What are the HIPAA breach notification deadlines?
Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more residents of a state also require media notice and notice to the Secretary within the same 60 days; smaller breaches are reported annually.
The answer differs between the federal level and the states, see the rows below.
The answer by level
Federal level
Notice to affected individuals goes out without unreasonable delay and no later than 60 calendar days after discovery of the breach.
45 CFR §§ 164.400 to 164.414Sector rule
A breach affecting 500 or more residents of a state also requires notice to prominent media and to the Secretary within the same 60 days. Smaller breaches are logged and reported annually within 60 days after the calendar year ends.
HHS Breach Portal, notification to the SecretaryEnforcement
The Security Rule requires the administrative, physical and technical safeguards that the breach analysis is measured against.
45 CFR Part 164, Subpart C
Source lines
- The Breach Notification Rule sets discovery as the day the breach is known, or would have been known with reasonable diligence, to any workforce member.
- An impermissible use or disclosure is presumed a breach unless a four factor risk assessment shows a low probability that protected health information was compromised.
- Business associates notify the covered entity without unreasonable delay and no later than 60 days after discovery.
What it means for the company
The deadline is a ceiling, not a target. The presumption of breach means the burden sits with the covered entity to document the risk assessment that avoided notification.
| Level | Requirement | Source |
|---|---|---|
| Federal level | Notice to affected individuals goes out without unreasonable delay and no later than 60 calendar days after discovery of the breach. | 45 CFR §§ 164.400 to 164.414 |
| Sector rule | A breach affecting 500 or more residents of a state also requires notice to prominent media and to the Secretary within the same 60 days. Smaller breaches are logged and reported annually within 60 days after the calendar year ends. | HHS Breach Portal, notification to the Secretary |
| Enforcement | The Security Rule requires the administrative, physical and technical safeguards that the breach analysis is measured against. | 45 CFR Part 164, Subpart C |
What it means for the individual
Patients receive a written notice describing what happened, what information was involved and what steps they can take. The public breach portal lists incidents of 500 or more.
Source lines
- HIPAA Security Rule45 CFR Part 164, Subpart C · read 2026-08-25 · proof 706c242466335fce
- Electronic Code of Federal Regulations45 CFR §§ 164.400 to 164.414 · read 2026-08-25 · proof 706c242466335fceOfficial source
- U.S. Department of Health and Human Services, Office for Civil RightsHHS Breach Portal, notification to the Secretary · read 2026-08-25 · proof 706c242466335fceOfficial source
Next step
Record the discovery date for every reported event and run the four factor assessment in writing before deciding not to notify.
This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.