US Medical BillingRevenue cycle solutions
Compliance and Regulations

The HIPAA Breach Notification Rule in Medical Billing

The Privacy Rule decides who may use protected health information, and the Security Rule decides how the electronic form of it must be protected. The Breach Notification Rule is the third: it decides what a practice has to do once that information has been exposed anyway. It is the rule a billing operation reaches for on its worst day — after a laptop is stolen, a claim file is emailed to the wrong payer, or a vendor reports an intrusion — and its logic runs in a specific order: decide whether what happened is a breach, and if it is, notify the right people, in time, with the right information.

Updated 14 min read

On this page

Key takeaways

What counts as a breach

The Breach Notification Rule turns on a single defined event. A breach is the acquisition, access, use, or disclosure of protected health information in a manner the Privacy Rule does not permit, which compromises the security or privacy of that information (45 CFR 164.402). That is narrower than it first sounds, and the two qualifiers do real work: the use or disclosure has to be impermissible under the Privacy Rule, and it has to compromise the information. A permitted disclosure — sending a payer the minimum necessary to adjudicate a claim — is not a breach no matter how much data it involves.

The rule also reaches only unsecured PHI — information that has not been rendered unusable, unreadable, or indecipherable to unauthorized people by a technology or methodology the Secretary of HHS has specified, which in practice means encryption to the specified standard or destruction (45 CFR 164.402). This is the rule's one true safe harbor and the reason the HIPAA Security Rule's addressable encryption specification matters so much: a stolen but properly encrypted laptop holds PHI that is not unsecured, so its loss does not trigger the notification duty at all.

Three rules, three jobs

The presumption, and the risk assessment that can rebut it

The most important thing to understand about the rule is where it puts the default. An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach — and therefore notifiable — unless the covered entity or business associate demonstrates that there is a low probability the PHI has been compromised (45 CFR 164.402(2)). The burden runs toward notifying. Silence, or an unrecorded assumption that “it was probably fine,” is not a defense; the entity has to be able to show its work.

That demonstration is made through a risk assessment that weighs at least four factors set out in the rule:

  • The nature and extent of the PHI involved — the kinds of identifiers, and the likelihood the information could be re-identified.
  • The unauthorized person who used the PHI or to whom the disclosure was made.
  • Whether the PHI was actually acquired or viewed, or merely exposed.
  • The extent to which the risk to the PHI has been mitigated — for example, by obtaining the recipient's assurances that it was destroyed or not further used.

Weighed together, those factors either support a conclusion that compromise was unlikely — in which case notification is not required — or they do not, in which case it is. Either way, the analysis and its conclusion have to be documented, because the rule's default is that the incident was a breach.

Three narrow exceptions before the assessment even begins

Who must be notified

Once an incident is a breach of unsecured PHI, a covered entity owes notice to as many as three audiences. Two are always required; the third depends on the size of the breach in a given place.

The three notification audiences under the HIPAA Breach Notification Rule
The three notification audiences under the HIPAA Breach Notification Rule
WhoWhen it is requiredCitation
The affected individualsAlways. Each individual whose unsecured PHI was, or is reasonably believed to have been, accessed, acquired, used, or disclosed in the breach must be notified.45 CFR 164.404
The Secretary of HHSAlways, but on one of two schedules by size: a breach affecting 500 or more individuals is reported to the Secretary contemporaneously with the individual notice; a breach affecting fewer than 500 is entered in a log and reported annually.45 CFR 164.408
Prominent media outletsOnly when a single breach involves more than 500 residents of a State or jurisdiction. Notice goes to prominent media serving that State or jurisdiction and carries the same content as the individual notice.45 CFR 164.406

The media notice is not a press release the practice chooses to issue; above the threshold it is a required notification with defined content, in addition to — not instead of — the individual notice.

The split at the Secretary's office is worth holding onto because it changes the operational cadence. For a large breach, the report to HHS goes out with the individual letters. For a smaller one, the practice keeps a log through the year and submits the breaches discovered in a calendar year no later than 60 days after that year ends (45 CFR 164.408(c)). Both are submitted in the manner specified on the HHS website; “report it annually” does not mean “wait a year to write it down.”

How fast — and why the deadline is not the target

Individual notice must be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach (45 CFR 164.404(b)); the media notice, where required, runs on the same standard (164.406(b)). The clock starts at discovery, which the rule defines as the first day the breach is known to the entity, or by exercising reasonable diligence would have been known (164.404(a)(2)) — not the day someone finally admitted it, and not the day the investigation wrapped up.

'Without unreasonable delay' is the real standard

State law can be stricter — check both

What the notice has to say, and how it is delivered

The individual notice is not a free-form apology. The rule specifies, in plain language, what it must contain (45 CFR 164.404(c)):

  • A brief description of what happened, including the date of the breach and the date it was discovered, if known.
  • A description of the types of unsecured PHI involved — for example that names, Social Security numbers, dates of birth, diagnoses, or claim information were affected — without unnecessarily republishing the data itself.
  • The steps individuals should take to protect themselves from potential harm resulting from the breach.
  • A brief description of what the entity is doing to investigate the breach, mitigate the harm, and protect against further breaches.
  • Contact procedures for individuals to ask questions or learn more — a toll-free number, an email address, a website, or a postal address.

Delivery is generally by first-class mail to the individual's last known address, or by email if the individual has agreed to electronic notice (45 CFR 164.404(d)). Where the practice lacks sufficient or current contact information, the rule provides for substitute notice — an alternative form scaled to how many individuals cannot be reached, up to a posting on the practice's website or notice in major media, with a toll-free number people can call. When there is a possibility of imminent misuse, the practice may also contact individuals urgently by telephone in addition to the written notice.

