Even well-run practices can experience a data incident — a lost laptop, a misdirected message, a ransomware attack, or unauthorized snooping in the EHR. The HIPAA Breach Notification Rule sets out what must happen when unsecured protected health information is breached. Understanding it in advance lets you respond calmly and correctly.
What counts as a breach
Under the rule, a breach is generally an impermissible use or disclosure of protected health information (PHI) that compromises its security or privacy. The rule presumes such an impermissible use or disclosure is a breach unless the entity demonstrates a low probability that the PHI has been compromised, based on a risk assessment of specified factors.
Who must be notified
- Affected individuals: Notice must be provided to each affected individual without unreasonable delay and within the timeframe the rule specifies.
- HHS: The Secretary of HHS must be notified, with timing that depends on the number of individuals affected.
- The media: For breaches affecting a large number of residents of a state or jurisdiction, media notification may be required.
- Business associates: A business associate that discovers a breach must notify the covered entity.
How your EHR helps
EHR audit logs are central to both detecting and investigating incidents. They record who accessed which records and when, helping you determine whether PHI was actually viewed and the scope of an incident. Strong access controls, encryption, and monitoring reduce the chance of a breach and can affect the risk assessment.
Steps to take now
- Maintain and review EHR audit logs; investigate unusual access.
- Encrypt ePHI at rest and in transit where feasible.
- Have a written incident response and breach notification procedure.
- Keep current business associate agreements with vendors handling PHI.
- Train staff to report suspected incidents immediately.
Bottom line
The Breach Notification Rule rewards preparation: good audit logs, encryption, and a clear response plan make incidents manageable and notifications timely. Because exact timeframes and thresholds are set in regulation and updated guidance, confirm current specifics with the HHS Office for Civil Rights and involve qualified counsel for any real incident.
An incident response sequence
When something does happen, a calm, ordered response matters. A common sequence looks like this:
- Contain: Stop ongoing exposure — disable an account, isolate a device, or cut off an access path.
- Investigate: Use audit logs and interviews to determine what PHI was involved and who accessed it.
- Assess: Apply the rule's risk-assessment factors to decide whether notification is required.
- Notify: If required, notify affected individuals, HHS, and others within the applicable timeframes.
- Remediate: Fix the underlying weakness and update policies, training, or safeguards.
- Document: Keep a thorough record of the incident and your decisions.
Business associates and breaches
Many incidents originate with a vendor rather than inside the practice. Your business associate agreements should obligate vendors to notify you promptly when they discover a breach, and to cooperate in the investigation. When a cloud EHR or other service provider is involved, the BAA and the vendor's incident-handling practices become part of your own breach-response readiness.
Why this connects to everything else
Breach notification ties together the other themes on this site: HIPAA's safeguards, access controls, encryption, audit logs, and vendor agreements all reduce both the likelihood and the impact of an incident. Practices that take those measures seriously are not only less likely to suffer a breach — they are also better positioned to respond quickly and demonstrate good faith if one occurs.