Covered entities must notify affected individuals without unreasonable delay and within 60 days of discovery, notify HHS annually or within 60 days for breaches affecting 500 or more individuals, and notify media for large breaches in a state or jurisdiction.
A risk assessment determines whether an impermissible use constitutes a reportable breach.
Alternative Names:
HIPAA Breach Notification, PHI Breach Notification
Why it Matters?
The risk assessment is where the analysis concentrates, since an impermissible disclosure is presumed to be a breach unless the entity demonstrates a low probability that the information was compromised. Four specified factors govern that assessment and must be documented. Law firms handling protected health information are business associates with notification obligations to the covered entity, which is separate from any state breach statute obligation.
Frequently Confused with
Related terms
Frequently asked questions
Is every impermissible disclosure a breach?
What are a law firm's obligations?





