When a HIPAA breach occurs, the clock starts immediately. Covered entities have 60 days from the date of discovery to notify affected individuals, report to HHS, and — for breaches affecting 500 or more individuals in a state — notify prominent media outlets. The response you take in the first hours and days after a breach determines both the regulatory outcome and the financial cost. A disorganized or delayed response dramatically increases penalties; a documented, systematic response demonstrates the due diligence that OCR looks for.
- You have 60 days from discovery to notify affected individuals and HHS — not 60 days from when the breach occurred
- Every breach — even small ones affecting fewer than 500 individuals — must be reported to HHS annually
- Breaches affecting 500+ individuals in a state require media notification within the same 60-day window
- Identity theft protection must be offered to affected patients — estimated at approximately $50 per patient per year for two years
- Documenting your response is as important as the response itself — OCR auditors look for due diligence, not perfection
- The Montefiore Medical Center case ($4.75M, 2024) shows that insider threats are as dangerous as external attacks
Has your organization experienced a suspected breach? HIPAA Vault’s compliance specialists can help you assess the scope, navigate notification requirements, and harden your environment against future incidents.
What Counts as a HIPAA Breach?
Under the HIPAA Breach Notification Rule (45 CFR Part 164), a breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy.
A breach is presumed to have occurred unless you can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised:
- The nature and extent of the PHI involved (types of identifiers, sensitivity)
- Who accessed or could have accessed the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
Encryption provides a safe harbor. If PHI was encrypted using standards consistent with NIST SP 800-111 and the encryption key was not also compromised, the incident is generally not considered a reportable breach. This is one of the most important reasons why encryption is not optional.
The Real Cost of a HIPAA Breach
Before walking through the response steps, it’s worth understanding what a breach actually costs — because this context shapes every response decision.
Gil Vidals, CTO and co-founder of HIPAA Vault, explains the breach cost math every healthcare organization should know:
“Let’s say that your app that you’ve created or that you’re hosting somewhere in the cloud has a breach. There’s a breach. There’s unauthorized access and you know that in your app there are 1,000 patient records — 1,000 different patients. Typically what happens is that you have to purchase, for every patient, what’s called identity protection. That’s a third-party service where they’ll keep an eye and find out if any of that data is being abused out in the wild. This kind of service normally would cost — if you went out to retail — say $25 for the year and you have to get it for at least two years. So now you’re looking at $50 per patient, per year, for two years. With 1,000 patients that’s $50,000 just for identity protection. And that’s before any OCR fine.”
The math at scale:
- 1,000 patients × $50/year × 2 years = $50,000 in identity protection alone
- 10,000 patients = $500,000
- 100,000 patients = $5,000,000
Plus OCR civil penalties ranging from $145 to $73,011 per violation, with an annual cap of $2,190,294. The 2024 Montefiore Medical Center breach — involving only 12,570 patients — resulted in a $4.75 million penalty, exceeding OCR’s total collections for all of 2023.
Step-by-Step HIPAA Breach Response
Step 1: Contain the Breach Immediately
The moment a breach is discovered or suspected, stop the unauthorized access:
- Isolate affected systems — take compromised servers, devices, or accounts offline
- Revoke access credentials for compromised accounts
- Preserve evidence — do not wipe or modify systems before forensic review
- Engage your IT security team or incident response vendor immediately
- Document the time and date of discovery — this starts your 60-day clock
Critical: The 60-day notification window begins at the date of discovery, not the date the breach occurred. A breach that went undetected for months still triggers a 60-day notification requirement from the moment you discover it.
Step 2: Assess the Scope
Conduct a four-factor risk assessment to determine whether a reportable breach has occurred:
- Identify what PHI was involved — types of data, number of records, identifiers present
- Determine who accessed or could have accessed the PHI
- Assess whether the PHI was actually viewed, acquired, or exfiltrated
- Evaluate what mitigation has occurred (e.g., device recovered, data encrypted)
- Document the risk assessment in writing — this is your primary defense in an OCR investigation
As Gil Vidals notes from Episode 42 of the HIPAA Vault Show:
“The auditor is not looking for perfection. They’re looking for due diligence. You need to be able to show that you’re actively looking at things, finding gaps, planning to remediate them.”
If the risk assessment concludes there is a low probability the PHI was compromised, the incident may not require breach notification. However, this determination must be documented thoroughly. When in doubt, treat it as a reportable breach.
Step 3: Notify Affected Individuals
If the risk assessment confirms a reportable breach, notify affected individuals without unreasonable delay and no later than 60 days from discovery.
Required notification elements per the HIPAA Breach Notification Rule:
- A brief description of what happened
- The types of PHI involved
- Steps individuals should take to protect themselves
- What your organization is doing to investigate, mitigate harm, and prevent future breaches
- Contact information for affected individuals to ask questions
Notification methods:
- Written letter to the individual’s last known address (first-class mail)
- Email if the individual has agreed to electronic communication
- Substitute notification (website posting for 90 days or major media notice) if contact information is insufficient for 10 or more individuals
Don’t make the same mistake as Solara Medical Supplies. In their January 2025 OCR settlement ($3 million), one contributing factor was mailing breach notification letters to wrong addresses — exposing an additional 1,531 individuals. Verify contact information before sending.
