Find & Ask › Federal › this rule
45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary
FederalregulationU.S. Department of Health and Human Services (HHS), Office for Civil Rights· effective 2009-09-23
What this rule requires your agency to do
- 1For breaches involving 500 or more individuals, provide the notification to the Secretary contemporaneously with the individual notice required by § 164.404(a), except as provided in § 164.412, and in the manner specified on the HHS Web site (§ 164.408(b)).(45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary)
- 2For breaches involving fewer than 500 individuals, maintain a log or other documentation of such breaches (§ 164.408(c)).(45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary)
- 3For breaches involving fewer than 500 individuals, provide the required notification to the Secretary for breaches discovered during the preceding calendar year no later than 60 days after the end of each calendar year, in the manner specified on the HHS web site (§ 164.408(c)).(45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary)
- 4Following discovery of a breach of unsecured protected health information as provided in § 164.404(a)(2), notify the Secretary (§ 164.408(a)).(45 CFR 164.408 — HIPAA Breach Notification Rule: Notification to the Secretary)
Applies to: cross-cutting
This section requires a covered entity to notify the Secretary of HHS following discovery of a breach of unsecured protected health information. Breaches involving 500 or more individuals must be reported contemporaneously with individual notice; breaches involving fewer than 500 individuals must be logged and reported to the Secretary no later than 60 days after the end of the calendar year.
Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.