Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When must you notify a HIPAA breach?

Updated

Covered entities notify individuals without unreasonable delay and in no case later than 60 calendar days after discovery (45 CFR 164.404). HHS OCR uses a 500+ versus <500 clock (164.408). Media notice is a separate 500-resident trigger (164.406). Not legal advice; does not start a clock.

HIPAA jurisdiction guide, last verified 8 September 2026 against 45 CFR Part 164 Subpart D (eCFR, title 45 up to date as of 3 September 2026; Subpart D last amended 25 January 2013) and HHS OCR breach-notification pages actually fetched. OCR guidance is guidance, not the rule. It is not legal advice, not a filing, not a four-factor finding on YOUR facts, not a determination that you are a covered entity or a business associate, and not a substitute for counsel.

This is 45 CFR §§164.400–414, not YOUR determination

Audience: a compliance lead, privacy officer, CISO, or counsel at a covered entity or business associate triaging an incident that may involve unsecured protected health information. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that HIPAA applies, that you are a covered entity or a business associate, that a breach of unsecured PHI occurred, that low probability of compromise is or is not demonstrated, or that you must file.

The HIPAA Breach Notification Rule is 45 CFR Part 164 Subpart D (§§164.400–414). §164.400: the requirements of this subpart apply with respect to breaches of protected health information occurring on or after September 23, 2009. Those sections are legal requirements only if HIPAA applies to YOUR facts. Last verified 8 September 2026. Not legal advice.

  • Statute versus guidance: 45 CFR §§164.400–414 are legal requirements only if HIPAA applies. HHS OCR breach-notification pages, the HHS how-to for submitting notice to the Secretary, and the Secretary's encryption-and-destruction guidance are OCR materials or Secretary guidance, not the rule. This page quotes which kind of text it is relying on.
  • This page does not start 60 calendar days, does not convert 60 calendar days into 2 months or 45 days, and does not convert 'without unreasonable delay' into a number of days other than the outer mark the cited section states.
  • Individual notice (§164.404), media notice (§164.406), and Secretary notice (§164.408) are different recipient classes with different triggers. Do not paste the media trigger onto HHS or individual notice. Do not collapse the 500+ and <500 HHS clocks into one number.
  • The reporting-deadlines page on this site is the statute table of clocks. The who-to-notify page on this site is the recipient-class map. The supporting-evidence page on this site is the evidentiary record. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not a HIPAA clock, and it does not file with HHS OCR. A named human still submits.

Four-factor risk assessment — low probability of compromise

§164.402 defines breach. Except for three listed exclusions, an acquisition, access, use, or disclosure of PHI not permitted under subpart E is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment of at least four factors. This page quotes those factors. It does not find low probability on YOUR facts. Last verified 8 September 2026. Not legal advice.

§164.402 definition of breach (legal requirement only if HIPAA applies — not YOUR four-factor finding; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
Breach (chapeau)Breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information.Legal requirement — §164.402 definition. Only if HIPAA applies.8 September 2026
Exclusion (i) — unintentional workforceAny unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under subpart E.Legal requirement — §164.402(1)(i). Counsel applies the exclusion. This page does not.8 September 2026
Exclusion (ii) — inadvertent internal disclosureAny inadvertent disclosure by a person who is authorized to access protected health information at a covered entity or business associate to another person authorized to access protected health information at the same covered entity or business associate, or organized health care arrangement in which the covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted under subpart E.Legal requirement — §164.402(1)(ii). Not a finding that YOUR disclosure was inadvertent.8 September 2026
Exclusion (iii) — unable to retainA disclosure of protected health information where a covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.Legal requirement — §164.402(1)(iii). Not a finding of YOUR good faith belief.8 September 2026
PresumptionExcept as provided in paragraph (1) of this definition, an acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors.Legal requirement — §164.402(2). Presumed a breach unless that demonstration is made. This page does not make it.8 September 2026
Factor (i)The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification.Legal requirement — §164.402(2)(i). One of at least four factors.8 September 2026
Factor (ii)The unauthorized person who used the protected health information or to whom the disclosure was made.Legal requirement — §164.402(2)(ii).8 September 2026
Factor (iii)Whether the protected health information was actually acquired or viewed.Legal requirement — §164.402(2)(iii).8 September 2026
Factor (iv)The extent to which the risk to the protected health information has been mitigated.Legal requirement — §164.402(2)(iv).8 September 2026
Burden of proofIn the event of a use or disclosure in violation of subpart E, the covered entity or business associate, as applicable, shall have the burden of demonstrating that all notifications were made as required by this subpart or that the use or disclosure did not constitute a breach, as defined at §164.402.Legal requirement — §164.414(b). This page does not carry YOUR burden.8 September 2026
OCR four-factor restatementOCR's Fact Sheet: Ransomware and HIPAA restates the same four factors and cites 45 CFR 164.402(2). It is OCR guidance, not the rule. Entities are encouraged there to consider additional factors as needed. Additional factors in that fact sheet are not a fifth numbered factor in §164.402(2).OCR guidance, not the rule. This page does not apply ransomware analysis to YOUR facts.8 September 2026

