Find & Ask › Federal › this rule
45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals
FederalregulationU.S. Department of Health and Human Services (HHS), Office for Civil Rights· effective 2009-09-23
What this rule requires your agency to do
- 1Except as provided in § 164.412, the covered entity must provide the notification without unreasonable delay and in no case later than 60 calendar days after discovery of the breach (subd. b).(45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals)
- 2Following the discovery of a breach of unsecured protected health information, a covered entity must notify each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach; a breach is treated as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to any workforce member or agent other than the person who committed it (subd. a).(45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals)
- 3The notification must be provided by written notice via first-class mail to the individual's last known address (or by e-mail if the individual has agreed), or to the next of kin/personal representative if the individual is known to be deceased; notice may be provided in one or more mailings as information becomes available (subd. d(1)).(45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals)
- 4Where insufficient or out-of-date contact information precludes written notice, the covered entity must provide substitute notice reasonably calculated to reach the individual; for 10 or more individuals, substitute notice must be a conspicuous 90-day home-page website posting or conspicuous major print/broadcast media notice in the affected areas, plus a toll-free number active for at least 90 days; and in urgent situations involving possible imminent misuse the entity may also notify by telephone or other means (subd. d(2)-(3)).(45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals)
- 5The notification must include, to the extent possible, a brief description of what happened (including the dates of the breach and its discovery, if known), the types of unsecured PHI involved, steps individuals should take to protect themselves, a description of what the entity is doing to investigate the breach and mitigate harm and protect against further breaches, and contact procedures including a toll-free number, e-mail address, website, or postal address; and it must be written in plain language (subd. c).(45 CFR 164.404 — HIPAA Breach Notification: Notification to Individuals)
Applies to: cross-cutting
The HIPAA Breach Notification Rule's requirement that a covered entity notify each affected individual following discovery of a breach of unsecured protected health information — without unreasonable delay and no later than 60 calendar days after discovery — specifying the required content, plain-language standard, and methods of notice (written first-class mail or email, substitute notice, and urgent additional notice). Cross-cutting federal baseline for the Privacy & Security (HIPAA) topic.
Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.