The HIPAA Breach Notification Clock — What Independent Practices in Palm Beach County Need to Know
- Anthony Lauria

- 6 days ago
- 7 min read

A data breach at your medical practice starts two clocks the moment it's discovered. The first is the operational clock — how quickly can you contain the breach, identify what happened, and get your systems back online. The second is the regulatory clock — and this one has legal consequences if it runs out before you've taken the required steps.
The HIPAA Breach Notification Rule establishes specific timelines and requirements for notifying affected individuals, HHS, and in some cases the media after a breach involving unsecured protected health information. These requirements are mandatory, they apply to independent medical practices of every size, and the consequences of missing them — or of misunderstanding what triggers them — can compound an already difficult situation significantly.
I've been doing healthcare IT for independent dental and medical practices in Palm Beach County for 25 years. Breach notification is one of the areas where the gap between what practice owners think they need to do and what they're actually required to do is widest. This article closes that gap.
What triggers the breach notification requirement
The HIPAA Breach Notification Rule applies when there is an acquisition, access, use, or disclosure of protected health information that is not permitted under the Privacy Rule — and that compromises the security or privacy of that information.
The key phrase is "not permitted under the Privacy Rule." Not every security incident is a reportable breach. An employee accessing a patient record they have authorization to access — even if they're accessing it from home on a personal device — is not a breach. A misdirected fax to the wrong physician's office may or may not be a reportable breach depending on the information involved and the circumstances.
What definitively triggers the notification requirement is unauthorized access to or disclosure of unsecured ePHI. Ransomware that encrypts your patient records is presumed to be a breach — because the attacker who deployed the ransomware had access to your data before encrypting it, even if you can't confirm data was actually exfiltrated. A phishing attack that compromises an email account containing patient information is a breach. A stolen laptop with unencrypted patient records on it is a breach.
The 2026 HIPAA Security Rule updates tightened this by eliminating most of the flexibility practices had to self-assess whether an incident constituted a reportable breach. The presumption is now that a security incident involving ePHI is a breach — the burden is on the practice to demonstrate why it doesn't meet the reporting threshold, not the other way around.
The notification timelines you need to know
60 days from discovery to notify affected individuals.
The HIPAA Breach Notification Rule requires that affected individuals be notified no later than 60 days after the breach is discovered. This timeline runs from discovery — not from when the breach began. If a breach began six months ago but was discovered today, the 60-day clock starts today.
Notification must be in writing, delivered by first-class mail or email if the individual has consented to electronic communication. It must include a description of what happened, the types of information involved, what the practice is doing to investigate and mitigate the breach, what individuals can do to protect themselves, and contact information for the practice.
60 days sounds like a long time. In practice, between discovering the breach, conducting the forensic investigation to understand its scope, identifying which patients are affected, drafting and reviewing notifications, and managing the operational disruption of the breach itself — 60 days moves faster than expected.
60 days to notify HHS for breaches affecting 500 or more individuals.
Breaches affecting 500 or more individuals must be reported to HHS within 60 days of discovery. HHS posts these breaches publicly on the "Wall of Shame" — the HHS breach portal that lists all reported breaches. For a practice in a community as interconnected as Jupiter or Palm Beach Gardens, a public HHS breach listing can reach your patient community before your notification letters do.
Annual reporting to HHS for breaches affecting fewer than 500 individuals.
Breaches affecting fewer than 500 individuals can be logged and reported to HHS annually — within 60 days of the end of the calendar year in which they occurred. This is the provision that applies to most small breaches at independent practices — a misdirected fax, a lost device, a limited email compromise. These incidents need to be documented and reported, but not on the same urgent timeline as large breaches.
Media notification for breaches affecting 500 or more residents of a state or jurisdiction.
If a breach affects 500 or more residents of a state, HHS also requires notification to prominent media outlets in that state. For most independent practices in Palm Beach County, this threshold would only be reached in the event of a significant ransomware attack or a large-scale data compromise. But it's worth knowing because the media notification requirement adds a public dimension to large breaches that can be more reputationally damaging than the breach itself.
