72,000 Patients Found Out About Their Breach From the Evening News

That's not a hypothetical. In 2023, Yakima Valley Memorial Hospital discovered that 23 security guards had been snooping through patient medical records — accessing the protected health information of roughly 72,000 individuals. The hospital reported the breach to HHS, but the notification process was bumpy, public, and expensive. It's a case I reference often because it illustrates exactly how the HIPAA breach notification rule works in the real world — and how much damage poor execution causes even when you technically follow the steps.

If you handle PHI in any capacity — as a covered entity, a business associate, or even a medical courier — you need to understand this rule inside and out. Not the general concept. The specifics. The deadlines. The thresholds. The exceptions that most organizations get wrong.

That's what this post covers.

What Is the HIPAA Breach Notification Rule?

The HIPAA breach notification rule requires covered entities and their business associates to notify affected individuals, the Secretary of HHS, and in some cases the media, following a breach of unsecured protected health information. The rule is codified at 45 CFR Part 164, Subpart D.

A breach is defined as an impermissible use or disclosure of PHI that compromises the security or privacy of the information. There's a presumption that every impermissible use or disclosure is a breach unless the covered entity can demonstrate a low probability that PHI was actually compromised, based on a four-factor risk assessment.

Those four factors are:

  • The nature and extent of the PHI involved, including types of identifiers and likelihood of re-identification
  • The unauthorized person who used the PHI or to whom the disclosure was made
  • Whether the PHI was actually acquired or viewed
  • The extent to which risk to the PHI has been mitigated

I've seen organizations skip this risk assessment entirely and jump straight to notification — or worse, skip both. Neither approach ends well.

The 60-Day Clock That Most People Misunderstand

Here's where organizations trip up more than anywhere else. The HIPAA breach notification rule gives covered entities a maximum of 60 calendar days from the date the breach is discovered — not from the date it occurred — to notify affected individuals. Discovery happens when the breach is first known, or when it would have been known through reasonable diligence.

That distinction matters enormously. If an employee accesses records improperly in January but no one notices until April, the clock starts in April. But if your audit logs would have caught it in February and no one bothered to check, OCR may argue discovery happened in February.

This is exactly why I push organizations to invest in incident response training before a breach happens. Our First 60 Minutes: Incident Response course walks your team through the critical actions to take immediately after discovering a potential breach — including how to properly document the discovery date.

Individual Notification Requirements

You must notify each affected individual in writing, sent to their last known address by first-class mail. Email is permitted only if the individual has previously agreed to electronic communication. The notice must include:

  • A description of what happened, including the date of the breach and the date of discovery
  • The types of PHI involved (name, SSN, diagnosis, etc.)
  • Steps individuals should take to protect themselves
  • What your organization is doing to investigate and mitigate harm
  • Contact information for follow-up questions

If you have outdated contact information for 10 or more individuals, you must post a conspicuous notice on your website homepage for at least 90 days or provide notice through major print or broadcast media. This is where breaches become front-page stories.

HHS Notification: The 500-Person Threshold

Every breach must be reported to the Secretary of HHS. The timing depends on scale.

If a breach affects 500 or more individuals, you must notify HHS at the same time you notify individuals — within that 60-day window. These breaches are posted publicly on the HHS Breach Portal, commonly known as the "Wall of Shame."

If a breach affects fewer than 500 individuals, you can log it and submit it to HHS annually — no later than 60 days after the end of the calendar year in which the breach was discovered.

Don't treat that smaller threshold casually. OCR still investigates small breaches, especially when patterns emerge. Multiple small breaches from the same organization signal systemic problems.

The $1.5 Million Lesson From Presence Health

In 2017, OCR settled with Presence Health for $475,000 after the organization waited over a month past the 60-day deadline to report a breach affecting 836 individuals. Paper-based operating room schedules containing PHI had gone missing. The breach itself was relatively small. The penalty was entirely about the late notification.

I bring this up because many organizations think the severity of the breach determines the penalty. It doesn't — at least not exclusively. Timeliness matters independently. OCR has made that clear through enforcement.