When a vendor is where it happens

A great deal of a modern billing operation's PHI sits with outside parties — the clearinghouse, the software and hosting vendors, an outsourced billing company or collections agency. When a breach happens there, the business associate does not notify the patients. It notifies the covered entity, without unreasonable delay and in no case later than 60 calendar days after it discovers the breach (45 CFR 164.410). The practice remains the one that owes notice to the individuals, HHS, and any media — so its own clock effectively depends on how fast its vendor tells it.

That dependency is exactly what the business associate agreement exists to control. The vendor's notice must identify the individuals affected to the extent possible and provide the information the practice needs to make its own notifications (45 CFR 164.410(c)). A well-drafted BAA presses the vendor tighter than the federal outer limit — because the practice cannot notify anyone until the vendor has reported up, and every day the vendor waits is a day off the practice's own 60.

Discovery is imputed

The burden of proof, and building the rule into the operation

One provision shapes how a practice should treat every possible breach. If there is a use or disclosure that may require notification, the covered entity or business associate carries the burden of demonstrating either that all required notifications were made, or that the incident was not a breach — for instance, by showing through the risk assessment a low probability that the PHI was compromised (45 CFR 164.414(b)). The entity has to prove it did the right thing; an investigator does not have to prove it did the wrong one.

That is why the documentation is not paperwork after the fact — it is the defense. The rule also applies the administrative machinery of HIPAA to breach notification: written policies and procedures, workforce training, a way to receive complaints, sanctions for violations, and retention of the records, through 45 CFR 164.414(a) and 164.530. For a billing operation, complying comes down to a few durable habits:

  1. Write the incident-response process down before you need it

    Have a policy that says how a suspected breach is reported internally, who runs the risk assessment, and who decides on notification — so discovery does not depend on someone improvising on the worst day (45 CFR 164.414(a), 164.530).
  2. Run and record the four-factor risk assessment every time

    Because an impermissible use or disclosure is presumed to be a breach (45 CFR 164.402(2)), the risk assessment is what rebuts the presumption when compromise really was unlikely — and only if it is written down. Assess and document every incident, including the ones you conclude are not breaches.
  3. Know your notification map in advance

    Individuals always, the Secretary always (contemporaneously above 500, annual log below), media above 500 residents of a State or jurisdiction (45 CFR 164.404, 164.406, 164.408). Knowing the map before an incident is how the 60-day outer limit stays comfortable rather than tight.
  4. Put a breach-reporting deadline in every BAA

    A vendor breach is on the practice's clock. Require prompt notice to the practice, well inside the federal outer limit, and the information the practice needs to notify (45 CFR 164.410) — a term the business associate agreement must carry.
  5. Check state law alongside the federal rule

    State breach-notification laws can be stricter and are not preempted; confirm the requirement for each state where affected individuals live, and treat the tighter deadline as the real one.

The Breach Notification Rule is one piece of the wider set of regulatory duties in the Compliance and Regulations category — it works alongside the Privacy Rule's permission to use PHI for payment and the Security Rule's safeguards that keep a breach from happening. Because the rules are revised and enforcement guidance evolves, a practice's breach-response policy should point to the current regulation and be reviewed when it changes.

Educational, not legal advice

Common questions

Is every impermissible disclosure of PHI a breach?

No. An impermissible acquisition, access, use, or disclosure of unsecured PHI is presumed to be a breach, but the presumption can be rebutted (45 CFR 164.402(2)). If the incident fits one of the three narrow exceptions in the definition — a good-faith within-authority access, an inadvertent disclosure between two authorized people at the same entity, or a disclosure the recipient could not reasonably have retained — it is not a breach. Otherwise, the entity may show through a documented four-factor risk assessment that there is a low probability the PHI was compromised, in which case notification is not required.

We lost an encrypted laptop. Do we have to send breach notices?

Not under the Breach Notification Rule. The rule applies only to unsecured PHI — information not rendered unusable, unreadable, or indecipherable through encryption or destruction to the standard the Secretary of HHS has specified (45 CFR 164.402). PHI that was properly encrypted is not unsecured, so its loss does not trigger the federal notification duty. Confirm the encryption actually met the specified standard, and check any applicable state law, which may define its own safe harbor differently.

How long do we have to notify people?

Individual notice must go out without unreasonable delay and in no case later than 60 calendar days after discovery of the breach (45 CFR 164.404(b)). Discovery is the first day the breach is known, or by reasonable diligence would have been known (164.404(a)(2)). The 60 days is an outer limit, not a target — 'without unreasonable delay' is the operative standard — and many states set shorter deadlines that are not preempted, so the real deadline is the tighter of the federal and state requirements.

When do we have to notify HHS and the media?

The Secretary of HHS is always notified: a breach affecting 500 or more individuals is reported contemporaneously with the individual notice, while a breach affecting fewer than 500 is logged and reported annually, no later than 60 days after the calendar year ends (45 CFR 164.408). Prominent media serving a State or jurisdiction must be notified only when a single breach involves more than 500 residents of that State or jurisdiction (164.406), and that notice carries the same content as the individual notice.

Our billing vendor had the breach. Who notifies the patients?

The covered entity does. A business associate that discovers a breach notifies the covered entity — not the individuals — without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.410), and provides the information the practice needs to make its own notifications. The practice then owes notice to the individuals, HHS, and any required media. Because the practice's clock depends on the vendor, the business associate agreement should require notice well inside the federal limit.

What happens if we decide something was not a breach?

You can reach that conclusion, but you must be able to prove it. The rule places the burden of proof on the covered entity or business associate to demonstrate either that all required notifications were made or that the incident did not constitute a breach (45 CFR 164.414(b)). In practice that means documenting the risk assessment for every incident — including the ones you conclude are not breaches — because an undocumented decision is, to an investigator, indistinguishable from no decision at all.

Authoritative sources

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.