Find & Ask Federal › this rule

45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate

FederalregulationU.S. Department of Health and Human Services (HHS), Office for Civil Rights· effective 2009-09-23

What this rule requires your agency to do

  • 1A business associate must provide the notification without unreasonable delay and in no case later than 60 calendar days after discovery of the breach, except as provided in § 164.412 (§ 164.410(b)).(45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate)
  • 2The notification must include, to the extent possible, the identification of each individual whose unsecured PHI has been or is reasonably believed to have been accessed, acquired, used, or disclosed during the breach (§ 164.410(c)(1)).(45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate)
  • 3A business associate must provide the covered entity with any other available information the covered entity is required to include in individual notification under § 164.404(c), at the time of notification or promptly thereafter as information becomes available (§ 164.410(c)(2)).(45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate)
  • 4A business associate must, following the discovery of a breach of unsecured PHI, notify the covered entity of the breach (§ 164.410(a)(1)).(45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate)
  • 5A business associate must treat a breach as discovered on the first day it is known, or by exercising reasonable diligence would have been known, to it (including knowledge imputed through its employees, officers, or agents under Federal common law of agency) (§ 164.410(a)(2)).(45 CFR 164.410 — HIPAA Breach Notification Rule: Notification by a business associate)

Applies to: cross-cutting

Requires a business associate to notify the covered entity following discovery of a breach of unsecured PHI, treating a breach as discovered on the first day it is known or would have been known by exercising reasonable diligence. The notification must be provided without unreasonable delay and no later than 60 calendar days after discovery, and must identify affected individuals and include the other information the covered entity needs for individual notification.

Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.