Unsecured PHI — the rule plus Secretary guidance

Notification duties in Subpart D attach to a breach of unsecured protected health information. §164.402: unsecured protected health information means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of Public Law 111-5. That definition is the rule. The technologies and methodologies themselves sit in Secretary guidance. Last verified 8 September 2026. Not legal advice.

  • Legal requirement (the definition): §164.402 'unsecured protected health information'. Only if HIPAA applies.
  • Secretary guidance (not the rule): Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals names encryption consistent with specified NIST publications, and destruction (hard-copy shredded so it cannot be reconstructed; electronic media cleared, purged, or destroyed consistent with NIST SP 800-88). Redaction is specifically excluded as a means of data destruction in that guidance. This page does not find that YOUR encryption or destruction meets that guidance.
  • HHS Breach Notification Rule overview (OCR materials): covered entities and business associates must only provide the required notifications if the breach involved unsecured PHI. Entities that secure information as specified by the guidance are relieved from providing notifications following the breach of such information. That sentence is OCR materials restating the definition, not a finding about YOUR media.

Individual notice — 60 calendar days from discovery

§164.404 is the covered entity's notice to each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach. Quote the section's words. 60 calendar days is not 2 months and not 45 days. This page does not start that clock. Last verified 8 September 2026. Not legal advice.

