---
title: Understanding the HIPAA Breach Notification Rule - SCA Security
description: What Entities Need to Understand About the HIPAA Breach Notification Rule With Electronic Health Records (EHR) becoming a healthcare industry standard, information security becomes highly critical to protect health records from unauthorized use and disclosure. If a breach of unsecured protected health information should occur, it’s important to inform the affected individuals and regulators about
image: https://blog.scasecurity.com/hubfs/Imported_Blog_Media/hipaa-breach-notification-rule-1.jpg
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 June 06, 2019

# Understanding the HIPAA Breach Notification Rule

 By: SCA Editor

![](https://blog.scasecurity.com/hubfs/Imported_Blog_Media/hipaa-breach-notification-rule-1.jpg)

## What Entities Need to Understand About the HIPAA Breach Notification Rule

With Electronic Health Records (EHR) becoming a [healthcare](https://scasecurity.com/industries/healthcare/) industry standard, information security becomes highly critical to protect health records from unauthorized use and disclosure. If a breach of unsecured protected health information should occur, it’s important to inform the affected individuals and regulators about the breach. The HIPAA Breach Notification Rule provides guidelines and requirements for providing notice. While most entities understand the notification requirements, organizations that have not experienced a data breach may lack a good working knowledge of HIPAA Breach Notification Rule [compliance](https://scasecurity.com/compliance/).

### HIPAA Breach Notification Rule

Unsecured protected health information (PHI) is information in any form, whether paper, verbal, or electronic, that has not been rendered unreadable, unusable or illegible to unauthorized persons. A breach is considered to have occurred if there was an impermissible disclosure of PHI to an unauthorized person(s). Unauthorized disclosure will not be considered a breach of unsecured PHI has been properly “de-identified,” and thus is exempted from notification mandates. Covered entities or business associates must stay in compliance with the HIPAA Breach Notification Rule by conducting a risk analysis to determine if the unsecured PHI has been compromised. This involves taking into account the nature and extent of the PHI, the individual(s) who gained unauthorized access to PHI, whether the information was acquired or viewed, and the extent to which the covered entity has mitigated the risk.

If a HIPAA covered entity discovers a breach of unsecured PHI, [it must provide notification](https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html) to individuals affected by the breach, the Secretary of Health and Human Services (HHS), and in some instances, the media, as stipulated under 45 CFR § 164.400-414. If a breach occurs at or by a business associate, they must equally notify covered entities.

As provided by the HIPAA Breach Notification Rule, notification of a breach of unsecured PHI must be provided to all affected individuals in writing form by first-class mail or e-mail. If there’s out-of-date or insufficient information for 10 or more individuals, substitute individual notice must be provided by either posting the notice on the website for at least 90 days or by using broadcast media or major print where the affected people likely live. If the breach has affected fewer than 10 individuals, an alternative form of notice, such as telephone, may be used. The notification should have a brief description of the breach, the type of information involved, steps taken by the covered entity in investigating the breach, and the steps that should be taken by affected individuals to protect themselves from potential harm.

### Notifications Depending on the Number of Affected Individuals

The HIPAA Breach Notification Rule requirements vary based on the [number of individuals affected](https://www.hhs.gov/hipaa/for-professionals/breach-notification/breach-reporting/index.html), usually 500 or more individuals or fewer than 500 individuals. If there’s uncertainty about the number of affected individuals at the time of submission, an estimate should be provided, and if additional information is discovered, the covered entity should submit the updates as they come in.

If 500 or more individuals are affected by a breach of unsecured protected health information, a covered entity must send a notification to the Secretary no later than 60 days from the discovery of the breach, and without unreasonable delay. Conversely, if fewer than 500 individuals are affected by the breach, the entity must submit the notice to the Secretary on an annual basis.

### Administrative Requirements for the HIPAA Breach Notification Rule

Covered entities and their business associates bear the burden of proving that all notifications have been provided, or that a breach did not occur following the unauthorized access. Thus, the entity should maintain documentation to demonstrate that all required notifications were made, or documentation to show that a breach never occurred and thus, notification was not required. In the case where the covered entity believes there was no breach, it should provide its risk assessment showing that there’s a low risk that the PHI was compromised.

### Contact SCA to Learn More About HIPAA Breach Notification Rule

[Security](https://scasecurity.com/security/) Compliance Associates (SCA) has many years of experience in delivering risk assessment and [information security](https://scasecurity.com/security/consulting/) compliance services to healthcare organizations. If your business has experienced a breach, we can assess your people, processes and technology to help mitigate risks and reduce the likelihood of a breach while helping you stay in compliance with HIPAA Security, Privacy, and Breach Notification rules.

Contact SCA today at (727) 571-1141 to schedule a no-cost consultation.

#### Subscribe

Email\*

Notification Frequency

[Blog](https://blog.scasecurity.com/tag/blog)

[February 07, 2025 Preparing for 2025 HIPAA Changes: What Healthcare Organizations Need to Know](https://blog.scasecurity.com/preparing-for-2025-hipaa-changes-what-healthcare-organizations-need-to-know) [October 23, 2024 What is a Vulnerability Assessment (and Why You Need One)](https://blog.scasecurity.com/blog/what-is-a-vulnerability-assessment) [October 10, 2024 Understanding the Risks and Mitigation of Phishing Attacks](https://blog.scasecurity.com/understanding-the-risks-and-mitigation-of-phishing-attacks)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T15:51:41.437Z",
  "datePublished" : "2019-06-06T04:00:00.000Z",
  "headline" : "Understanding the HIPAA Breach Notification Rule - SCA Security",
  "image" : [ "https://blog.scasecurity.com/hubfs/Imported_Blog_Media/hipaa-breach-notification-rule-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/hipaa-breach-notification-rule",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```