The Breach Notification Rule in plain English

Every section of the Breach Notification Rule, 164.400 through 164.414, translated line by line: what counts as a breach, the four-factor test, the 60-day clocks, and who must be told what.

Last verified: 2026-07-12

This is a plain-language translation of the HIPAA Breach Notification Rule, keeping the same section headings and outline structure as the official text with simplified wording. It is a study aid, not the law itself; for the exact binding language, use the linked eCFR text, which is the authority everywhere this page and the regulation could be read differently.

One orientation note before the sections. This rule fires only on breaches of unsecured PHI, and unsecured has a precise meaning defined below. Data properly encrypted to the standards in HHS guidance is not unsecured, which is why one technical decision changes whether this entire rule ever applies to your bad day.

164.400 Applicability

This subpart applies to breaches of protected health information occurring on or after September 23, 2009.

164.402 Definitions

Breach. Acquiring, accessing, using, or disclosing PHI in a way the Privacy Rule does not permit, where that compromises the security or privacy of the PHI.

Three situations do NOT count as a breach:

  1. A workforce member or person acting under your authority unintentionally acquires, accesses, or uses PHI in good faith, within their job, and does not further use or disclose it improperly.
  2. A person authorized to access PHI accidentally discloses it to another authorized person at the same covered entity, business associate, or organized health care arrangement, and it is not further used or disclosed improperly.
  3. You have a good faith belief that the unauthorized person who received the PHI would not reasonably have been able to retain it.

Otherwise, an impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the PHI was compromised, based on a risk assessment weighing at least these four factors:

  1. What PHI was involved: the types of identifiers, and how likely re-identification is;
  2. Who the unauthorized person was that used the PHI or received the disclosure;
  3. Whether the PHI was actually acquired or viewed; and
  4. The extent to which the risk to the PHI has been mitigated.

The presumption is the part people miss. You do not get to assume an incident was harmless; you either notify, or you document the four-factor assessment that shows low probability of compromise. Silence with no assessment is not one of the options.

Unsecured protected health information. PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified by the Secretary in guidance. In practice: PHI that is not encrypted to the specified standards or destroyed.

“You do not get to assume an incident was harmless; you either notify, or you document the four-factor assessment that shows low probability of compromise.”

164.404 Notifying the individuals

(a) General rule. After discovering a breach of unsecured PHI, you must notify each individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed in the breach.

When a breach counts as discovered. On the first day the breach is known to anyone in your organization other than the person who committed it, or would have been known by exercising reasonable diligence. Your clock does not wait for the right person to find out.

(b) Timing. Notify without unreasonable delay, and in no case later than 60 calendar days after discovery. The 60 days is the outer limit, not the target; if you could reasonably notify sooner, unreasonable delay is itself a violation.

(c) What the notice must say. In plain language, and to the extent possible:

  1. A brief description of what happened, including the date of the breach and the date of discovery, if known;
  2. The types of unsecured PHI involved (name, Social Security number, date of birth, address, account number, diagnosis, and so on);
  3. Steps individuals should take to protect themselves from potential harm;
  4. A brief description of what you are doing to investigate, mitigate harm, and prevent further breaches; and
  5. Contact procedures for questions: a toll-free number, email address, website, or postal address.

(d) How to deliver it.

  1. Written notice, by first-class mail to the last known address, or by email if the individual agreed to electronic notice and has not withdrawn that agreement. If you know the individual is deceased and have an address for the next of kin or personal representative, the notice goes there.
  2. Substitute notice, when contact information is insufficient or out of date. For fewer than 10 such individuals: an alternative form of written notice, telephone, or other means. For 10 or more: either a conspicuous posting on your website home page for 90 days or conspicuous notice in major print or broadcast media where the affected individuals likely reside, plus a toll-free number, active at least 90 days, where people can learn whether their information was involved.
  3. Urgent situations. If misuse of the PHI may be imminent, you may also notify by telephone or other means, in addition to, not instead of, the written notice.

164.406 Notifying the media

For a breach involving more than 500 residents of a single state or jurisdiction, you must notify prominent media outlets serving that state or jurisdiction. Same clock as individual notice: without unreasonable delay, no later than 60 calendar days after discovery. The content requirements are the same as the individual notice.

164.408 Notifying the Secretary (HHS)

500 or more individuals: notify HHS contemporaneously with the individual notices, in the manner specified on the HHS website.

Fewer than 500 individuals: keep a log of these breaches and submit them to HHS within 60 days after the end of the calendar year in which they were discovered, in the manner specified on the HHS website.

The under-500 annual log is the provision small clinics forget. A five-record breach in March still gets reported; it just gets reported by the deadline early the following year rather than immediately.

164.410 Notification by a business associate

(a) General rule. After discovering a breach of unsecured PHI, a business associate must notify the covered entity. Discovery works the same way: first day known, or knowable with reasonable diligence, by any employee, officer, or agent of the business associate other than the person who committed the breach.

(b) Timing. Without unreasonable delay, and no later than 60 calendar days after discovery.

(c) Content. To the extent possible, the identity of each individual whose PHI was or is reasonably believed to have been involved, plus any other information the covered entity needs for its own notices, provided at the time of the notification or promptly as it becomes available.

Note what this section does and does not do. The business associate’s duty runs to you, not to your families; the individual, media, and HHS notices remain your obligations, on your clock. This is why your business associate agreements should set a reporting deadline much shorter than 60 days: your vendor’s day 59 report leaves you one day of your own 60.

164.412 Law enforcement delay

If a law enforcement official states that a required notification would impede a criminal investigation or damage national security:

(a) If the statement is in writing and specifies the time needed, delay the notification for that period.

(b) If the statement is oral, document it, including the identity of the official, and delay no more than 30 days from the oral statement, unless a written statement arrives during that time.

164.414 Administrative requirements and burden of proof

(a) The Privacy Rule’s administrative machinery applies to this rule too: training, complaint procedures, sanctions, no retaliation, no waiver of rights, policies and procedures, and documentation, per the referenced provisions of 164.530.

(b) Burden of proof. In the event of an impermissible use or disclosure, the covered entity or business associate carries the burden of demonstrating either that all required notifications were made, or that the use or disclosure did not constitute a breach as defined at 164.402.

This last sentence is the quiet spine of the whole rule. You are not presumed compliant; you must be able to prove it, which means the four-factor risk assessments you performed, the notices you sent, and the dates of all of it live in your documentation for the day someone asks.

The short version

  • This rule fires only on breaches of unsecured PHI; properly encrypted data is outside it.
  • An impermissible use or disclosure is presumed a breach unless a documented four-factor assessment shows low probability of compromise.
  • Individuals: 60 days from discovery, and discovery runs on what you should have known.
  • Over 500 in one state adds media notice; under 500 goes in an annual log to HHS.
  • The burden of proof is yours: keep the assessments, the notices, and the dates.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

The clock starts before you notice.

Breach discovery runs on what you should have known, not what you happened to see. WiseUpHIPAA tracks the obligations, the deadlines, and the evidence trail from the moment something goes wrong, honestly, while the clock is still your friend.