Research

What has to happen after a clinic loses your records

The federal medical privacy rules define a breach by presumption, then set a sixty-day clock, five things the notice has to say, and separate duties toward the media and the regulator that turn on population counts.

By Nora Castellan, Standards Editor

The short answer

The federal medical privacy rules define a breach as the acquisition, access, use, or disclosure of protected health information in a manner not permitted under the privacy subpart which compromises the security or privacy of that information.

They then reverse the usual burden. Except for three named exclusions, any impermissible acquisition, access, use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates that there is a low probability that the information has been compromised, based on a risk assessment.

Following discovery of a breach of unsecured protected health information, a covered entity must notify each individual whose information has been, or is reasonably believed to have been, accessed, acquired, used or disclosed as a result.

The outside limit is sixty calendar days after discovery, and the rules also say notification must be without unreasonable delay, which is a separate and earlier obligation.

The presumption, and the four factors that can rebut it

The presumption is what makes this rule different from a rule that requires notice only after someone concludes harm occurred.

The risk assessment must consider at least four factors. The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification. The unauthorized person who used the information or to whom the disclosure was made. Whether the information was actually acquired or viewed. And the extent to which the risk to the information has been mitigated.

The standard the entity has to reach is a low probability that the information has been compromised. It is framed around compromise of the information rather than around demonstrated harm to a person.

Three situations are excluded from the definition of breach entirely. An unintentional acquisition, access or use by a workforce member or person acting under the authority of a covered entity or business associate, made in good faith and within the scope of authority, which does not result in further impermissible use or disclosure. An inadvertent disclosure between two people authorized to access protected health information at the same entity, or within an organized health care arrangement the entity participates in, where the information is not further used or disclosed impermissibly. And a disclosure where the entity has a good faith belief that the unauthorized recipient would not reasonably have been able to retain the information.

Unsecured, and why encryption changes the answer

The notification duties attach to a breach of unsecured protected health information, and unsecured is a defined term.

It means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the guidance the rules name.

That single definition is why two incidents with identical facts can produce different obligations. Information rendered unusable, unreadable or indecipherable by a specified technology or methodology is not unsecured, and the notification duties are written for unsecured information.

The rules also define when a breach is treated as discovered, and the definition is broader than the moment someone in charge learns of it. A breach is treated as discovered as of the first day on which it is known to the covered entity, or by exercising reasonable diligence would have been known to it. The entity is deemed to have knowledge if the breach is known, or by reasonable diligence would have been known, to any person other than the person committing the breach who is a workforce member or agent of the entity.

So the sixty-day clock does not start when the incident is escalated. It starts when the entity knew or, exercising reasonable diligence, would have known.

What the notice to an individual has to say

The rules list five elements, each qualified by the words to the extent possible, and require the whole notice to be written in plain language.

A brief description of what happened, including the date of the breach and the date of discovery, if known. A description of the types of unsecured protected health information involved, and the rules give examples: whether full name, social security number, date of birth, home address, account number, diagnosis, disability code or other types of information were involved.

Any steps individuals should take to protect themselves from potential harm resulting from the breach. A brief description of what the covered entity is doing to investigate the breach, to mitigate harm to individuals, and to protect against further breaches.

And contact procedures for individuals to ask questions or learn additional information, which must include a toll-free telephone number, an email address, website, or postal address.

The default method is written notification by first-class mail to the individual's last known address, or by email if the individual agreed to electronic notice and has not withdrawn that agreement. Notification may be provided in one or more mailings as information becomes available.

When the address does not work, and when it is urgent

The rules deal with stale contact information explicitly, and they scale the answer by how many people are affected.

Where insufficient or out-of-date contact information precludes written notification, a substitute form of notice reasonably calculated to reach the individual must be provided. For fewer than ten individuals, that may be by an alternative form of written notice, telephone, or other means.

For ten or more individuals, substitute notice must take one of two forms: a conspicuous posting for ninety days on the home page of the covered entity's website, or conspicuous notice in major print or broadcast media in the geographic areas where the affected individuals likely reside. Either way it must include a toll-free phone number that remains active for at least ninety days, where an individual can learn whether their information may be included in the breach.

A ninety-day home page posting is a visible artefact. It is one of the few parts of this rule an outsider can observe directly.

There is also an urgency provision. Where the covered entity deems a case to require urgency because of possible imminent misuse, it may provide information to individuals by telephone or other means in addition to the written notice.

The media, the regulator, and the vendor

Three further duties sit alongside individual notice, and they turn on different triggers.

For a breach involving more than five hundred residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving that state or jurisdiction, on the same timing and with the same content requirements as individual notice.

The covered entity must also notify the Secretary of every breach of unsecured protected health information. For breaches involving five hundred or more individuals, that notice must be provided contemporaneously with individual notice and in the manner specified on the department's website. For breaches involving fewer than five hundred individuals, the entity must maintain a log or other documentation of them and provide notification not later than sixty days after the end of each calendar year, for breaches discovered during the preceding year.

