Definition
The Breach Notification Rule requires covered entities and business associates to provide notifications following a breach of unsecured protected health information, subject to defined exceptions.
In practice
- A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.
Who this applies to
- Covered entities
- Business associates
- Individuals affected by a breach
- HHS and, for certain breaches, prominent media outlets
What the rule asks for
- Conduct and document a risk assessment following a suspected impermissible use or disclosure.
- Notify affected individuals without unreasonable delay and within the applicable time limit.
- Business associates must notify the covered entity according to the BAA and applicable rule requirements.
- Retain documentation supporting the investigation, risk assessment, and notifications.
How teams put it into practice
- Define an incident intake path that preserves facts, timestamps, and decision owners.
- Use a repeatable four-factor risk assessment and document why an exception does or does not apply.
- Exercise notification workflows with legal, privacy, security, communications, and executive stakeholders.
Common mistakes
- Waiting to investigate because an event was initially described as a cybersecurity issue.
- Failing to preserve evidence and decision rationale.
- Treating a vendor incident as the vendor's issue rather than coordinating under the BAA.
Questions that come up
Is every impermissible disclosure a reportable breach?
Not necessarily. The organization must evaluate the circumstances and applicable exceptions, including the required risk assessment for many incidents.
References
- Breach Notification Rule U.S. Department of Health & Human Services