Step 4: Notify HHS
All breaches must be reported to HHS, regardless of size. The timing depends on breach scope:
Breaches affecting 500 or more individuals:
- Report to HHS within 60 days of discovery
- Submit via the HHS Breach Reporting Portal
- These breaches are posted publicly on HHS’s “Wall of Shame”
Breaches affecting fewer than 500 individuals:
- Log in your breach register throughout the year
- Submit to HHS annually — no later than 60 days after the end of the calendar year in which the breach was discovered via the HHS Breach Reporting Portal
Step 5: Notify Media (If Required)
For breaches affecting 500 or more residents of a single state or jurisdiction:
- Notify prominent media outlets serving that state within 60 days of discovery
- A press release to major newspapers or broadcast networks in the affected area satisfies this requirement
Step 6: Notify Business Associates (If Applicable)
If the breach occurred at a business associate — a vendor, cloud provider, or service partner — they must notify the covered entity within 60 days of discovery. Your BAA should specify a shorter notification window (commonly 5–10 days) to give your organization adequate time to manage the full response.
- Review your BAA with the affected business associate for notification obligations
- Confirm whether the business associate or covered entity will send individual notifications
- Document all communications with the business associate during the response
Step 7: Offer Identity Theft Protection
For any breach involving sensitive identifiers (Social Security numbers, financial information, driver’s license numbers), offer affected individuals identity theft protection services.
- Contract with a reputable identity monitoring service
- Provide services for a minimum of two years — longer for highly sensitive data
- Include identity monitoring information in breach notification letters
As Gil Vidals explains, this is a significant and often underestimated cost — budget approximately $50 per patient per year for two years when calculating breach exposure.
Step 8: Conduct a Root Cause Analysis
After immediate response is complete, investigate how the breach occurred:
- Was it an external cyberattack? (phishing, credential stuffing, ransomware)
- Was it an insider threat? (unauthorized access, intentional data theft)
- Was it a configuration error? (misconfigured cloud storage, wrong email recipient)
- Was it a physical breach? (lost device, unauthorized physical access)
Gil Vidals on the insider threat that healthcare organizations often overlook:
“The most common breaches, of course, are from what we call a bad actor — a cyber attacker coming in from the outside. But this one was from an insider. An employee was collecting patient information, including names, Social Security numbers, personal identifiable information, and they were selling it. That’s kind of a bummer because these companies spend so much money protecting from an attacker from the outside, but we can’t forget the attack from the inside too.”
Step 9: Implement Remediation
Address the root cause to prevent recurrence:
- Patch vulnerabilities that enabled the breach
- Revoke and reset compromised credentials
- Implement or strengthen access controls — least-privilege principles
- Add or improve audit logging to detect anomalous behavior earlier
- Retrain staff on phishing awareness, password hygiene, and PHI handling
- Review and update your BAAs if vendor failure contributed to the breach
- Consider penetration testing to identify remaining vulnerabilities
Step 10: Document Everything
Every step of your breach response must be documented and retained:
- Date and time of discovery
- Four-factor risk assessment and conclusion
- All notification communications (letters, emails, dates sent)
- HHS breach report submission confirmation
- Media notifications (if applicable)
- Identity monitoring contract and patient communications
- Root cause analysis report
- Remediation actions taken and timeline
- Staff retraining records
Retention requirement: All breach-related documentation must be retained for 6 years from the date of creation or the date it was last in effect — whichever is later.
Breach Response Timeline Summary
| Action | Deadline |
| Contain breach and begin assessment | Immediately upon discovery |
| Complete four-factor risk assessment | As soon as possible |
| Notify affected individuals | Within 60 days of discovery |
| Notify HHS (500+ individuals) | Within 60 days of discovery |
| Notify media (500+ in one state) | Within 60 days of discovery |
| Log small breaches (<500 individuals) | Throughout the year |
| Report small breaches to HHS | Within 60 days after end of calendar year |
| Retain all breach documentation | 6 years minimum |
Ready for the 2026 HIPAA Rules
See the fully managed solutions that meet MFA, encryption, and recovery requirements out of the box
See HIPAA SolutionsHow to Reduce Breach Risk Before It Happens
The best breach response is prevention. The most common causes of HIPAA breaches — and how HIPAA Vault addresses each:
| Common Breach Cause | Prevention |
| Unencrypted devices lost or stolen | AES-256 encryption at rest — included on all HIPAA Vault plans |
| Phishing attacks on staff | Staff training + email security controls |
| Misconfigured cloud storage | Managed configuration + vulnerability scanning |
| Insider threats | Audit logging + least-privilege access controls |
| Outdated software with known vulnerabilities | Managed patching + vulnerability scanning |
| Ransomware | Daily encrypted backups + WAF + 24/7 monitoring |
Don’t wait for a breach to find your compliance gaps. HIPAA Vault provides a fully managed HIPAA-compliant environment — with encryption, audit logging, access controls, daily backups, and 24/7 monitoring — all under one signed BAA.
View hosting plans → | Schedule a free risk assessment →
Frequently Asked Questions
This article draws on expert commentary from Gil Vidals, CTO and co-founder of HIPAA Vault, from HIPAA Vault Show Episode 42 (“Mastering Business Associate Agreements“) and the Live with Adam & Gil session on HIPAA breach costs and liability. Case study details sourced from publicly available HHS OCR enforcement announcements. This content is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney and incident response specialist when an actual breach occurs.


