Skip to main content

Free · no signup · no PHI

When are your HIPAA breach notifications actually due?

The Breach Notification Rule has three separate clocks with two different population thresholds, and they do not move together. Enter what you know and see which obligations apply, when each is due, and the citation behind it.

This is a scheduling aid, not legal advice. Whether an incident is a reportable breach at all is a separate analysis under 45 CFR 164.402, and state breach laws may impose shorter deadlines than these. Confirm your obligations with counsel. Do not enter patient information anywhere on this page.

You are the…

2 obligations

60 days until the 60-day outer limit

60 days is a ceiling, not a target. Every deadline below also carries “without unreasonable delay”, so waiting until day 59 without a reason is itself a compliance problem. A law enforcement official can require delay — in writing for a stated period, or orally for no more than 30 days (45 CFR 164.412).

  • Notify each affected individual

    Sunday, October 4, 2026

    Without unreasonable delay and in no case later than 60 calendar days after discovery.

    45 CFR 164.404(b)

  • Notify the Secretary of HHS (annual log submission)

    Monday, March 1, 2027

    For breaches involving fewer than 500 individuals, keep a log and submit it not later than 60 days after the end of the calendar year in which the breach was discovered (2026).

    45 CFR 164.408(c)

The question that follows a breach

After the notifications, the next thing anyone asks for is your security risk analysis — and whether it was current when the breach happened. The Security Rule requires it to be accurate and thorough, and to be reviewed when your operations, technology, or environment materially change (45 CFR 164.308(a)(1)(ii)(A), 164.308(a)(8)).

Our $99 workspace produces one: 31 safeguards, a scored risk register, a remediation plan with owners and dates, an evidence-binder checklist, management attestation, and a dated PDF. One payment, no subscription, no PHI.

How the three clocks differ

Why do the HHS and media thresholds not match?
They measure different things. Notice to the Secretary turns on the total number of individuals — 500 or more goes contemporaneously with individual notice (164.408(b)), fewer than 500 goes in the annual log (164.408(c)). Media notice turns on more than 500 residents of one State or jurisdiction (164.406(a)). Those tests can disagree, and treating them as one number is the usual mistake.
When does the clock actually start?
On the first day the breach was known — or would have been known by exercising reasonable diligence — by any workforce member or agent other than the person who committed it (164.404(a)(2)). Not the day it was escalated to management, and not the day the investigation concluded.
Does this tell me whether I have a reportable breach?
No. That is a separate analysis under 164.402, including the four-factor risk assessment and the exclusions. This page assumes you have already concluded that notification is required, and only tells you when the resulting obligations are due.

Rule text current as of the eCFR publication of 45 CFR Part 164 Subpart D dated 2026-08-03. State breach notification laws are not covered here and are frequently stricter.