Blog Post

Common HIPAA Breach Notification Mistakes Healthcare Organizations Make

Richard P. Kusserow | August 2026

Responding to a breach of protected health information (PHI) requires healthcare organizations to make several decisions within a relatively short period of time. Organizations must determine what occurred, assess whether the incident constitutes a reportable breach, identify applicable notification requirements, and provide required notifications within the appropriate time frames. Having established procedures in place before an incident occurs can help organizations meet these requirements.

One common mistake is failing to identify and track the different notification deadlines that may apply following a breach. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured protected health information (PHI). The deadline for notifying the U.S. Department of Health and Human Services (HHS) depends on the number of individuals affected. Breaches affecting 500 or more individuals must be reported to HHS without unreasonable delay and no later than 60 calendar days following discovery. Breaches affecting fewer than 500 individuals may be reported annually, but no later than 60 calendar days after the end of the calendar year in which the breach was discovered.

Organizations should have procedures for identifying applicable deadlines, assigning responsibility for required notifications, and tracking each notification through completion. Organizations should also account for applicable state breach notification requirements, which may impose different or more stringent deadlines.

An impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity or business associate demonstrates that there is a low probability that the PHI has been compromised. When making that determination, the organization must conduct a risk assessment that considers at least four factors:

  1. The nature and extent of the PHI involved, including the types of identifiers and likelihood of re-identification. Consider the specific information involved and the extent to which it could identify an individual.
  2. The unauthorized person who used the PHI or to whom the disclosure was made. Consider who received or accessed the information and whether that person had an obligation to protect its confidentiality.
  3. Whether the PHI was actually acquired or viewed. Determine, to the extent possible, whether the information was actually accessed or whether there was only an opportunity for access.
  4. The extent to which the risk to the PHI was mitigated. Consider the steps taken following the incident and the extent to which those actions reduced the risk that the PHI was compromised.

Organizations should document the risk assessment and the conclusions reached. Covered entities and business associates also have the option of providing the required breach notifications without conducting a risk assessment.

Once an organization determines that notification is required, the content and method of the notification must comply with HIPAA. Individual notices must be written in plain language and, to the extent possible, include a brief description of what happened; the types of PHI involved; steps individuals should take to protect themselves from potential harm; a description of what the covered entity is doing to investigate the breach, mitigate harm, and protect against further breaches; and contact information for individuals who have questions or need additional information.

Covered entities should also confirm that they have current contact information for affected individuals. When contact information is insufficient or out of date, the Breach Notification Rule includes specific requirements for providing substitute notice. Organizations should establish procedures for preparing and reviewing breach notifications to ensure that required information is included before notices are distributed.

Breaches involving business associates can create additional notification and coordination issues. A business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery. To the extent possible, the business associate must also provide information identifying affected individuals and other information needed by the covered entity to provide the required notices.

Business associate agreements and incident response procedures should clearly address how security incidents and potential breaches will be reported, what information must be provided, and which party is responsible for completing required notifications.

Individual notification may not be the only notification required following a breach. For breaches affecting 500 or more individuals, covered entities must also notify HHS without unreasonable delay and no later than 60 calendar days following discovery.

A covered entity must also notify prominent media outlets serving a state or jurisdiction when a breach affects more than 500 residents of that state or jurisdiction. Media notification must be provided without unreasonable delay and no later than 60 calendar days after discovery of the breach. Organizations should determine all applicable notification requirements early in the breach response process rather than addressing each reporting obligation separately as deadlines approach.

Breach response involves both the protection of PHI and the Privacy Rule obligations that arise when information is improperly accessed, used, or disclosed. An effective response therefore depends on more than meeting notification deadlines. Organizations should have established processes for identifying and escalating potential incidents, conducting and documenting breach risk assessments, coordinating with business associates, notifying affected individuals, and completing required regulatory reporting.

A Privacy Program Evaluation can assess whether an organization’s policies, procedures, training, documentation, and breach response practices are consistent with HIPAA requirements and whether responsibilities are clearly understood by those involved in responding to an incident. The evaluation can also identify areas where breach response processes or other components of the Privacy Program may need to be strengthened.

Through privacy and security program evaluation services, Strategic Management can identify gaps, clarify responsibilities, and recommend practical steps to reduce compliance risk before an incident results inleads to regulatory scrutiny. To learn more about Strategic Management’s privacy and security program evaluation services, please connect with us.

About the Author

Richard P. Kusserow established Strategic Management Services, LLC, after retiring from being the DHHS Inspector General, and has assisted over 3,000 health care organizations and entities in developing, implementing and assessing compliance programs.

Subscribe to blog