Skip to main content
Compliance & Legal

Breach Notification Rule

The HIPAA rule requiring notice when unsecured PHI is exposed.

The Breach Notification Rule requires covered entities and business associates to notify affected individuals, HHS, and in some cases the media when unsecured PHI is exposed. It sits alongside the Privacy and Security Rules and defines reporting timelines after a breach is discovered.

Accidental disclosures can trigger it too. See examples of unintentional HIPAA violations.

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.