HIPAA breach notification deadline calculator
Enter the date a breach was discovered and how many people it affects. The calculator lists who must be told and the latest date the rules allow. Nothing you type leaves your browser.
Free preview before you pay. Editable Word files. 14 day refund.
Enter the date the breach was discovered.
These are the latest dates the federal rules and the California facility rule allow. Notice is due without unreasonable delay, so sooner is expected. A law enforcement request can delay notice, and some states set shorter deadlines of their own.
What counts as a breach
A breach is the acquisition, access, use, or disclosure of protected health information in a way the Privacy Rule does not permit, which compromises its security or privacy. An impermissible use or disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. The assessment weighs four factors:
- What information was involved, including the types of identifiers and how likely it is that someone could be identified
- Who used or received the information without permission
- Whether the information was actually acquired or viewed
- How far the risk has been reduced, for example by getting a written assurance that the information was destroyed
Encryption changes everything
If the information was encrypted to the standard in HHS guidance and the key was not also taken, it is not unsecured information, and the notification rules do not apply. That is the strongest practical argument for encrypting every laptop and phone in the practice.
When the clock starts
A breach is treated as discovered on the first day it is known to anyone in the workforce, other than the person who caused it, or the first day it would have been known with reasonable diligence. Knowledge of a workforce member or agent counts as knowledge of the practice, so a front desk employee who notices a problem starts the clock.
What the notice to individuals must say
Send it by first class mail, or by email if the person has agreed to email notice. If you cannot reach 10 or more people, substitute notice is required, such as a notice on your website for 90 days or in major print or broadcast media, with a toll free number that works for at least 90 days.
- A brief description of what happened, with the date of the breach and the date it was discovered, if known
- The types of information involved, such as names, Social Security numbers, diagnoses, or account numbers
- What individuals should do to protect themselves
- What the practice is doing to investigate, reduce the harm, and prevent a repeat
- How to reach the practice, including a toll free number, an email address, a website, or a postal address
Business associates
A vendor that discovers a breach must tell the practice without unreasonable delay and no later than 60 days after discovery, identifying each affected person where it can. Many business associate agreements set a shorter deadline, so check yours. The practice stays responsible for notifying individuals and HHS, though it can agree for the vendor to send the notices.
Keep the paperwork
The practice has the burden of showing that every required notice was made, or that an incident was not a breach. Keep the risk assessment, copies of notices, and the breach log for six years.
Questions
How long do you have to report a HIPAA breach?
Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more people go to HHS within the same 60 days; smaller ones are reported to HHS within 60 days after the end of the calendar year.
Is a lost laptop a HIPAA breach?
If it held patient information that was not encrypted to the HHS standard, it is presumed to be a breach unless a risk assessment shows a low probability of compromise. If it was properly encrypted and the key was not lost with it, it is generally not a reportable breach.
Do small breaches have to be reported?
Yes. Breaches affecting fewer than 500 people still require notice to each individual, and must be reported to HHS within 60 days after the end of the calendar year.
Does the calculator store what I enter?
No. It runs entirely in your browser and sends nothing to us.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- HIPAA compliance checklist for small medical practices in California
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
- HIPAA business associate agreement: what it must include
- HIPAA compliance checklist for small practices, 2026
- Free HIPAA policy templates: where to get them, and what they leave out
- HIPAA training requirements for small practices
- HIPAA policies for podiatry practices
- HIPAA policies for dermatology practices
- HIPAA policies for pediatric practices
- HIPAA for acupuncture practices
- HIPAA policies for speech therapy practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.