
Recipient: Affected individuals
Deadline: No later than 60 days after discovery
Notes: Clock starts at discovery, not investigation completion.
Recipient: HHS, 500+ affected
Deadline: No later than 60 days after discovery
Notes: Submit via the HHS breach portal.
Recipient: HHS, fewer than 500 affected
Deadline: Within 60 days after the end of the calendar year
Notes: Report in aggregate on the annual log.
Recipient: Media, 500+ residents of a state
Deadline: No later than 60 days after discovery
Notes: Notify prominent media outlets in the affected area.
Recipient: Business associate to covered entity
Deadline: No later than 60 days after BA discovery
Notes: BAA may specify a shorter window.
  • Incident log and forensics summary: date of discovery, systems and data involved, scope of unauthorized access.
  • Risk assessment: nature and extent of PHI involved, identity of the unauthorized person, whether PHI was actually acquired or viewed, and mitigation actions taken.
  • Affected individual roster: names, last-known mailing addresses, and email addresses (if applicable); count by state and jurisdiction.
  • BAA details: if a business associate is involved, BAA terms, BA contact points, and the BA's notice to the covered entity.
  • Notice templates: individual notice letter, media statement, and HHS submission checklist. See Templates & Resources below.
1
Contain and investigateSecure affected systems, preserve evidence, and engage IT or forensic resources to determine scope.
2
Assess breach statusConduct the HIPAA four-factor risk assessment to determine whether notification is required, or whether the encryption safe harbor or low-probability-of-compromise exception applies.
3
Identify all recipientsDetermine who must be notified (affected individuals, HHS, media) and whether a BA notification to the covered entity is needed or has been received.
4
Draft noticesInclude all required elements: what happened and when, types of PHI involved, what individuals should do to protect themselves, what the organization is doing, and a toll-free contact number.
5
Deliver within required timelinesSend notices, track undeliverables, and issue substitute notice if needed. Log all delivery attempts.
6
Document and remediatePreserve all records; remediate root causes; update policies, BAAs, and training as appropriate.
  • Individuals: First-class mail to last-known address. Email is permitted if the individual previously agreed to receive communications electronically.
  • Substitute notice, more than 10 individuals with insufficient contact info: Post a conspicuous notice on the organization's website for at least 90 days, or provide notice to major print or broadcast media in the affected area.
  • Substitute notice, 10 or fewer individuals with insufficient contact info: Alternative written notice, telephone, or other means.
  • Media: Press release or equivalent to prominent media outlets serving the affected state or jurisdiction; required when 500+ residents are affected.
  • HHS: Electronic submission via the HHS breach portal. Large breaches (500+) are reported promptly; smaller breaches are reported on the annual log.
  • All individual notices must include a toll-free contact number active for at least 90 days, steps individuals can take, and, if applicable, credit monitoring or other services being offered.
  • Determination recordsRisk assessment, investigation reports, and the final breach/not-breach determination with supporting rationale.
  • Notices and proofsCopies of all notices sent (individual, HHS submission confirmation, media release) and delivery proofs or logs.
  • Substitute notice recordsRecord of substitute notice actions taken (website postings, media outlets notified).
  • Inquiry and remediation logsCall center or inquiry logs and remediation or corrective action plans.
  • RetentionAt least 6 years from the date of creation or last effective date, consistent with HIPAA's general documentation standard.

Common traps

Starting the 60-day clock from investigation completion: The clock starts at discovery, not when the investigation wraps up. You may still be investigating on day 60; you still have to send the notice.
Assuming encryption without confirming it: The encryption safe harbor only applies when the data was encrypted to NIST standards and the key was not also compromised. Assuming it doesn't work.
Missing the media notice: When 500 or more residents of a single state or jurisdiction are affected, a media notice is required; it's a separate obligation from the individual and HHS notices, not optional.
Underestimating state law requirements: Many states impose shorter timelines or additional recipients (such as the state AG). A HIPAA-compliant response may still be incomplete under state law.
BAA doesn't specify reporting timelines: HIPAA requires BA notification to the CE "without unreasonable delay." If the BAA doesn't specify a shorter window, you're at the mercy of the BA's interpretation. Negotiate specific timeframes in your BAAs.

FAQs

What is a "breach of unsecured PHI"?
An impermissible acquisition, access, use, or disclosure of PHI that compromises the privacy or security of the information, unless the covered entity or BA demonstrates that there is a low probability the PHI has been compromised based on a four-factor risk assessment, or that another exception applies (such as the encryption safe harbor).

Who must be notified?
Always: affected individuals and HHS. Additionally: prominent media outlets if 500 or more residents of a single state or jurisdiction are affected. If a business associate caused or discovered the breach, the BA must notify the covered entity so the CE can fulfill its notice obligations.

What are the penalties for late or missing notification?
Civil monetary penalties under HIPAA/HITECH are tiered by culpability, from situations where the entity did not know and could not have known, up to willful neglect. Annual caps apply per violation category. Criminal penalties are possible in cases of knowing misuse of PHI. OCR corrective action plans are common outcomes of enforcement investigations.

Does this apply to self-insured employer health plans?
Yes. A self-insured group health plan is a covered entity under HIPAA. The employer acting as plan sponsor has obligations under the plan's HIPAA policies. If the plan uses a TPA, the TPA is likely a business associate; ensure the BAA addresses breach notification timelines and cooperation.

Report to HHS through the official OCR portal, and use the drop-in starters below for the individual notice letter, the media statement, and your HHS submission checklist. Tailor each to the specific incident and have counsel review before sending.

Individual notice letter (drop-in starter; must contain all five required elements):

"Dear [Name],

We are writing to notify you of a data security incident that may have involved some of your protected health information. What happened: On [discovery date], we discovered that [brief description of what happened and the date/range of the breach]. Information involved: The information that may have been involved included [types of PHI, e.g., name, date of birth, Social Security number, member ID, claims/diagnosis information]. What you can do: [Steps the individual should take to protect themselves, e.g., review statements, place a fraud alert, monitor credit; include any credit-monitoring offer]. What we are doing: [Investigation, mitigation, and steps to prevent recurrence]. For more information: Please contact us at [toll-free number active at least 90 days], [email], or [postal address].

Sincerely, [Plan/Plan Sponsor name]"

Media statement (drop-in starter; required when 500+ residents of one state/jurisdiction are affected):

"[Plan/Plan Sponsor name] is notifying individuals of a data security incident discovered on [date] that may have involved the protected health information of [number] residents of [state/jurisdiction]. The information potentially involved included [types of PHI]. [Plan name] is [investigating/mitigating/offering services] and has begun notifying affected individuals directly. Individuals with questions may call [toll-free number]."

HHS submission checklist:

  • Covered entity and (if applicable) business associate contact information.
  • Dates of the breach and of discovery.
  • Approximate number of individuals affected (and, for the portal, the type of breach and location of breached information).
  • Types of PHI involved and a brief description of what happened.
  • Safeguards in place before the breach and actions taken in response (investigation, mitigation, notification, prevention).
  • Whether the 500+ (prompt) or under-500 (annual log) timing applies.

Note: HIPAA notice content is federally required, but many states impose additional or stricter requirements (shorter deadlines, notice to the state attorney general, specific letter content). Confirm state-law obligations before finalizing any notice.