§164.404 individual notice (legal requirement only if HIPAA applies — not YOUR start time; not legal advice; does not start a clock)
ElementWhat the text saysKind of textLast verified
DutyA covered entity shall, following the discovery of a breach of unsecured protected health information, notify each individual whose unsecured protected health information has been, or is reasonably believed by the covered entity to have been, accessed, acquired, used, or disclosed as a result of such breach.Legal requirement — §164.404(a)(1). Only if HIPAA applies. Covered entity, not the business associate's individual-notice duty.8 September 2026
TimelinessExcept as provided in §164.412, a covered entity shall provide the notification required by paragraph (a) of this section without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.Legal requirement — §164.404(b). 60 calendar days is the outer mark. 'Without unreasonable delay' is not converted here into a smaller number. 60 calendar days is not 2 months and not 45 days.8 September 2026
DiscoveryA breach shall be treated as discovered by a covered entity as of the first day on which such breach is known to the covered entity, or, by exercising reasonable diligence would have been known to the covered entity. A covered entity shall be deemed to have knowledge of a breach if such breach is known, or by exercising reasonable diligence would have been known, to any person, other than the person committing the breach, who is a workforce member or agent of the covered entity (determined in accordance with the federal common law of agency).Legal requirement — §164.404(a)(2). This is HIPAA discovery, including constructive knowledge. It is not GDPR Article 33(1) 'having become aware'. It is not Form 8-K Item 1.05 materiality determination.8 September 2026
Content (to the extent possible)A brief description of what happened, including the date of the breach and the date of the discovery of the breach, if known; a description of the types of unsecured PHI involved (examples in the section include full name, social security number, date of birth, home address, account number, diagnosis, disability code, or other types); any steps individuals should take to protect themselves from potential harm; a brief description of what the covered entity is doing to investigate, mitigate harm, and protect against further breaches; and contact procedures for individuals to ask questions or learn additional information, which shall include a telephone number, an e-mail address, Web site, or postal address. The notification shall be written in plain language.Legal requirement — §164.404(c). This page does not draft YOUR notice.8 September 2026
Written noticeWritten notification by first-class mail to the individual at the last known address, or, if the individual agrees to electronic notice and such agreement has not been withdrawn, by electronic mail. The notification may be provided in one or more mailings as information is available. If the covered entity knows the individual is deceased and has the address of the next of kin or personal representative, written notification by first-class mail to either.Legal requirement — §164.404(d)(1). Not a finding that YOU have a last known address.8 September 2026
Substitute noticeIf insufficient or out-of-date contact information precludes written notification: a substitute form of notice reasonably calculated to reach the individual. Fewer than 10 individuals: alternative written notice, telephone, or other means. 10 or more individuals: conspicuous posting for 90 days on the home page of the Web site of the covered entity, or conspicuous notice in major print or broadcast media in geographic areas where the individuals affected likely reside; and a phone number that remains active for at least 90 days where an individual can learn whether that individual's unsecured PHI may be included. Substitute notice need not be provided where insufficient contact information precludes written notification to next of kin or a personal representative under (d)(1)(ii).Legal requirement — §164.404(d)(2). Fewer than 10 is not 10 or more. This page does not run YOUR contact-information census.8 September 2026
Urgent additional noticeIn any case deemed by the covered entity to require urgency because of possible imminent misuse of unsecured PHI, the covered entity may provide information to individuals by telephone or other means, as appropriate, in addition to notice under paragraph (d)(1).Legal requirement — §164.404(d)(3). Additional to, not instead of, (d)(1). This page does not deem urgency.8 September 2026

500+ versus <500 — HHS, media, and individual clocks are not one number

Three recipient classes. Three different 500-related sentences. Do not paste the media trigger onto HHS or individual notice. Do not treat the 500+ HHS clock and the <500 HHS clock as one number. Last verified 8 September 2026. Not legal advice.

Individual, media, and Secretary notice (legal requirement only if HIPAA applies — not YOUR census; not legal advice; does not start a clock)
Recipient classTrigger as the section states itTiming as the section states itKind of textLast verified
Individuals — §164.404Each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach. No 500-person threshold in that sentence.Without unreasonable delay and in no case later than 60 calendar days after discovery, except as provided in §164.412.Legal requirement — §164.404(a)–(b).8 September 2026
Media — §164.406A breach of unsecured PHI involving more than 500 residents of a State or jurisdiction. 'More than 500 residents of a State or jurisdiction' is not '500 or more individuals' nationwide.Without unreasonable delay and in no case later than 60 calendar days after discovery of a breach, except as provided in §164.412. Content meets §164.404(c).Legal requirement — §164.406. Additional to, not instead of, individual notice. Do not paste this trigger onto §164.408.8 September 2026
Secretary of HHS — 500 or more individuals — §164.408(b)Breaches of unsecured PHI involving 500 or more individuals. That count is individuals, not 'residents of a State or jurisdiction'.Contemporaneously with the notice required by §164.404(a) and in the manner specified on the HHS Web site, except as provided in §164.412. §164.404(a) is itself without unreasonable delay and in no case later than 60 calendar days after discovery.Legal requirement — §164.408(a)–(b). Not the media trigger. Not the <500 annual log.8 September 2026
Secretary of HHS — fewer than 500 individuals — §164.408(c)Breaches of unsecured PHI involving less than 500 individuals. Maintain a log or other documentation of such breaches.Not later than 60 days after the end of each calendar year, provide the notification required by paragraph (a) for breaches discovered during the preceding calendar year, in the manner specified on the HHS web site. That clock is not the 60-calendar-day-from-discovery clock in §164.404(b) and §164.408(b).Legal requirement — §164.408(c). The two HHS clocks are not one number.8 September 2026

How to notify the Secretary — OCR materials, not the rule

§164.408 says notify the Secretary 'in the manner specified on the HHS Web site.' The manner is not restated in the CFR text this page fetched. Last verified 8 September 2026 against the HHS page Submitting Notice of a Breach to the Secretary. That page is OCR materials, not 45 CFR 164.408. This product does not file with HHS OCR. A named human still submits.

