Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.
If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.
Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.
Crucial Exception: Individual Notifications
While federal government reporting can wait until the end of the year, individual patient notifications cannot.
You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.
What Must Be Included in a HIPAA Breach Notification?
To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:
- A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
- Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
- Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
- Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
- Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.
Ensure Your Practice is Fully HIPAA Compliant
Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.
Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.
- Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
- Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
- Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.