skip to content

Under the HIPAA Breach Notification Rule, a hospital loses an unencrypted laptop holding 800 patients' records — who must it notify, and by when?

level: seniorimportance: must knowfreq 50%

answer

  1. unsecured PHI only
  2. presumed breach, four-factor rebuttal
  3. 60 calendar days is an outer limit
  4. media: more than 500 in a state
  5. HHS: 500 or more, contemporaneously

basics

~20 s

Unless a four-factor risk assessment shows a low probability of compromise, it is a breach of unsecured PHI. The hospital notifies each patient within 60 calendar days of discovery, HHS contemporaneously (500 or more), and media where more than 500 residents of one state are affected.

solid answer

~50 s

Under `45 CFR 164.402`, an impermissible disclosure is **presumed to be a breach** unless the covered entity shows a **low probability of compromise** through a risk assessment of at least four factors: the nature and extent of the PHI, who obtained it, whether it was actually acquired or viewed, and mitigation. An unencrypted laptop holds **unsecured PHI**, so notification applies. **Individuals**: without unreasonable delay and no later than **60 calendar days** after discovery (`164.404(b)`). **HHS**: for **500 or more** individuals, contemporaneously with individual notice (`164.408(b)`). **Media**: prominent outlets in a state or jurisdiction where **more than 500 residents** are affected (`164.406`), within the same 60 days. Discovery is the first day the breach is known, or would be with reasonable diligence, to any workforce member or agent. The hospital bears the burden of proof (`164.414(b)`).

go deeper

for a junior

Recall that notification applies to unsecured PHI, that individuals get notice within 60 calendar days of discovery, and that 500 affected people is a key threshold.

for a middle

Explain the breach presumption and the four risk-assessment factors, and the different triggers for individual, media and HHS notice.

for a senior

Walk through a real loss: set the discovery date, document the risk assessment, split affected people by state for the media test, and time HHS notice with the individual letters.

for a principal

Discuss how encryption policy, device inventory and business associate terms reduce the organization's exposure to the notification duties in the first place.

## Is it a breach? The **HIPAA Breach Notification Rule** is 45 CFR part 164, **subpart D**. Under `164.402`, a **breach** is the acquisition, access, use or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises its security or privacy. Three exclusions exist, covering good-faith unintentional access by workforce, inadvertent disclosure between authorized persons at the same entity, and disclosure where the entity believes in good faith the recipient could not reasonably have retained the information. Outside the exclusions, the impermissible use or disclosure is **presumed to be a breach** unless the covered entity demonstrates a **low probability that the PHI has been compromised**, based on a risk assessment of at least: 1. the nature and extent of the PHI, including types of identifiers and likelihood of re-identification; 2. the unauthorized person who used it or to whom it was disclosed; 3. whether the PHI was actually acquired or viewed; 4. the extent to which the risk has been mitigated. For a laptop lost in transit, factor 3 is usually unknowable and factor 2 is unknown, so the presumption normally stands. ## Why encryption matters The duties attach only to **unsecured PHI**: PHI not rendered unusable, unreadable or indecipherable to unauthorized persons through a technology or methodology specified in the Secretary's guidance. Had the laptop's disk been encrypted consistently with that guidance, the records would not be unsecured PHI and the notification duties would not apply. Because it was unencrypted, they do. ## The notification map | Recipient | Trigger | Deadline | Section | |---|---|---|---| | Each affected individual | Any breach of unsecured PHI | Without unreasonable delay, no later than 60 calendar days after discovery | `164.404` | | Prominent media outlets | More than 500 residents of a State or jurisdiction | Same as individuals | `164.406` | | HHS Secretary | 500 or more individuals | Contemporaneously with individual notice | `164.408(b)` | | HHS Secretary | Fewer than 500 individuals | Log it; report within 60 days after the end of the calendar year | `164.408(c)` | Applied to 800 patients: every patient is notified; HHS is notified at the same time as the patients, because 800 is at least 500; media notice is required only in a state or jurisdiction where **more than 500** of the affected patients reside. If the 800 are spread so that no state has more than 500, there is no media duty, although HHS still gets contemporaneous notice. ## When the clock starts Under `164.404(a)(2)`, a breach is treated as **discovered** on the first day it is known to the covered entity, or would have been known by exercising reasonable diligence. Knowledge of any workforce member or agent, other than the person committing the breach, is imputed to the entity. The 60 days are an **outer limit**: notice must also be without unreasonable delay, so waiting until day 59 without a reason can still violate the rule. `164.412` allows a **law enforcement delay**: if an official states notice would impede a criminal investigation or damage national security, a written statement delays notice for the period specified; an oral statement must be documented and delays notice for no longer than 30 days unless a written statement follows. ## What the individual notice must say Under `164.404(c)`, written in plain language and to the extent possible: - what happened, with the breach date and discovery date if known; - the types of unsecured PHI involved; - steps individuals should take to protect themselves; - what the entity is doing to investigate, mitigate harm and prevent recurrence; - contact procedures, including a toll-free number, email address, website or postal address. Delivery is first-class mail, or email if the individual agreed. If contact information is insufficient for 10 or more people, substitute notice is a conspicuous website posting for 90 days or major print or broadcast media, plus a toll-free number active for at least 90 days. ## Burden of proof and business associates `164.414(b)` puts the **burden of proof** on the covered entity or business associate to show that all notices were made or that the event was not a breach, so the risk assessment must be documented. If a business associate had lost the laptop, `164.410` would require it to notify the hospital within the same 60-calendar-day outer limit, and the hospital would carry the individual, media and HHS notices.

  • The laptop is recovered two days later with no sign it was opened. Does that change anything?
    It may. Under `164.402` the entity can rebut the breach presumption by documenting a risk assessment showing a low probability of compromise, and whether the PHI was actually acquired or viewed is one of the four factors. The burden of proof sits with the entity under `164.414(b)`.
  • How is a breach affecting 40 patients reported to HHS?
    Under `164.408(c)`, breaches affecting fewer than 500 individuals are logged, and the covered entity reports them to HHS no later than 60 days after the end of the calendar year in which they were discovered. Individual notice still follows `164.404`.
  • Can police ask the hospital to hold notification?
    Yes. Under `164.412`, a written statement that notice would impede a criminal investigation or harm national security delays notice for the period stated; an oral statement must be documented and delays it no longer than 30 days unless followed by a written one.

saying these in an interview costs you the question

  • Says HIPAA gives 72 hours to notify individuals
  • Treats the 60 days as a safe harbor regardless of delay
  • Believes a breach needs proof of harm before notice is due
  • Applies the media duty whenever 500 or more are affected in total
  • Thinks the clock starts when the investigation concludes
  • Says encrypted PHI lost under the guidance still triggers notice