  • OCR materials (HHS breach-reporting page): a HIPAA covered entity must notify the Secretary if it discovers a breach of unsecured PHI (see 45 CFR 164.408). A HIPAA business associate may submit a breach report on behalf of a covered entity. That 'may submit on behalf' sentence is OCR materials, not a rewrite of §164.408's covered-entity duty.
  • OCR materials — 500 or more: submit the notice electronically through the online breach reporting portal; without unreasonable delay; no later than 60 calendar days from the discovery of the breach. Complete all required fields. If uncertain about the number affected at submission, provide an estimate.
  • OCR materials — fewer than 500: within 60 days after the end of the calendar year in which the breach was discovered. You do not have to wait until the end of the year; you may report the breach as soon as it is discovered. That early-optional sentence is OCR materials, not a second clock in §164.408(c).
  • Public list: as required by section 13402(e)(4) of the HITECH Act, the Secretary posts a list of breaches of unsecured PHI affecting 500 or more individuals. The HIPAA public list this page fetched is the OCR portal at ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf. Inclusion on that list is a posted report, not a finding of noncompliance by this page. This product does not post there.
  • 42 CFR Part 2 (substance-use-disorder records) has a separate Secretary-notice path on the same HHS how-to page. Part 2 is not Subpart D. This page does not treat Part 2 clocks.

Covered entity versus business associate — do not invert the duties

A business associate is not a covered entity. §164.410 is the business associate's notice to the covered entity. §§164.404, 164.406, and 164.408 are the covered entity's notices to individuals, the media, and the Secretary. Do not invert those duties. Last verified 8 September 2026. Not legal advice.

BA versus covered entity (legal requirement only if HIPAA applies — not a determination that YOU are either; not legal advice)
WhoDuty as the text states itKind of textLast verified
Covered entity — who45 CFR 160.103: covered entity means (1) a health plan; (2) a health care clearinghouse; (3) a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.Legal requirement — 45 CFR 160.103 definition. This page does not determine that YOU are a covered entity.8 September 2026
Business associate — who45 CFR 160.103: with respect to a covered entity, a person who on behalf of such covered entity creates, receives, maintains, or transmits PHI for a function or activity regulated by the subchapter, or who provides listed services involving disclosure of PHI, other than in the capacity of a workforce member. Includes a subcontractor that creates, receives, maintains, or transmits PHI on behalf of the business associate. A covered entity may be a business associate of another covered entity.Legal requirement — 45 CFR 160.103 definition. This page does not determine that YOU are a business associate.8 September 2026
Business associate → covered entityA business associate shall, following the discovery of a breach of unsecured protected health information, notify the covered entity of such breach. Except as provided in §164.412, without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. To the extent possible, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach, plus any other available information the covered entity is required to include in notification to the individual under §164.404(c), at the time of the BA notice or promptly thereafter as information becomes available.Legal requirement — §164.410. The BA notifies the covered entity. The BA's §164.410 notice is not individual notice, not media notice, and not Secretary notice.8 September 2026
BA discoveryA breach shall be treated as discovered by a business associate as of the first day on which such breach is known to the business associate or, by exercising reasonable diligence, would have been known to the business associate. Deemed knowledge if known, or by reasonable diligence would have been known, to any person, other than the person committing the breach, who is an employee, officer, or other agent of the business associate (federal common law of agency).Legal requirement — §164.410(a)(2). Parallel to, not the same sentence as, covered-entity discovery in §164.404(a)(2).8 September 2026
Covered entity → individuals / media / Secretary§164.404 individual notice, §164.406 media notice, and §164.408 Secretary notice are covered-entity duties. A BA submitting a Secretary report on behalf of a covered entity, as the HHS how-to page describes, is OCR materials about the portal — it does not rewrite §164.408 into a BA-owned Secretary duty, and it does not make the BA the individual-notice sender under §164.404.Legal requirement (the CE duties) plus OCR materials (portal may-submit). Do not invert.8 September 2026
Subcontractor160.103: a subcontractor that creates, receives, maintains, or transmits PHI on behalf of the business associate is a business associate. §164.410 still says the business associate notifies the covered entity. This page does not rewrite that sentence into a different recipient for YOUR chain, and it does not decide YOUR chain.Legal requirement — 160.103(3)(iii) plus §164.410 as fetched. Not a determination of YOUR subcontract.8 September 2026

