News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data Breach

Data Breach

HIPAA Breach Notification Overview

TL;DR

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovering a breach of unsecured PHI. See our complete Breach Notification Rule guide for full coverage of all requirements.

The HIPAA Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovering a breach of unsecured PHI. See our complete Breach Notification Rule guide for full coverage of all requirements.

What to do in the first 60 days after a breach: assess, document, notify individuals and HHS, and avoid the mistakes that turn a breach into a penalty.

medcomply.ai editorial teamPublished May 11, 2026Updated May 11, 20261 min read

The HIPAA Breach Notification Rule requires covered entities and business associates to provide notification when unsecured Protected Health Information is breached.

We have published a complete guide to the HIPAA Breach Notification Rule covering the breach definition, four-factor risk assessment, all notification requirements, and deadlines. Read the full guide for complete coverage.

For complete coverage of all Breach Notification Rule requirements see our full guide: Understanding the HIPAA Breach Notification Rule.

Quick reference

Who must notify: Covered entities notify individuals, HHS, and media. Business associates notify the covered entity.

Deadline: 60 days from date of discovery — not from when your investigation concludes.

Presumption: Any impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a four-factor risk assessment demonstrates low probability of compromise.

Threshold for immediate HHS reporting: 500 or more individuals affected.

Threshold for media notification: 500 or more residents of a state or jurisdiction.

For the complete analysis of each requirement including the four-factor assessment, all notification content requirements, business associate obligations, and state law considerations, see our complete Breach Notification Rule guide.

Sources & citations

  • 45 CFR §§164.400-414 — Breach Notification RuleOpen

All content verified against official HHS guidance and the Code of Federal Regulations.

Frequently asked questions

Where can I find the complete HIPAA breach notification guide?
See our complete guide: Understanding the HIPAA Breach Notification Rule — covering the breach definition, four-factor risk assessment, all notification requirements, and timelines.

Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.