When a HIPAA breach occurs, the clock starts immediately. Covered entities have 60 days from the date of discovery to notify affected individuals, report to HHS, and — for breaches affecting 500 or more individuals in a state — notify prominent media outlets. The response you take in the first hours and days after a breach determines both the regulatory outcome and the financial cost. A disorganized or delayed response dramatically increases penalties; a documented, systematic response demonstrates the due diligence that OCR looks for.


  • You have 60 days from discovery to notify affected individuals and HHS — not 60 days from when the breach occurred
  • Every breach — even small ones affecting fewer than 500 individuals — must be reported to HHS annually
  • Breaches affecting 500+ individuals in a state require media notification within the same 60-day window
  • Identity theft protection must be offered to affected patients — estimated at approximately $50 per patient per year for two years
  • Documenting your response is as important as the response itself — OCR auditors look for due diligence, not perfection
  • The Montefiore Medical Center case ($4.75M, 2024) shows that insider threats are as dangerous as external attacks


Has your organization experienced a suspected breach? HIPAA Vault’s compliance specialists can help you assess the scope, navigate notification requirements, and harden your environment against future incidents.

Talk to a specialist →


What Counts as a HIPAA Breach?

Under the HIPAA Breach Notification Rule (45 CFR Part 164), a breach is defined as the unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy.

A breach is presumed to have occurred unless you can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised:

  1. The nature and extent of the PHI involved (types of identifiers, sensitivity)
  2. Who accessed or could have accessed the PHI
  3. Whether the PHI was actually acquired or viewed
  4. The extent to which the risk has been mitigated

Encryption provides a safe harbor. If PHI was encrypted using standards consistent with NIST SP 800-111 and the encryption key was not also compromised, the incident is generally not considered a reportable breach. This is one of the most important reasons why encryption is not optional.


The Real Cost of a HIPAA Breach

Before walking through the response steps, it’s worth understanding what a breach actually costs — because this context shapes every response decision.

Gil Vidals, CTO and co-founder of HIPAA Vault, explains the breach cost math every healthcare organization should know:

“Let’s say that your app that you’ve created or that you’re hosting somewhere in the cloud has a breach. There’s a breach. There’s unauthorized access and you know that in your app there are 1,000 patient records — 1,000 different patients. Typically what happens is that you have to purchase, for every patient, what’s called identity protection. That’s a third-party service where they’ll keep an eye and find out if any of that data is being abused out in the wild. This kind of service normally would cost — if you went out to retail — say $25 for the year and you have to get it for at least two years. So now you’re looking at $50 per patient, per year, for two years. With 1,000 patients that’s $50,000 just for identity protection. And that’s before any OCR fine.”

The math at scale:

  • 1,000 patients × $50/year × 2 years = $50,000 in identity protection alone
  • 10,000 patients = $500,000
  • 100,000 patients = $5,000,000

Plus OCR civil penalties ranging from $145 to $73,011 per violation, with an annual cap of $2,190,294. The 2024 Montefiore Medical Center breach — involving only 12,570 patients — resulted in a $4.75 million penalty, exceeding OCR’s total collections for all of 2023.


Step-by-Step HIPAA Breach Response

Step 1: Contain the Breach Immediately

The moment a breach is discovered or suspected, stop the unauthorized access:

  •   Isolate affected systems — take compromised servers, devices, or accounts offline
  •   Revoke access credentials for compromised accounts
  •   Preserve evidence — do not wipe or modify systems before forensic review
  •   Engage your IT security team or incident response vendor immediately
  •   Document the time and date of discovery — this starts your 60-day clock

Critical: The 60-day notification window begins at the date of discovery, not the date the breach occurred. A breach that went undetected for months still triggers a 60-day notification requirement from the moment you discover it.


Step 2: Assess the Scope

Conduct a four-factor risk assessment to determine whether a reportable breach has occurred:

  •   Identify what PHI was involved — types of data, number of records, identifiers present
  •   Determine who accessed or could have accessed the PHI
  •   Assess whether the PHI was actually viewed, acquired, or exfiltrated
  •   Evaluate what mitigation has occurred (e.g., device recovered, data encrypted)
  •   Document the risk assessment in writing — this is your primary defense in an OCR investigation

As Gil Vidals notes from Episode 42 of the HIPAA Vault Show:

“The auditor is not looking for perfection. They’re looking for due diligence. You need to be able to show that you’re actively looking at things, finding gaps, planning to remediate them.”

If the risk assessment concludes there is a low probability the PHI was compromised, the incident may not require breach notification. However, this determination must be documented thoroughly. When in doubt, treat it as a reportable breach.


Step 3: Notify Affected Individuals

If the risk assessment confirms a reportable breach, notify affected individuals without unreasonable delay and no later than 60 days from discovery.

Required notification elements per the HIPAA Breach Notification Rule:

  •   A brief description of what happened
  •   The types of PHI involved
  •   Steps individuals should take to protect themselves
  •   What your organization is doing to investigate, mitigate harm, and prevent future breaches
  •   Contact information for affected individuals to ask questions

Notification methods:

  • Written letter to the individual’s last known address (first-class mail)
  • Email if the individual has agreed to electronic communication
  • Substitute notification (website posting for 90 days or major media notice) if contact information is insufficient for 10 or more individuals

Don’t make the same mistake as Solara Medical Supplies. In their January 2025 OCR settlement ($3 million), one contributing factor was mailing breach notification letters to wrong addresses — exposing an additional 1,531 individuals. Verify contact information before sending.