Law-enforcement delay — §164.412

If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under this subpart would impede a criminal investigation or cause damage to national security, a covered entity or business associate shall: (a) if the statement is in writing and specifies the time for which a delay is required, delay such notification, notice, or posting for the time period specified by the official; or (b) if the statement is made orally, document the statement, including the identity of the official making the statement, and delay the notification, notice, or posting temporarily and no longer than 30 days from the date of the oral statement, unless a written statement as described in paragraph (a) is submitted during that time. Legal requirement — §164.412. Only if HIPAA applies. This page does not find that a delay applies. Last verified 8 September 2026. Not legal advice.

HIPAA does not discharge state notice, and state notice does not discharge HIPAA

HIPAA Subpart D is not Cal. Civ. Code §1798.82. It is not Form 8-K Item 1.05. Filing one does not discharge the others. That is a strategy note, not a determination that any named instrument applies to YOU. Last verified 8 September 2026. Not legal advice.

  • The US-state-laws guide on this site is the representative high-variance comparison of state individual, attorney-general, and credit-bureau notice. State breach-notification laws do not discharge HIPAA. HIPAA does not discharge state AG or individual notice.
  • HIPAA is not Cal. Civ. Code §1798.82. §1798.82 is a California customer-records breach-notification statute. Do not paste 60 calendar days from HIPAA discovery onto California's 30 calendar days from discovery or notification, and do not paste California's 30 calendar days onto §164.404.
  • SEC Form 8-K Item 1.05 does not discharge HIPAA. Item 1.05 is a registrant material-cybersecurity-incident disclosure. Clock-start there is a materiality determination, not HIPAA discovery. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106.
  • GDPR Article 33(1) 'having become aware' is not HIPAA discovery. The GDPR breach-notification guide on this site is Articles 33–34. Do not paste that awareness sentence onto §164.404(a)(2).
  • Civil money penalties for HIPAA administrative-simplification violations sit at 45 CFR 160.404 (amount determined with §§160.406, 160.408, and 160.412; inflation-adjusted figures appear at 45 CFR part 102). Those are maxima and tiers, not typical fines, not an average settlement, and not YOUR penalty. The failure-to-report-consequences page on this site is the maxima table. This page does not invent a typical OCR fine.

Checklist

This is a question list, not a filing, not a four-factor finding, and not YOUR notice. Walk it with counsel. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The supporting-evidence page on this site is the evidentiary record.

