When Exposure of Health Information Must Be Reported
An impermissible use or disclosure is presumed to be a reportable breach. The presumption can be rebutted, but only by a documented assessment against four defined factors, and the clock for notifying everyone who must be told runs from discovery rather than from the conclusion of that assessment.

The rule in short
An acquisition, access, use or disclosure of protected health information not permitted by the privacy rule is presumed a breach unless the entity documents a low probability of compromise using four factors: the nature of the information, who received it, whether it was actually acquired or viewed, and the extent of mitigation. Individual notice is due no later than sixty calendar days after discovery, with separate media and federal tiers keyed to the number affected.
Start from the presumption. An acquisition, access, use or disclosure of protected health information in a manner not permitted by the privacy rule is a breach, and the entity carries the burden of demonstrating otherwise. Nothing needs to be proven before the obligation attaches. The work is in rebutting it, and the rebuttal has to be written down.
Three things that are not breaches at all
Before the assessment, check the exclusions. An unintentional acquisition or use by a workforce member acting in good faith within the scope of authority is excluded, provided no further impermissible use follows. An inadvertent disclosure between two people both authorized to access information at the same entity is excluded on the same condition. And a disclosure is excluded where the entity has a good faith belief that the unauthorized recipient would not reasonably have been able to retain the information.
Separately, the whole framework reaches only unsecured information. Information encrypted to the specified standard, or destroyed so that it cannot be reconstructed, is not unsecured, and its exposure is not reportable under this rule at all. That is the single most valuable control an organization can implement, because it removes the question rather than answering it.
The four factors and how they are weighed
Where no exclusion applies, the presumption stands unless the entity demonstrates a low probability that the information was compromised. Four factors are assessed at minimum. First, the nature and extent of the information, including the types of identifier and the likelihood of re-identification. Second, the unauthorized person who used it or received it. Third, whether the information was actually acquired or viewed. Fourth, the extent to which the risk has been mitigated.
Each factor is evaluated and the conclusion rests on the combination. A disclosure of names and appointment times to another covered entity that returned the file unopened reads differently from a disclosure of diagnoses and account numbers to an unknown recipient. The standard is low probability of compromise, not certainty of harm, and an assessment that reasons toward no harm without addressing all four factors is not a defense.
The sixty days run from discovery, not from the completion of the risk assessment. An organization that spends fifty days investigating has ten days left to draft, print and mail, and substitute notice arrangements take longer than that. Build the assessment on a schedule that leaves room, and treat any incident still unresolved at the halfway mark as one that will be notified.
The three notification tiers
Individual notice comes first and applies to every breach regardless of size. It goes out without unreasonable delay and in no case later than sixty calendar days after discovery, by first-class mail to the last known address, or by email where the individual has agreed to electronic notice. Where contact information is insufficient or out of date, substitute notice is required, and its form depends on how many individuals cannot be reached.
Media notice attaches where a breach affects more than five hundred residents of a state or jurisdiction. Notice goes to prominent media outlets serving that area, on the same timetable as individual notice. Federal notice runs on two tracks: a breach affecting five hundred or more individuals is reported contemporaneously with individual notice, and smaller breaches are logged and submitted within sixty days after the end of the calendar year in which they were discovered.
| Obligation | Who is notified | Trigger | Outer deadline | Method |
|---|---|---|---|---|
| Individual notice | Each affected individual | Any breach of unsecured information | Sixty days from discovery | First-class mail, or email by prior agreement |
| Substitute notice | Individuals who cannot be reached | Insufficient or out-of-date contact information | Same as individual notice | Alternative written form, or web posting and toll-free line where ten or more are affected |
| Media notice | Prominent outlets in the jurisdiction | More than five hundred residents of one state affected | Sixty days from discovery | Press release or equivalent |
| Federal notice, large breach | The federal enforcement agency | Five hundred or more individuals affected | Contemporaneous with individual notice | Electronic submission |
| Federal notice, small breach | The federal enforcement agency | Fewer than five hundred individuals affected | Sixty days after the calendar year ends | Annual log submission |
| Upward report | The covered entity | Breach at a business associate | Sixty days from discovery by the associate | As specified in the written agreement |
Breaches that begin downstream
A business associate that discovers a breach reports it to the covered entity without unreasonable delay and no later than sixty days after discovery, identifying the individuals affected so far as known. The covered entity's own sixty-day clock is what governs individual notice, so a vendor that uses the full period leaves the entity with none. Contracts routinely shorten the vendor deadline for that reason, and the mechanics sit in the treatment of business associate agreements and downstream liability.
