{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-08",
    "fingerprint": "ewai:se:eb6e10",
    "proof": "sha256:897f10528bd34ddfd18923c8866f4a963bfca7e4731018ad6ec766d0344d776b",
    "jurisdiction": "se",
    "lang": "en"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "package",
  "object_id": "package:us:hipaa-art-164-408-covered-entity",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/package",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity",
  "source": "NovaCopilot",
  "item": {
    "question": "What must a covered-entity do under HIPAA art. 164.408?",
    "answer": "Covered-entity must notify the Secretary of HHS of breaches of unsecured protected health information within 60 days, reporting to Secretary of Health and Human Services (45 CFR 164.408 (HIPAA Breach Notification Rule)).",
    "obligation": "obligation:us:hipaa-art-164-408-covered-entity",
    "exceptions": [],
    "deadline": "60 days",
    "timeline": {
      "in_application": false,
      "next_milestone": null,
      "relative_deadlines": [
        "60 days",
        "60 days",
        "60 days",
        "60 days"
      ]
    },
    "source": {
      "title": "45 CFR 164.408 (HIPAA Breach Notification Rule)",
      "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D"
    },
    "contract": "frozen_core_v1",
    "frozen_fields": [
      "question",
      "answer",
      "obligation",
      "exceptions",
      "deadline",
      "timeline",
      "source"
    ],
    "risk_level": "medium",
    "risk_reason": "Breach of 45 CFR 164.408 (HIPAA Breach Notification Rule): Notify the Secretary of HHS of breaches of unsecured protected health information.",
    "risk_consequence": "civil_penalty up to USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3) (HHS Office for Civil Rights)",
    "risk_source": {
      "provision": "42 U.S.C. § 1320d-5",
      "authority": "HHS Office for Civil Rights",
      "url": "https://www.law.cornell.edu/uscode/text/42/1320d-5"
    },
    "verification_state": "verified",
    "verified_at": "2026-08-31",
    "verified_sources": [
      "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D",
      "https://www.law.cornell.edu/uscode/text/42/1320d-5"
    ],
    "note": null,
    "related_packages": [
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-404-covered-entity",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-406-covered-entity",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-410-business-associate",
      "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-308-covered-entity"
    ],
    "related_obligations": [
      "obligation:us:hipaa-art-164-404-covered-entity",
      "obligation:us:hipaa-art-164-406-covered-entity",
      "obligation:us:hipaa-art-164-410-business-associate",
      "obligation:us:hipaa-art-164-308-covered-entity"
    ],
    "related_exemptions": [],
    "related_cases": [
      "us:iowa-25-2197-2026-10-02",
      "us:calctapp-e086667m-2026-09-23",
      "us:txctapp10-10-24-00353-cv-2026-09-17"
    ],
    "related_authorities": [
      "HHS Office for Civil Rights"
    ],
    "related_statistics": [
      "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
      "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa"
    ],
    "last_changed": "2026-10-08",
    "change_type": "new_package",
    "change_reason": "First publication of the package.",
    "previous_hash": null,
    "precedent_strength": "strong",
    "leading_cases": [
      "us:iowa-25-2197-2026-10-02",
      "us:calctapp-e086667m-2026-09-23",
      "us:txctapp10-10-24-00353-cv-2026-09-17"
    ],
    "contradicting_cases": [],
    "basis": "18 judgments in the register for hipaa.",
    "token_estimate": 170,
    "retrieval_equivalent_tokens_saved": 20830,
    "estimated_source_documents": 6,
    "method": "token_estimate = characters/4 of the frozen core. Retrieval equivalent: provision 1200, judgment 6000, sanction 600 tokens each.",
    "usable_without_further_analysis": true,
    "gaps": [],
    "generative_output": false,
    "attribution": "Source: NovaCopilot",
    "links": {
      "obligation": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-408-covered-entity",
      "compliance_effect": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-408-covered-entity",
      "exceptions": "https://legal.exploreworldai.com/api/public/v1/obj/exception/us:hipaa-art-164-408-covered-entity",
      "timeline": "https://legal.exploreworldai.com/api/public/v1/obj/timeline/us:hipaa",
      "risk_chain": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity",
      "changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes?type=package",
      "index": "https://legal.exploreworldai.com/api/public/v1/agent-packages"
    },
    "hash": "b87e0efa83cbae68f2f8619e8fe375a3f9a81cf60e77fab5dbd9457f889c32c2"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:hipaa-art-164-408-covered-entity",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa-art-164-408-covered-entity",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa-art-164-408-covered-entity"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "us:hipaa-art-164-408-covered-entity"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=us",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:897f10528bd34ddfd18923c8866f4a963bfca7e4731018ad6ec766d0344d776b",
  "version": "legal-2026-10-08",
  "expires": "2026-10-09T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-08+legal-2026-10-08+2026-10-08T18:37:18",
    "content_hash": "sha256:897f10528bd34ddfd18923c8866f4a963bfca7e4731018ad6ec766d0344d776b",
    "revalidate_after": "2026-10-08T20:02:33.668Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa-art-164-408-covered-entity",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}