  • Are you a covered entity or a business associate as 45 CFR 160.103 defines those terms? This page does not decide. The obligation-map `hipaa` in-scope mark is not that determination.
  • Was there an acquisition, access, use, or disclosure of PHI not permitted under subpart E? Does an exclusion in §164.402(1) apply? Counsel applies those tests. This page does not.
  • If no exclusion, can you demonstrate a low probability that the PHI has been compromised, based on a risk assessment of at least the four factors in §164.402(2)? This page does not run that assessment and does not find low probability on YOUR facts. Burden of proof is §164.414(b).
  • Was the PHI unsecured as §164.402 defines that term, including by reference to the Secretary's encryption-and-destruction guidance? Guidance is guidance. This page does not find that YOUR encryption meets it.
  • Discovery: first day known, or by reasonable diligence would have been known, including workforce-member or agent knowledge other than the person committing the breach. Do not paste GDPR 'became aware' or SEC materiality determination onto that sentence. This page does not start 60 calendar days.
  • Individual notice: §164.404, without unreasonable delay and in no case later than 60 calendar days after discovery, except §164.412. 60 calendar days is not 2 months. Content and method as §164.404(c)–(d) state.
  • Media notice: only if more than 500 residents of a State or jurisdiction — §164.406. Do not paste that trigger onto HHS or individual notice.
  • Secretary notice: 500 or more individuals contemporaneously with individual notice — §164.408(b). Fewer than 500: log, then not later than 60 days after the end of the calendar year — §164.408(c). Those two clocks are not one number. Submit in the manner specified on the HHS Web site. This product does not.
  • If you are a business associate: §164.410 notice to the covered entity. That is not individual, media, or Secretary notice. Do not invert the duties.
  • Do overlapping US-state statutes also sit on the facts? HIPAA does not discharge them. The US-state-laws guide on this site is that representative table.
  • Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Breach§164.402: acquisition, access, use, or disclosure of PHI not permitted under subpart E which compromises the security or privacy of the PHI. Presumed a breach unless an exclusion applies or low probability of compromise is demonstrated.
Four-factor assessment§164.402(2)(i)–(iv): nature and extent (including identifiers and re-identification); unauthorized person; whether actually acquired or viewed; extent of mitigation. This page does not run it.
Unsecured PHI§164.402: PHI not rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified in the Secretary's guidance. The guidance is guidance, not the rule.
Discovery§164.404(a)(2) / §164.410(a)(2): first day known, or by exercising reasonable diligence would have been known, including certain workforce or agent knowledge. Not GDPR 'became aware'. Not SEC materiality determination.
60 calendar daysOuter mark in §164.404(b) (individual), §164.406(b) (media), §164.408(b) via contemporaneous individual notice (HHS 500+), and §164.410(b) (BA to CE). Not 2 months. Not 45 days. Not the <500 HHS year-end clock.
500 or more individuals§164.408(b) HHS contemporaneous notice. Not the media trigger.
Less than 500 individuals§164.408(c) HHS annual log, due not later than 60 days after the end of the calendar year for breaches discovered during the preceding calendar year.
More than 500 residents of a State or jurisdiction§164.406 media notice. Additional to individual notice. Not the HHS 500-or-more-individuals sentence.
Covered entity45 CFR 160.103: health plan; health care clearinghouse; or a health care provider who transmits health information in electronic form in connection with a covered transaction.
Business associate45 CFR 160.103, including a subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate. §164.410: BA notifies the covered entity.
OCR guidanceHHS OCR pages and fact sheets. Not 45 CFR §§164.400–414. This page labels them when it relies on them.

Where this shows up in ShipReady Metrics

The signed-in app does not decide that HIPAA applies, does not determine that the organisation is a covered entity or a business associate, does not run the four-factor risk assessment, does not find low probability of compromise, does not start a 60-calendar-day clock, does not start a year-end <500 clock, and does not file with HHS OCR. None of the surfaces below is a §164.404 notice, a §164.406 media notice, a §164.408 Secretary notice, a §164.410 BA notice, or an instruction to submit a filing. The product does not have a HIPAA reporting ladder and does not auto-file to the HHS portal.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a HIPAA clock, not a 60-calendar-day discovery clock, not an OCR submission, and not a four-factor assessment. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.