Whether the underlying event was impermissible at all is answered by the analysis of the permitted uses of health information. A disclosure inside one of those permissions is not a breach, however alarming it looks. The reporting reflex here parallels the environmental rules on spill and release reporting: a short fixed window, running from awareness rather than from confirmation.
Enforcement exposure after the notice goes out
Civil money penalties are graded by culpability, from a violation the entity did not know of and would not have known of with reasonable diligence, through reasonable cause, to willful neglect corrected within thirty days, to willful neglect not corrected. The ranges are set by regulation and are adjusted for inflation on a recurring basis, so the operative figures should be read from the current penalty provision rather than from memory.
Large breaches attract an enforcement review almost automatically, and reviews frequently end in a settlement with an obligation to remediate under supervision. What that obligation looks like in practice is set out in the discussion of corrective action plans and integrity agreements. The variable that most reliably reduces exposure is whether the entity had performed and documented a risk analysis before the incident, not after it.
Points to carry away
- An impermissible disclosure is presumed a breach; the entity carries the burden of showing otherwise.
- The rebuttal rests on four defined factors and must be documented as a written risk assessment.
- Individual notice is due no later than sixty calendar days after discovery of the breach.
- A breach affecting five hundred or more individuals triggers media notice and contemporaneous federal notice.
- Smaller breaches are logged and reported after the end of the calendar year in which they were discovered.
- Properly encrypted or destroyed information falls outside the definition of unsecured information entirely.
Questions readers ask
When is a breach treated as discovered?
On the first day the breach is known to the entity, or by exercising reasonable diligence would have been known, counting the knowledge of any workforce member or agent other than the person who committed the breach. That construction matters. A help desk ticket describing the incident starts the clock even if it sits unread for weeks, and an entity cannot extend the deadline by routing incidents slowly. Diligence is measured against what a reasonable entity in the same position would have detected.
What must the notice actually say?
Five elements, in plain language: a brief description of what happened including the date range where known, the types of information involved, the steps individuals should take to protect themselves, what the entity is doing to investigate and mitigate, and contact procedures including a toll-free number, an email address, a website or a postal address. Notices that describe the incident but omit the protective steps or the contact route are incomplete, and incompleteness is itself a violation separate from the underlying exposure.
Can notification be postponed at the request of investigators?
Yes, in defined terms. Where a law enforcement official states that notification would impede a criminal investigation or damage national security, the entity delays for the period specified. If the statement is in writing and specifies a time period, the entity delays for that period. If the statement is oral, the entity documents it, including the identity of the official, and delays no longer than thirty days unless a written statement follows. The delay does not otherwise change any deadline.
Sources
- eCFR — 45 CFR 164.402, DefinitionsThe definition of breach, the three exclusions and the four-factor assessment.
- eCFR — 45 CFR 164.404, Notification to IndividualsThe sixty-day outer limit, the required content and substitute notice.
- eCFR — 45 CFR 164.408, Notification to the SecretaryThe five hundred individual threshold and the annual log for smaller breaches.
- eCFR — 45 CFR 164.410, Notification by a Business AssociateWhat a business associate must report upward and how quickly.
- eCFR — 45 CFR Part 164 Subpart D, Notification in the Case of Breach of Unsecured Protected Health InformationThe full notification subpart including media notice and law enforcement delay.
- eCFR — 45 CFR 160.404, Amount of a Civil Money PenaltyThe culpability tiers and how the penalty range is set and adjusted.
Lawwise is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Healthcare Regulation
Using Health Information Without Written Authorization
A covered entity may use or disclose protected health information without authorization to the individual, for treatment, payment and health care operations, under an opportunity to agree or object, and for an enumerated set of public interest purposes. Everything outside that list requires a written authorization, and psychotherapy notes, marketing and any sale of information require one regardless. Permitted disclosures are separately limited to the minimum necessary to accomplish the purpose.
The Self-Referral Prohibition and the Exceptions to It
Where a physician or an immediate family member holds an ownership interest in or a compensation arrangement with an entity, the physician may not refer designated health services to that entity for federal payment and the entity may not present a claim for them, unless the arrangement satisfies an exception in full. Liability does not depend on intent. Amounts collected on prohibited referrals must be refunded, and knowing violations carry additional penalties.
Provider Enrollment, Revalidation and Revocation
Enrollment establishes the effective date from which claims may be paid, and certain practitioner types may bill retrospectively for up to thirty days before it. Enrollment must be revalidated every five years, or every three for equipment suppliers, and a revalidation request must be answered within sixty calendar days. Revocation carries a reenrollment bar of one to ten years, extended to twenty for a second revocation, and it takes effect thirty days after the notice is mailed.


