Category: Data Security

  • HIPAA Breach Deadlines for Under 500 Affected People

    Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.

    If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.

    Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.

    Crucial Exception: Individual Notifications

    While federal government reporting can wait until the end of the year, individual patient notifications cannot.

    You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.

    What Must Be Included in a HIPAA Breach Notification?

    To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:

    • A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
    • Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
    • Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
    • Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
    • Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.

    Ensure Your Practice is Fully HIPAA Compliant

    Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.

    Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.

    • Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Office for Civil Rights – Guidance on HIPAA IT Asset Inventories

    On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.

    Here are some helpful sections from the newsletter:

    “The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”

    How to Create an IT Asset Inventory

    “An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโ€™s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:

    • Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโ€™s networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
    • Software assets that are programs and applications that run on an organizationโ€™s electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโ€™s inventory.
    • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”

    As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.

    All these asset inventory lists must be reviewed and confirmed during the risk assessment process.

    Not One and Done

    This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.