What must an employer do after a HIPAA breach?
Last updated October 2, 2026
After discovering a breach of unsecured protected health information, the plan must notify affected individuals without unreasonable delay and within 60 days, notify HHS (immediately for breaches of 500+, annually for smaller ones), and notify media for large breaches — while documenting its risk assessment.
Group health plans are HIPAA covered entities, so a breach of protected health information triggers the Breach Notification Rule regardless of whether the breach happened at the employer or a vendor.
The sequence:
- Assess: determine whether the incident compromises unsecured PHI (a documented risk assessment can show low probability of compromise).
- Notify individuals: without unreasonable delay, no later than 60 days from discovery.
- Notify HHS: within 60 days for breaches affecting 500+ individuals; smaller breaches log annually within 60 days of year end.
- Notify media: for breaches affecting 500+ in a state or jurisdiction.
Business associates (TPAs, brokers with PHI access) must report breaches to the plan — one more reason business associate agreements and vendor oversight belong in your governance routine. Document everything: the assessment, the notices, and the remediation.
Thanks for your feedback!