HIPAAmart

Incident response · 7 min read

Breach Notification Rule

Know when an impermissible use or disclosure may be a breach, who must be notified, and what documentation supports the decision.

Reviewed August 2026

Definition

The Breach Notification Rule requires covered entities and business associates to provide notifications following a breach of unsecured protected health information, subject to defined exceptions.

In practice

  • A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.

Who this applies to

  • Covered entities
  • Business associates
  • Individuals affected by a breach
  • HHS and, for certain breaches, prominent media outlets

What the rule asks for

  • Conduct and document a risk assessment following a suspected impermissible use or disclosure.
  • Notify affected individuals without unreasonable delay and within the applicable time limit.
  • Business associates must notify the covered entity according to the BAA and applicable rule requirements.
  • Retain documentation supporting the investigation, risk assessment, and notifications.

How teams put it into practice

  • Define an incident intake path that preserves facts, timestamps, and decision owners.
  • Use a repeatable four-factor risk assessment and document why an exception does or does not apply.
  • Exercise notification workflows with legal, privacy, security, communications, and executive stakeholders.

Common mistakes

  • Waiting to investigate because an event was initially described as a cybersecurity issue.
  • Failing to preserve evidence and decision rationale.
  • Treating a vendor incident as the vendor's issue rather than coordinating under the BAA.

Questions that come up

Is every impermissible disclosure a reportable breach?

Not necessarily. The organization must evaluate the circumstances and applicable exceptions, including the required risk assessment for many incidents.

References