Free compliance & forms tool

HIPAA Breach Notification Deadline Calculator

Under HIPAA breach notification requirements, a covered practice must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach. HHS is told at the same time if 500 or more people are affected, or within 60 days after the end of the calendar year if fewer. The media must be told if more than 500 residents of one state are affected. Enter your dates below.

Prepared by Prospyr · Reviewed October 3, 2026 · Free, no sign-up, runs in your browser

HIPAA breach notification requirements at a glance

Who is notifiedWhenRule
Affected individualsWithout unreasonable delay, no later than 60 calendar days after discovery45 CFR 164.404
HHS, 500 or more individualsAt the same time as individual notice45 CFR 164.408(b)
HHS, fewer than 500Within 60 days after the end of the calendar year of discovery45 CFR 164.408(c)
Media, more than 500 residents of one stateWithout unreasonable delay, no later than 60 calendar days after discovery45 CFR 164.406
Your practice, from a business associateWithout unreasonable delay, no later than 60 calendar days after the vendor discovers it45 CFR 164.410

The rule applies to a breach of unsecured PHI: information not rendered unusable, unreadable or indecipherable to unauthorized people. Encrypted data that meets HHS guidance is generally outside the notification duty.

How to tell whether it is a reportable breach

An impermissible use or disclosure of PHI is presumed to be a breach unless you show a low probability that the information was compromised. That assessment weighs at least four factors:

  1. The nature and extent of the PHI involved, including identifiers and the likelihood of re-identification.
  2. The unauthorized person who used the PHI or received it.
  3. Whether the PHI was actually acquired or viewed.
  4. The extent to which the risk has been mitigated.

Three narrow exceptions exist, such as an unintentional, good-faith access by a workforce member acting within their authority. Write down your assessment for every incident, including the ones you decide are not breaches.

Worked example: 750 patients, two states

Your practice finds on October 1, 2026 that a misconfigured file share exposed a patient list of 750 people: 650 Texas residents and 100 in California. Counting 60 calendar days from October 1 gives November 30, 2026.

  • Patients: notify by November 30, and sooner if you can.
  • HHS: 750 is 500 or more, so report at the same time as the patient notices, also by November 30.
  • Media: 650 Texas residents is more than 500, so notify prominent media in Texas by November 30. The 100 California residents do not trigger it.

If only 120 people were affected, patient notice would still be due November 30, but the HHS report would be due March 1, 2027 (60 days after December 31, 2026), and there would be no media notice.

What the breach notice must say, and what to do next

Each individual notice includes, in plain language:

  • What happened, the date of the breach and the date you discovered it, if known.
  • The types of information involved, such as name, date of birth, diagnosis or treatment details.
  • Steps individuals should take to protect themselves.
  • What you are doing to investigate, limit harm and prevent a repeat.
  • How to reach you: a toll-free number, email, website or postal address.

If you lack current contact details for 10 or more people, the rule calls for substitute notice, including a toll-free number active for 90 days. Keep your breach log current. It helps to have your HIPAA checklist and a risk assessment on file before an incident, and to know which of your vendors sign a BAA; our HIPAA and BAA comparison covers what to ask.

Frequently asked questions

How long do you have to report a HIPAA breach?

You must notify affected individuals without unreasonable delay and no later than 60 calendar days after the breach is discovered. The 60 days is an outer limit, not a target, so a practice that waits until day 59 without a reason can still be out of compliance. HHS and media deadlines depend on how many people are affected.

When does the 60-day clock start?

It starts on the first day the breach is known to your practice or, using reasonable diligence, would have been known. Knowledge by any workforce member or agent other than the person who committed the breach counts as knowledge of the practice. That is why staff should report suspected incidents right away. The calculator counts 60 days from the discovery date you enter.

Do I have to report a breach of fewer than 500 people to HHS?

Yes. For breaches affecting fewer than 500 individuals, you report to HHS within 60 days after the end of the calendar year in which the breach was discovered. For a breach discovered in 2026 that date is March 1, 2027. You may log several small breaches and submit them together after year end.

When is media notice required?

When a breach involves more than 500 residents of a single state or jurisdiction, you must notify prominent media outlets serving that area, within the same 60-day limit. Exactly 500 residents does not trigger the media rule, though 500 or more total individuals does trigger the HHS rule. The calculator checks each state you list.

What must a breach notification letter include?

The letter must describe what happened and when, the types of information involved, the steps individuals should take to protect themselves, what your practice is doing to investigate and prevent a repeat, and how to contact you. Use plain language. Notices go by first-class mail, or by email if the individual agreed to electronic notice.

Are state breach notification laws stricter than HIPAA?

Often, yes. All 50 states, the District of Columbia and several territories have their own breach notification laws, and some set shorter deadlines or require notice to a state attorney general or other agency. This calculator covers only the federal HIPAA rule, so check the law of each state where affected patients live.

What if my software vendor had the breach?

A business associate must notify your practice without unreasonable delay and within 60 calendar days of its own discovery. Your own deadlines still run from your discovery date, and if the vendor is acting as your agent its discovery can be treated as yours. Choose the vendor option in the calculator to see both dates, and ask your attorney which applies.

Sources and scope

Educational calculator for the federal HIPAA Breach Notification Rule, not legal advice. State laws may be stricter, and a law enforcement delay can apply. Talk to your attorney as soon as you suspect a breach.

Report a correction

Run your practice on one system