Note that the media threshold and the Secretary threshold are worded differently, and are not the same test. Media notice turns on more than five hundred residents of a state or jurisdiction. Contemporaneous notice to the Secretary turns on five hundred or more individuals.

The third duty runs the other way. A business associate that discovers a breach of unsecured protected health information must notify the covered entity, without unreasonable delay and in no case later than sixty calendar days after discovery, applying the same knew-or-would-have-known discovery standard. The notification must include, to the extent possible, the identification of each individual whose information has been or is reasonably believed to have been involved, and the business associate must provide any other available information the covered entity needs for its own notice, at that time or promptly as it becomes available.

That structure means a breach at a vendor produces a chain of notices rather than a single one, and the sixty-day clocks are stacked rather than shared.

The one thing that can stop the clock

A single provision permits delay, and it is narrow.

If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under the subpart would impede a criminal investigation or cause damage to national security, the entity must delay it.

Where the statement is in writing and specifies the time for which a delay is required, the delay runs for the period the official specified. Where the statement is oral, the entity must document it, including the identity of the official making it, and delay temporarily for no longer than thirty days from the date of the oral statement, unless a written statement is submitted within that time.

That is the same oral-statement ceiling the medical privacy rules use elsewhere for suspensions, and it leaves a documentation trail inside the entity either way.

All of this applies to covered entities and business associates as the regulations define those terms. A company outside those definitions is not brought inside them by this subpart, and a separate federal rule covers breaches at health apps and online services that the medical privacy law does not reach. This article makes no claim about which sellers in this market fall on which side of that line.

Key takeaways

Frequently asked questions

What counts as a breach under the medical privacy rules?

The acquisition, access, use, or disclosure of protected health information in a manner not permitted under the privacy subpart which compromises its security or privacy. Except for three named exclusions, an impermissible acquisition, access, use or disclosure is presumed to be a breach unless the entity demonstrates a low probability that the information has been compromised, based on a risk assessment of at least four specified factors.

How quickly does notice have to go out?

Without unreasonable delay and in no case later than sixty calendar days after discovery of the breach. Discovery is defined as the first day the breach is known to the entity, or by exercising reasonable diligence would have been known, with knowledge attributed through any workforce member or agent other than the person committing the breach.

What has to be in the notice?

Five elements, to the extent possible, in plain language: a brief description of what happened including the dates of the breach and its discovery; a description of the types of information involved; any steps individuals should take to protect themselves; a brief description of what the entity is doing to investigate, mitigate and protect against further breaches; and contact procedures including a toll-free number, email address, website, or postal address.

What happens if the contact details are out of date?

Substitute notice is required. For fewer than ten individuals it may be by alternative written notice, telephone or other means. For ten or more it must be either a conspicuous posting for ninety days on the home page of the entity's website, or conspicuous notice in major print or broadcast media where the affected individuals likely reside, and must include a toll-free number active for at least ninety days.

When does a breach have to be reported to the media or the regulator?

Media notice is required for a breach involving more than five hundred residents of a state or jurisdiction, to prominent media outlets serving it. The Secretary must be notified of every breach: contemporaneously with individual notice where five hundred or more individuals are involved, and otherwise through a log submitted not later than sixty days after the end of the calendar year in which the breaches were discovered.

Does encryption change what has to be done?

The duties attach to a breach of unsecured protected health information, and unsecured is defined as information not rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified by the Secretary in the guidance the rules name. Information rendered so is not unsecured, and the notification duties are written for unsecured information.

Sources

Each document below is named as it names itself, with the date printed on that document rather than the day it was read.

  1. Title 45 Code of Federal Regulations Section 164.402, Definitions, read in full — the definition of breach with its three exclusions, the presumption and the four risk assessment factors, and the definition of unsecured protected health information; amendment note 78 FR 5695, Jan. 25, 2013Electronic Code of Federal Regulations, Office of the Federal Register, September 2026
  2. Title 45 Code of Federal Regulations Section 164.404, Notification to individuals, read in full — the general rule, the breaches-treated-as-discovered standard, the sixty calendar day limit, the five content elements and plain language requirement, and the written, substitute and urgent notice methods including the ninety day posting and toll-free numberElectronic Code of Federal Regulations, Office of the Federal Register, September 2026
  3. Title 45 Code of Federal Regulations Section 164.406, Notification to the media, read in full — the more than 500 residents of a State or jurisdiction threshold, the timeliness requirement and the content cross-referenceElectronic Code of Federal Regulations, Office of the Federal Register, September 2026
  4. Title 45 Code of Federal Regulations Section 164.408, Notification to the Secretary, read in full — the contemporaneous notice requirement for breaches involving 500 or more individuals and the annual log for breaches involving fewer than 500Electronic Code of Federal Regulations, Office of the Federal Register, September 2026
  5. Title 45 Code of Federal Regulations Sections 164.410, Notification by a business associate, and 164.412, Law enforcement delay, both read in full — the business associate duty to notify the covered entity within sixty calendar days with identification of each individual involved, and the written and oral law enforcement delay provisions with the thirty day ceiling on an oral statementElectronic Code of Federal Regulations, Office of the Federal Register, September 2026