HIPAA BinderGet my forms

Breach Notification Rule

The Breach Notification Rule (45 CFR 164.400–414) requires covered entities to notify affected individuals, HHS, and sometimes the media after a breach of unsecured PHI. Notice to individuals is due without unreasonable delay and no later than 60 days from discovery. It applies to breaches occurring on or after September 23, 2009.

45 CFR §§ 164.400–414Read the regulation on eCFR

Last verified: July 23, 2026

What breach notification rule means under HIPAA

Subpart D of Part 164, sections 164.400 through 414, is the Breach Notification Rule. Section 164.400 sets its scope: the requirements apply to breaches of protected health information occurring on or after September 23, 2009. The heart of the rule is the notification timeline: after discovering a breach of unsecured PHI, a covered entity must notify each affected individual without unreasonable delay and no later than 60 calendar days from discovery.

There are two more notification tracks. Breaches affecting 500 or more residents of a state or jurisdiction also require notice to prominent media in that area, and HHS must be notified, immediately for large breaches and in an annual log for smaller ones. Before any of that, the rule builds in a breach risk assessment: an impermissible use or disclosure is presumed to be a breach unless the entity demonstrates a low probability that PHI was compromised, based on defined factors.

This is the part of the binder you hope never to use, which is exactly why it should be written down in advance. A breach procedure that names who assesses an incident, how you document the risk assessment, the federal deadlines, and your state’s own breach statute (often stricter and faster) turns a stressful event into a checklist. Keep an empty breach log ready alongside it.

Breach Notification Rule FAQ

Related terms

See every term in the HIPAA glossary.

Turn the vocabulary into the documents

Knowing the terms is step one. See the full document set a covered practice keeps, or generate the ones you can build yourself now.

See what goes in a HIPAA binder

Source

Last verified July 23, 2026. This definition is educational self-help information, not legal advice, and it paraphrases the regulation; the controlling text is 45 CFR §§ 164.400–414, linked above. Whether HIPAA applies to your practice depends on the covered-entity test. State law may add stronger requirements.