Compare that with the $4.8 million settlement against New York-Presbyterian Hospital and Columbia University in 2014 for a breach affecting 6,800 individuals where ePHI became accessible through internet search engines. The scale was larger, but the principle is the same: the breach notification rule has teeth regardless of how the breach happens.

Business Associates: You're on the Hook Too

If you're a business associate and you discover a breach, you must notify the covered entity without unreasonable delay and no later than 60 days after discovery. The covered entity then handles the individual and HHS notifications.

But here's the catch: your business associate agreement may impose a much tighter timeline — I've seen contracts requiring notification within 24 or 48 hours. If your BAA says 24 hours and you take a week, you've breached the contract, which creates its own cascade of problems.

Medical couriers, IT vendors, billing companies, shredding services — all of these roles carry business associate obligations. If your organization uses couriers to transport PHI, make sure they understand their reporting duties. Our HIPAA Training for Medical Couriers covers these obligations in detail.

The Three Exceptions That Can Save You

Not every impermissible disclosure triggers the breach notification rule. Three narrow exceptions exist:

  • Unintentional access by workforce members acting in good faith. A nurse opens the wrong patient chart, realizes it immediately, and closes it. As long as the access was within the scope of their authority and no further disclosure occurs, this is not a reportable breach.
  • Inadvertent disclosure between authorized persons. A lab tech sends results to the wrong department within the same covered entity, and the recipient is also authorized to access PHI. No reportable breach.
  • Good faith belief that the unauthorized recipient couldn't retain the information. A fax goes to the wrong number but the recipient confirms they destroyed it immediately.

These exceptions are narrower than most people assume. I've watched compliance officers try to shoehorn serious incidents into exception one when the facts clearly didn't support it. Document your reasoning carefully — OCR will review it.

Phishing: The Fastest Path to a Breach Notification Nightmare

Phishing attacks are now the leading cause of healthcare data breaches. A single employee clicking a malicious link can expose the ePHI of thousands of patients in seconds. And once an attacker has access to an email account containing PHI, you're almost certainly looking at a reportable breach.

The risk assessment under the breach notification rule rarely works in your favor after a phishing compromise. You usually can't prove the attacker didn't view or exfiltrate PHI, which means the presumption of breach holds.

Workforce training is your best upstream defense. I recommend starting with Phishing Training for Healthcare Workers — it's designed specifically for clinical and administrative staff who handle PHI daily.

Your Breach Notification Checklist for 2026

Here's what I tell every organization I work with:

  • Conduct the four-factor risk assessment for every impermissible use or disclosure. Document it in writing every single time — even when you conclude it's not a reportable breach.
  • Know your discovery date. Train supervisors that "discovery" is a legal concept, not just an informal awareness. The clock starts earlier than you think.
  • Pre-draft your notification templates. You don't want to be wordsmithing a patient letter during a crisis. Have templates reviewed by counsel now.
  • Audit your BAAs for notification timelines. Make sure your business associates know their contractual deadlines, not just the regulatory ones.
  • Test your incident response plan. Run a tabletop exercise at least annually. Include your privacy officer, IT security lead, legal counsel, and communications team.
  • Train your entire workforce. Not just clinicians. Front desk staff, couriers, IT contractors — anyone who touches PHI. Browse the full HIPAACertify training catalog for role-specific options.

The Bottom Line on the HIPAA Breach Notification Rule

The HIPAA breach notification rule isn't optional, and it's not negotiable on timing. Sixty days is the outer boundary, not the target. OCR expects you to notify as quickly as possible, and they've penalized organizations that treated the deadline as a suggestion.

Every day you delay increases your regulatory exposure, your reputational risk, and the harm to the individuals whose data was compromised. Build the muscle now — train your workforce, test your response plans, and document everything. When the breach happens (and it will), you'll be ready to respond within hours, not scramble for weeks.

The organizations that survive breaches aren't the ones that never get hit. They're the ones that respond fast, transparently, and by the book. That's what the breach notification rule demands, and that's what your patients deserve.