Step 4: Notify HHS

All breaches must be reported to HHS, regardless of size. The timing depends on breach scope:

Breaches affecting 500 or more individuals:

  •   Report to HHS within 60 days of discovery
  •   Submit via the HHS Breach Reporting Portal
  •   These breaches are posted publicly on HHS’s “Wall of Shame”

Breaches affecting fewer than 500 individuals:

  •   Log in your breach register throughout the year
  •   Submit to HHS annually — no later than 60 days after the end of the calendar year in which the breach was discovered via the HHS Breach Reporting Portal

Step 5: Notify Media (If Required)

For breaches affecting 500 or more residents of a single state or jurisdiction:

  •   Notify prominent media outlets serving that state within 60 days of discovery
  •   A press release to major newspapers or broadcast networks in the affected area satisfies this requirement

Step 6: Notify Business Associates (If Applicable)

If the breach occurred at a business associate — a vendor, cloud provider, or service partner — they must notify the covered entity within 60 days of discovery. Your BAA should specify a shorter notification window (commonly 5–10 days) to give your organization adequate time to manage the full response.

  •   Review your BAA with the affected business associate for notification obligations
  •   Confirm whether the business associate or covered entity will send individual notifications
  •   Document all communications with the business associate during the response

Step 7: Offer Identity Theft Protection

For any breach involving sensitive identifiers (Social Security numbers, financial information, driver’s license numbers), offer affected individuals identity theft protection services.

  •   Contract with a reputable identity monitoring service
  •   Provide services for a minimum of two years — longer for highly sensitive data
  •   Include identity monitoring information in breach notification letters

As Gil Vidals explains, this is a significant and often underestimated cost — budget approximately $50 per patient per year for two years when calculating breach exposure.


Step 8: Conduct a Root Cause Analysis

After immediate response is complete, investigate how the breach occurred:

  •   Was it an external cyberattack? (phishing, credential stuffing, ransomware)
  •   Was it an insider threat? (unauthorized access, intentional data theft)
  •   Was it a configuration error? (misconfigured cloud storage, wrong email recipient)
  •   Was it a physical breach? (lost device, unauthorized physical access)

Gil Vidals on the insider threat that healthcare organizations often overlook:

“The most common breaches, of course, are from what we call a bad actor — a cyber attacker coming in from the outside. But this one was from an insider. An employee was collecting patient information, including names, Social Security numbers, personal identifiable information, and they were selling it. That’s kind of a bummer because these companies spend so much money protecting from an attacker from the outside, but we can’t forget the attack from the inside too.”


Step 9: Implement Remediation

Address the root cause to prevent recurrence:

  •   Patch vulnerabilities that enabled the breach
  •   Revoke and reset compromised credentials
  •   Implement or strengthen access controls — least-privilege principles
  •   Add or improve audit logging to detect anomalous behavior earlier
  •   Retrain staff on phishing awareness, password hygiene, and PHI handling
  •   Review and update your BAAs if vendor failure contributed to the breach
  •   Consider penetration testing to identify remaining vulnerabilities

Step 10: Document Everything

Every step of your breach response must be documented and retained:

  •   Date and time of discovery
  •   Four-factor risk assessment and conclusion
  •   All notification communications (letters, emails, dates sent)
  •   HHS breach report submission confirmation
  •   Media notifications (if applicable)
  •   Identity monitoring contract and patient communications
  •   Root cause analysis report
  •   Remediation actions taken and timeline
  •   Staff retraining records

Retention requirement: All breach-related documentation must be retained for 6 years from the date of creation or the date it was last in effect — whichever is later.


Breach Response Timeline Summary

ActionDeadline
Contain breach and begin assessmentImmediately upon discovery
Complete four-factor risk assessmentAs soon as possible
Notify affected individualsWithin 60 days of discovery
Notify HHS (500+ individuals)Within 60 days of discovery
Notify media (500+ in one state)Within 60 days of discovery
Log small breaches (<500 individuals)Throughout the year
Report small breaches to HHSWithin 60 days after end of calendar year
Retain all breach documentation6 years minimum

Ready for the 2026 HIPAA Rules

See the fully managed solutions that meet MFA, encryption, and recovery requirements out of the box

See HIPAA Solutions

How to Reduce Breach Risk Before It Happens

The best breach response is prevention. The most common causes of HIPAA breaches — and how HIPAA Vault addresses each:

Common Breach CausePrevention
Unencrypted devices lost or stolenAES-256 encryption at rest — included on all HIPAA Vault plans
Phishing attacks on staffStaff training + email security controls
Misconfigured cloud storageManaged configuration + vulnerability scanning
Insider threatsAudit logging + least-privilege access controls
Outdated software with known vulnerabilitiesManaged patching + vulnerability scanning
RansomwareDaily encrypted backups + WAF + 24/7 monitoring

Don’t wait for a breach to find your compliance gaps. HIPAA Vault provides a fully managed HIPAA-compliant environment — with encryption, audit logging, access controls, daily backups, and 24/7 monitoring — all under one signed BAA.

View hosting plans →  |  Schedule a free risk assessment →


Frequently Asked Questions


This article draws on expert commentary from Gil Vidals, CTO and co-founder of HIPAA Vault, from HIPAA Vault Show Episode 42 (“Mastering Business Associate Agreements“) and the Live with Adam & Gil session on HIPAA breach costs and liability. Case study details sourced from publicly available HHS OCR enforcement announcements. This content is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney and incident response specialist when an actual breach occurs.