What must an employer do after a HIPAA breach?

Last updated October 2, 2026

After discovering a breach of unsecured protected health information, the plan must notify affected individuals without unreasonable delay and within 60 days, notify HHS (immediately for breaches of 500+, annually for smaller ones), and notify media for large breaches — while documenting its risk assessment.

Group health plans are HIPAA covered entities, so a breach of protected health information triggers the Breach Notification Rule regardless of whether the breach happened at the employer or a vendor.

The sequence:

  • Assess: determine whether the incident compromises unsecured PHI (a documented risk assessment can show low probability of compromise).
  • Notify individuals: without unreasonable delay, no later than 60 days from discovery.
  • Notify HHS: within 60 days for breaches affecting 500+ individuals; smaller breaches log annually within 60 days of year end.
  • Notify media: for breaches affecting 500+ in a state or jurisdiction.

Business associates (TPAs, brokers with PHI access) must report breaches to the plan — one more reason business associate agreements and vendor oversight belong in your governance routine. Document everything: the assessment, the notices, and the remediation.

Thanks for your feedback!

Put these answers to work

Fiduciary In A Box walks your team through every one of these requirements step by step — documenting decisions, organizing files, and keeping your plan compliant year-round.

See how FIAB works