The Breach Notification Rule, from the top
A rule built on a presumption and a burden of proof. Why encryption decides whether it applies at all, why the clock starts before you notice, and why an empty incident log is the worst answer you can give.
Last verified: 2026-07-12
Most rules tell you what to do. This one tells you what you must be able to prove, and that difference explains everything about how it is built.
The Breach Notification Rule is short, and it rests on three load-bearing ideas: a scope that encryption can put you outside of, a presumption that runs against you, and a burden of proof that is explicitly yours. Understand those three and the rest is mechanics.
Idea one: it only applies to unsecured PHI
The rule fires on breaches of unsecured protected health information, and unsecured is defined precisely: PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified by the Secretary in guidance (45 CFR 164.402).
HHS specified it (74 FR 19006). In practice it means encryption to the named standards, or destruction. If the data was encrypted properly and the key did not travel with it, the data was not unsecured, and this entire rule, all of its clocks and letters and media notices, does not engage.
Sit with the size of that. One technical decision, made in advance, determines whether the worst administrative day in your clinic’s year happens at all. That is why encryption keeps appearing on this site as the highest-leverage choice a small clinic makes, and why it is genuinely strange that the Security Rule still labels it addressable. The full argument is in the technical safeguards.
Idea two: the presumption runs against you
An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach unless the covered entity demonstrates that there is a low probability that the PHI has been compromised, based on a risk assessment weighing at least four factors (45 CFR 164.402).
The four factors: the nature and extent of the PHI involved, including the identifiers and the likelihood of re-identification; the unauthorized person who used the PHI or to whom the disclosure was made; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated.
Notice the direction of the presumption. The default answer is breach. Silence is not neutrality; silence is a breach you failed to report. The only way out is a documented assessment that lands honestly at low probability, and “honestly” is doing real work in that sentence, because the assessment is evidence and it will be read by someone who was not hoping.
Three narrow exclusions exist (a workforce member’s good-faith, unintentional access that goes no further; an accidental disclosure between two authorized people inside the organization; and a disclosure the recipient could not reasonably have retained). They are narrow, and each still requires you to document why it applies.
Idea three: the burden of proof is yours
45 CFR 164.414(b) says it outright: in the event of a use or disclosure not permitted by the Privacy Rule, the covered entity or business associate has the burden of demonstrating that all required notifications were provided, or that the use or disclosure did not constitute a breach.
The rule does not ask whether you had a breach. It asks whether you can prove you did not.
That single sentence rearranges what your incident process is for. It is not a formality; it is your evidence file. The four-factor assessments you performed, the notices you sent, the dates on all of it, kept six years. A clinic that handled an incident perfectly and wrote nothing down is, under this rule, indistinguishable from a clinic that ignored it.
“The rule does not ask whether you had a breach. It asks whether you can prove you did not”
The mechanics, briefly
Discovery is the trigger, and it is defined generously against you: the first day the breach is known to anyone in your organization other than the person who caused it, or would have been known by exercising reasonable diligence (45 CFR 164.404(a)(2)). Not the day the owner heard. Not the day the investigation finished. A clinic that never looks cannot claim it never knew.
Individuals: without unreasonable delay, and no later than 60 calendar days from discovery (45 CFR 164.404(b)). Sixty is a ceiling, not a target, and sitting on a clear-cut breach until day 59 is itself a violation of the without-unreasonable-delay standard.
HHS: contemporaneously with the individual notices if 500 or more people are affected; otherwise in an annual log submitted within 60 days after the end of the calendar year (45 CFR 164.408). The under-500 annual log is the piece small clinics forget entirely.
Media: only if more than 500 residents of one state or jurisdiction are affected (45 CFR 164.406).
Business associates must notify you, within 60 days of their discovery at the latest (45 CFR 164.410). Their clock is not your clock: your obligations run from your discovery, which is why a vendor reporting on their day 59 leaves you one day of yours. Negotiate that number down in the contract.
What the rule is actually testing
Put the three ideas together and the rule’s real subject becomes clear. It is not testing whether bad things happen at your clinic; bad things happen at every clinic. It is testing whether your organization is the kind that notices, assesses honestly, and keeps the record.
Which is why the most damning artifact a clinic can hand an investigator is an empty incident log. Nothing logged, nothing assessed, nothing closed. No clinic in America goes three years without a misdirected email, a lost device, or a phished credential. An empty log does not read as a clean clinic. It reads as a clinic that never looked, and under a rule built on a presumption and a burden of proof, never looking is the worst possible posture.
The clinic with a log showing four small incidents, each assessed under the four factors, three closed as low probability with reasons and one notified on time, is presenting exactly what the rule was written to reward. That clinic looks competent because it is.
The one thing to do before you need any of this
Encrypt the devices, and write down that you did.
Everything else on this page is procedure you can learn in an afternoon when you need it, and the page for the day you need it is here. But the encryption decision cannot be made retroactively at 9pm when a tablet is missing, and it is the only decision on this page that determines whether the rest of the page applies to you at all.
The short version
- The rule applies only to unsecured PHI. Properly encrypted data is outside it entirely, which makes encryption the single highest-leverage decision in the rule.
- An impermissible use or disclosure is presumed to be a breach. You either notify, or you document a four-factor assessment showing a low probability of compromise.
- Discovery runs on what your organization knew or should have known with reasonable diligence, not on when leadership was told.
- The burden of proof is explicitly yours: you must be able to show either that you notified, or that it was not a breach.
- An empty incident log does not read as a clean clinic. It reads as a clinic that never looked.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Definitions, including breach and unsecured PHI45 CFR 164.402https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
- Notification to individuals45 CFR 164.404https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
- Notification to the media45 CFR 164.406https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.406
- Notification to the Secretary45 CFR 164.408https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.408
- Notification by a business associate45 CFR 164.410https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.410
- Administrative requirements and burden of proof45 CFR 164.414https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.414
- HHS guidance to render unsecured PHI unusable, unreadable, or indecipherable74 FR 19006, April 27, 2009https://www.federalregister.gov/documents/2009/04/27/E9-9512/guidance-specifying-the-technologies-and-methodologies-that-render-protected-health-information
- Security incident procedures45 CFR 164.308(a)(6)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
The proof is the point.
This rule puts the burden on you: prove you notified, or prove it was not a breach. WiseUpHIPAA keeps the incident record, the assessments, and the dates as your clinic operates, so the proof exists before anyone asks for it.