EnglishEspañol

Reporting HIPAA Breaches: Requirements, Timelines, and Process (2026)

By Recording Law Editorial TeamReviewed August 8, 202613 min read
Reporting HIPAA Breaches: Requirements, Timelines, and Process (2026)

Frequently Asked Questions

How quickly does a covered entity need to report a HIPAA breach?

Under 45 CFR 164.404, a covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. For breaches affecting 500 or more individuals, notification to HHS must also occur within 60 days; breaches affecting more than 500 residents of a single state or jurisdiction also require media notification within that timeframe. Breaches affecting fewer than 500 individuals are reported to HHS annually, within 60 days of the end of the calendar year.

What is the HHS Breach Portal (Wall of Shame)?

The HHS Breach Portal is an online database maintained by the Office for Civil Rights where all reported breaches affecting 500 or more individuals are publicly listed. The database includes the covered entity's name, breach type, number of individuals affected, and a summary of the incident. OCR investigates every breach reported through this portal.

Can a covered entity avoid reporting a breach if it was accidental?

Not automatically. HIPAA provides three narrow exceptions for unintentional workforce access (made in good faith and within scope of authority), inadvertent disclosure between authorized persons at the same entity, and disclosures where the recipient could not reasonably retain the information. Outside these exceptions, the covered entity must conduct a four-factor risk assessment to determine whether the incident is reportable.

Are business associates required to report breaches directly to affected individuals?

No. Under 45 CFR 164.410, a business associate that discovers a breach must notify the covered entity within 60 days. The covered entity then handles notification to individuals, HHS, and the media. However, business associates are directly liable under HIPAA for failing to notify the covered entity, and many business associate agreements impose stricter contractual deadlines.

What are the penalties for failing to report a HIPAA breach?

Civil monetary penalties range from $100 to $50,000 per violation for unknowing violations, up to a minimum of $50,000 per violation for willful neglect not corrected within 30 days. Each violation category has an annual cap of $1,500,000. Criminal penalties under 42 U.S.C. 1320d-6 can reach $250,000 in fines and up to 10 years of imprisonment for the most serious offenses.

Updates

Governing law re-checked for recent changes

Corrected two breach-notification claims: acknowledged the 45 CFR 164.412 law-enforcement delay exception to the 60-day notification deadline, and fixed the media-notification threshold from '500' to 'more than 500' residents to match 45 CFR 164.406 everywhere the figure appeared.

Governing law re-checked for recent changes

Sources and References

  1. 45 CFR 164.402 - Definitions (Breach)(law.cornell.edu)
  2. 45 CFR 164.404 - Notification to Individuals(law.cornell.edu)
  3. 45 CFR 164.406 - Notification to the Media(law.cornell.edu)
  4. 45 CFR 164.408 - Notification to the Secretary(law.cornell.edu)
  5. 45 CFR 164.410 - Notification by a Business Associate(law.cornell.edu)
  6. 45 CFR 160.404 - Amount of a Civil Money Penalty(law.cornell.edu)
  7. HHS Breach Notification Rule Overview(hhs.gov).gov
  8. HHS - Submitting Notice of a Breach to the Secretary(hhs.gov).gov
  9. HHS - Filing a Health Information Privacy Complaint(hhs.gov).gov
  10. HHS - 2024 HIPAA Accomplishments and Wrap-Up(hhs.gov).gov
  11. HHS - State Attorneys General Enforcement Authority(hhs.gov).gov
  12. HHS - HIPAA Enforcement Rule(hhs.gov).gov
Share: