Build my kit
Free tool

HIPAA breach notification deadline calculator

Enter the date a breach was discovered and how many people it affects. The calculator lists who must be told and the latest date the rules allow. Nothing you type leaves your browser.

Free preview before you pay. Editable Word files. 14 day refund.

The breach

The discovery date is the first day anyone in the practice, other than the person who caused it, knew about the breach, or would have known with reasonable diligence.

Enter the date the breach was discovered.

These are the latest dates the federal rules and the California facility rule allow. Notice is due without unreasonable delay, so sooner is expected. A law enforcement request can delay notice, and some states set shorter deadlines of their own.

What counts as a breach

A breach is the acquisition, access, use, or disclosure of protected health information in a way the Privacy Rule does not permit, which compromises its security or privacy. An impermissible use or disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised. The assessment weighs four factors:

Encryption changes everything

If the information was encrypted to the standard in HHS guidance and the key was not also taken, it is not unsecured information, and the notification rules do not apply. That is the strongest practical argument for encrypting every laptop and phone in the practice.

When the clock starts

A breach is treated as discovered on the first day it is known to anyone in the workforce, other than the person who caused it, or the first day it would have been known with reasonable diligence. Knowledge of a workforce member or agent counts as knowledge of the practice, so a front desk employee who notices a problem starts the clock.

What the notice to individuals must say

Send it by first class mail, or by email if the person has agreed to email notice. If you cannot reach 10 or more people, substitute notice is required, such as a notice on your website for 90 days or in major print or broadcast media, with a toll free number that works for at least 90 days.

Business associates

A vendor that discovers a breach must tell the practice without unreasonable delay and no later than 60 days after discovery, identifying each affected person where it can. Many business associate agreements set a shorter deadline, so check yours. The practice stays responsible for notifying individuals and HHS, though it can agree for the vendor to send the notices.

Keep the paperwork

The practice has the burden of showing that every required notice was made, or that an incident was not a breach. Keep the risk assessment, copies of notices, and the breach log for six years.

Questions

How long do you have to report a HIPAA breach?

Individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more people go to HHS within the same 60 days; smaller ones are reported to HHS within 60 days after the end of the calendar year.

Is a lost laptop a HIPAA breach?

If it held patient information that was not encrypted to the HHS standard, it is presumed to be a breach unless a risk assessment shows a low probability of compromise. If it was properly encrypted and the key was not lost with it, it is generally not a reportable breach.

Do small breaches have to be reported?

Yes. Breaches affecting fewer than 500 people still require notice to each individual, and must be reported to HHS within 60 days after the end of the calendar year.

Does the calculator store what I enter?

No. It runs entirely in your browser and sends nothing to us.

More guides

Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.