News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

Data Breach

HIPAA Breach Notification Overview

TL;DR

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovering a breach of unsecured PHI. See our complete Breach Notification Rule guide for full coverage of all requirements.

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovering a breach of unsecured PHI. See our complete Breach Notification Rule guide for full coverage of all requirements.

What to do in the first 60 days after a breach: assess, document, notify individuals and HHS, and avoid the mistakes that turn a breach into a penalty.

medcomply.ai editorial teamPublished May 11, 2026Updated May 11, 20261 min read

The HIPAA Breach Notification Rule requires covered entities and business associates to provide notification when unsecured Protected Health Information is breached.

We have published a complete guide to the HIPAA Breach Notification Rule covering the breach definition, four-factor risk assessment, all notification requirements, and deadlines. Read the full guide for complete coverage.

For complete coverage of all Breach Notification Rule requirements see our full guide: Understanding the HIPAA Breach Notification Rule.

Quick reference

Who must notify: Covered entities notify individuals, HHS, and media. Business associates notify the covered entity.

Deadline: 60 days from date of discovery — not from when your investigation concludes.

Presumption: Any impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a four-factor risk assessment demonstrates low probability of compromise.

Threshold for immediate HHS reporting: 500 or more individuals affected.

Threshold for media notification: 500 or more residents of a state or jurisdiction.

For the complete analysis of each requirement including the four-factor assessment, all notification content requirements, business associate obligations, and state law considerations, see our complete Breach Notification Rule guide.

Sources & citations

  • 45 CFR §§164.400-414 — Breach Notification RuleOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

Where can I find the complete HIPAA breach notification guide?
See our complete guide: Understanding the HIPAA Breach Notification Rule — covering the breach definition, four-factor risk assessment, all notification requirements, and timelines.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.