The four things that determine how you handle a breach
1. Is the ePHI encrypted?
Encrypted ePHI that is accessed without authorization may not trigger the breach notification requirement — if the encryption meets NIST standards and the decryption key wasn't compromised. This is one of the most important reasons encryption is a practical compliance tool, not just a technical security control. A stolen laptop with encrypted patient records may not be a reportable breach. A stolen laptop with unencrypted records definitely is.
2. What data was actually involved?
Notification requirements apply to protected health information. Not every piece of data in your systems qualifies. Scheduling information that doesn't include clinical data, administrative communications that don't reference specific patients, financial data that doesn't include health information — these may not trigger the notification requirement. The scope of the notification depends on what data was actually compromised.
3. How many individuals are affected?
The number of affected individuals determines the reporting timeline, the reporting mechanism, and whether media notification is required. Determining this accurately requires knowing which records were accessed — which is why a SIEM that logs access to patient records is so important. Without audit logs, you may not be able to determine how many individuals are affected, which means you have to assume the worst-case number.
4. Can you demonstrate it wasn't a breach?
The 2026 rule updates created a presumption of breach for security incidents involving ePHI. You can overcome this presumption by demonstrating a low probability that ePHI was compromised — based on the nature of the incident, the type of information involved, and the evidence about whether unauthorized access actually occurred. This demonstration needs to be documented. A verbal assessment isn't sufficient.
What you need in place before a breach happens
Breach notification is not something you can prepare for after a breach occurs. By the time you know you have a breach, the clock is running. The preparation happens before — and it requires specific things to be in place.
A documented incident response plan. Before a breach, you should have a written plan that defines what happens in the first 24 hours — who is notified internally, who the external contacts are, what the initial containment steps are, and when to engage legal counsel and forensic investigators. This plan should be reviewed annually and tested periodically.
A forensic-capable IT provider. The breach notification process depends on understanding the scope of the breach — which records, how many patients, what data types. That understanding comes from forensic investigation of your systems. Your IT provider needs to be able to conduct or facilitate that investigation — which requires the audit logs that a SIEM provides. Without logs, the forensic investigation is incomplete, and the scope assessment is inaccurate.
A relationship with healthcare legal counsel. Breach notification has legal dimensions — the content of notifications, the risk assessment that determines whether something is a reportable breach, the documentation that supports your HHS submission. Having a healthcare attorney on speed dial before a breach means you're not finding counsel while the clock is running.
A current, accurate patient contact list. Notification requires reaching affected individuals by mail or email. A contact list that's incomplete, outdated, or disorganized significantly complicates the notification process. Your patient demographics should be maintained accurately — not just for clinical purposes, but because you may need to notify every patient whose record was compromised.
What happens if you miss the deadlines
Missing HIPAA breach notification deadlines is itself a HIPAA violation — separate from and in addition to the underlying breach. OCR takes notification timeline violations seriously because they compound the harm to affected individuals, who can't take protective steps until they're notified.
Penalties for breach notification violations follow the same tiered structure as other HIPAA violations — from $100 per violation for unknowing violations to $50,000 per violation for willful neglect. When OCR investigates a breach, they review the notification timeline. A practice that notified in 75 days instead of 60 is in a different position than one that notified in 180 days — but both may face penalties.
The most consequential breach notification failures are those where the practice didn't know it had a breach until long after it occurred — which is the scenario that a SIEM prevents. A practice that discovers a breach nine months after it began has a very different notification timeline problem than one that detects it within days.
Where to start
If you're an independent medical practice in Palm Beach County and you're not sure whether you have the incident response plan, the audit logging capability, and the documentation required to manage a breach notification properly, the right starting point is an honest assessment of where you actually stand.
Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It covers your security and compliance posture across six categories — including your incident response readiness and audit control capability — and produces a written summary with prioritized recommendations. Yours to keep with no obligation.
Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.
Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.