HIPAA is a bundled framework in the catalog (`hipaa`, labelled HIPAA Security Rule readiness — a starter subset, not the full Privacy, Security, and Breach Notification Rules, and not the Breach Notification Rule as a filing pack). The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that the organization is a covered entity or a business associate, not a determination that HIPAA applies, and not a legal opinion that Subpart D has been triggered. The HIPAA starter control set is crosswalked to canonical controls; it includes procedure-exists rows for §164.404, §164.406, and §164.408. Evidence collection and the evidence-review overlay record control-mapped artifacts for that starter subset. Those rows are not a four-factor assessment, not a §164.404 notice, and not an OCR submission. The cyber risk register lives under Security. None of those surfaces files with HHS OCR, notifies an individual, notifies the media, or starts 60 calendar days.

Primary sources (last verified 8 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

45 CFR Part 164 Subpart D (§§164.400–414) on eCFR (title 45 up to date as of 3 September 2026; Subpart D source 74 FR 42767, 24 August 2009, as amended 78 FR 5695, 25 January 2013) is a legal requirement only if HIPAA applies. §164.402 is the definition of breach, including the four-factor low-probability-of-compromise assessment, and of unsecured PHI. §164.404 is individual notice. §164.406 is media notice. §164.408 is Secretary notice. §164.410 is notification by a business associate. §164.412 is law-enforcement delay. §164.414 is administrative requirements and burden of proof. 45 CFR 160.103 definitions of covered entity and business associate are legal requirements only if they apply. 45 CFR 160.404 is a civil-money-penalty amount schedule of maxima and tiers, not a typical fine; inflation-adjusted figures appear at 45 CFR part 102. HHS OCR Breach Notification Rule overview, Submitting Notice of a Breach to the Secretary, Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals, and Fact Sheet: Ransomware and HIPAA are OCR materials or Secretary guidance, not the rule. The public 500-or-more list this page fetched is ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf (HITECH Act section 13402(e)(4) posting). The US-state-laws guide on this site is the representative high-variance comparison. The GDPR breach-notification guide on this site is Articles 33–34. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. A dedicated Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. Not legal advice.

The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table of clocks. The supporting-evidence page on this site is the evidentiary record. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner.

Frequently asked questions

When must you notify a HIPAA breach?

If the HIPAA Breach Notification Rule applies: the covered entity notifies each affected individual without unreasonable delay and in no case later than 60 calendar days after discovery (§164.404). HHS OCR is contemporaneous with that individual notice if 500 or more individuals (§164.408(b)), or not later than 60 days after the end of the calendar year if fewer than 500 (§164.408(c)). Media notice is a separate more-than-500-residents-of-a-State-or-jurisdiction trigger (§164.406). A business associate notifies the covered entity (§164.410). Last verified 8 September 2026. Not legal advice.

Is this legal advice?

No. It is a HIPAA jurisdiction guide distilled from 45 CFR §§164.400–414 this page fetched on eCFR and from HHS OCR pages labelled as OCR materials or Secretary guidance, not the rule. Whether HIPAA applies, whether you are a covered entity or a business associate, whether a breach of unsecured PHI occurred, whether low probability of compromise is demonstrated, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file with HHS OCR?

No. The signed-in app does not file with HHS OCR, does not send individual or media notices, does not run the four-factor assessment, does not start a 60-calendar-day clock, and does not have a HIPAA reporting ladder. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not a HIPAA clock and not an OCR submission. The obligation map is frameworks marked in-scope, not a determination that the org is a covered entity or a business associate. A named human still submits.

Does a business associate notify individuals, HHS, and the media?

No. §164.410: the business associate notifies the covered entity, without unreasonable delay and in no case later than 60 calendar days after discovery. §§164.404, 164.406, and 164.408 are covered-entity duties to individuals, the media, and the Secretary. Do not invert those duties. A portal how-to sentence that a BA may submit a Secretary report on behalf of a covered entity is OCR materials, not a rewrite of those sections. Not legal advice.

Does HIPAA discharge Cal. Civ. Code §1798.82?

No. HIPAA Subpart D is not Cal. Civ. Code §1798.82. State breach-notification laws do not discharge HIPAA, and HIPAA does not discharge state AG or individual notice. SEC Form 8-K Item 1.05 does not discharge HIPAA. Filing one instrument is not filing the others. That is a strategy note, not a determination that any named statute applies to YOU. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.