Compliance Framework Alignment
HIPAA Breach Notification Rule — 45 CFR §§164.400–414 (Subpart D) Definition of breach and exceptions — 45 CFR §164.402 Notification to individuals — 45 CFR §164.404 Notification to the media — 45 CFR §164.406 Notification to the HHS Secretary — 45 CFR §164.408 Notification by a business associate — 45 CFR §164.410 Law-enforcement delay — 45 CFR §164.412 Administrative requirements and burden of proof — 45 CFR §164.414 HITECH Act (Pub. L. 111-5, Title XIII) This policy implements the HIPAA Breach Notification Rule for Acme Health Systems Inc. as a covered entity. It is an operational template and does not constitute legal or compliance advice; verify current federal deadlines and any stricter state breach-notification statute before acting on an incident. The Rule applies only to breaches of "unsecured" protected health information — PHI that is not rendered unusable, unreadable, or indecipherable through encryption or destruction meeting the Secretary's guidance.
ACME HEALTH SYSTEMS INC. HIPAA BREACH NOTIFICATION POLICY 45 CFR §§164.400–414 (Breach Notification Rule)
Effective Date [Effective Date]
Review Date [Review Date]
Entity Role Covered entity
Privacy Officer Dana Whitfield
Security Officer Marcus Lin
Incident Reporting privacy@company.com 1. Purpose and Scope
This HIPAA Breach Notification Policy ("Policy") establishes how Acme Health Systems Inc. identifies, assesses, and reports breaches of unsecured protected health information ("PHI") in accordance with the HIPAA Breach Notification Rule at 45 CFR §§164.400–414. It applies to the whole workforce — employees, volunteers, trainees, contractors, and other persons under the direct control of Acme Health Systems Inc. — and to all PHI created, received, maintained, or transmitted in any form. Where Acme Health Systems Inc. acts as a business associate, the reporting obligations in Clause 9 apply in addition to the internal duties in this Policy.
2. Definition of Breach (45 CFR §164.402)
A "breach" is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. An impermissible use or disclosure of PHI is presumed to be a breach that requires notification unless Acme Health Systems Inc. demonstrates, through the documented risk assessment in Clause 4, that there is a low probability the PHI has been compromised. Only "unsecured" PHI is in scope: PHI is not "unsecured" — and no notification is owed — if it was encrypted or destroyed in accordance with the methods specified in guidance issued by the Secretary of Health and Human Services under the HITECH Act.
3. Exceptions to Breach (45 CFR §164.402)
The definition of "breach" expressly excludes three situations, none of which requires notification: (a) a good-faith, unintentional acquisition, access, or use of PHI by a workforce member or person acting under the authority of Acme Health Systems Inc. or a business associate, if made within the scope of authority and not further used or disclosed impermissibly; (b) an inadvertent disclosure of PHI from one authorised person to another authorised person at the same covered entity, business associate, or organised health care arrangement, where the information is not further used or disclosed impermissibly; and (c) a disclosure where Acme Health Systems Inc. or the business associate has a good-faith belief that the unauthorised person who received the PHI would not reasonably have been able to retain it. Any reliance on an exception must be documented under Clause 11.
4. Four-Factor Risk Assessment (45 CFR §164.402)
To rebut the presumption of a breach, Acme Health Systems Inc. shall conduct and document a risk assessment of at least the following four factors to determine the probability that the PHI has been compromised: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the unauthorised person who used the PHI or to whom the disclosure was made; (3) whether the PHI was actually acquired or viewed, as opposed to merely having the opportunity to be acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated (for example, by obtaining satisfactory assurances that the information was returned or destroyed). Notification is required unless all four factors, considered together, support a conclusion of a low probability of compromise. This assessment shall be completed within 15 days of discovery wherever practicable and shall never justify delaying required notifications beyond the deadlines in this Policy.
5. Discovery, Internal Reporting, and the Notification Clock
A breach is treated as "discovered" on the first day on which it is known, or by exercising reasonable diligence would have been known, to Acme Health Systems Inc. — including knowledge held by any workforce member or agent other than the person who committed the breach. Every workforce member must report any known or suspected impermissible use or disclosure of PHI to privacy@company.com without delay, and in any event within 24 hours of becoming aware of it. The date of discovery starts the statutory clock for all external notifications, which run "without unreasonable delay" and in no case later than 60 calendar days after discovery; Acme Health Systems Inc. shall not treat the 60-day figure as a safe harbour where earlier notice is reasonably possible.
6. Notification to Affected Individuals (45 CFR §164.404)
Following the discovery of a breach of unsecured PHI, Acme Health Systems Inc. shall notify each affected individual (or the next of kin or personal representative of a deceased individual) without unreasonable delay and in no case later than 60 calendar days after discovery. Written notice shall be provided by first-class mail to the individual's last known address, or by electronic mail if the individual has agreed to electronic notice and has not withdrawn that agreement. Where Acme Health Systems Inc. has insufficient or out-of-date contact information for ten or more individuals, substitute notice shall be given by a conspicuous posting for 90 days on the home page of Acme Health Systems Inc. 's website, or by notice in major print or broadcast media in the relevant geographic area, together with a toll-free number active for at least 90 days. For fewer than ten individuals with inadequate contact details, substitute notice may be by an alternative written form, telephone, or other means. Urgent situations involving possible imminent misuse may also warrant notice by telephone or other means, in addition to written notice.
7. Required Content of the Individual Notice (45 CFR §164.404(c))
The notice to individuals shall be written in plain language and shall include, to the extent possible: (a) a brief description of what happened, including the date of the breach and the date of its discovery, if known; (b) a description of the types of unsecured PHI involved (such as name, Social Security number, date of birth, address, account number, diagnosis, disability code, or other identifiers) — without listing the actual PHI itself; (c) the steps individuals should take to protect themselves from potential harm resulting from the breach; (d) a brief description of what Acme Health Systems Inc. is doing to investigate the breach, to mitigate harm to individuals, and to protect against further breaches; and (e) contact procedures for individuals to ask questions or learn additional information, including a toll-free telephone number, an email address, website, or postal address.
8. Notification to Prominent Media (45 CFR §164.406)
For a breach of unsecured PHI involving more than 500 residents of a single State or jurisdiction, Acme Health Systems Inc. shall, in addition to notifying individuals, notify prominent media outlets serving that State or jurisdiction. Media notification shall be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach, and shall contain the same content elements required for the individual notice under Clause 7. This media notice does not replace the individual notices or the notice to the Secretary; it is an additional obligation triggered by the 500-per-jurisdiction threshold.
9. Notification to the HHS Secretary (45 CFR §164.408)
Acme Health Systems Inc. shall notify the Secretary of Health and Human Services of breaches of unsecured PHI by submitting a report through the HHS breach portal. For a breach involving 500 or more individuals, notice to the Secretary shall be provided contemporaneously with the notice to individuals and in no case later than 60 calendar days after discovery. For a breach involving fewer than 500 individuals, Acme Health Systems Inc. shall maintain a log or other documentation of such breaches and notify the Secretary for all breaches discovered during a calendar year no later than 60 days after the end of that calendar year. The 500-individual threshold for HHS reporting is counted across all affected individuals, unlike the 500-per-State/jurisdiction threshold that triggers media notice under Clause 8.
10. Notification by a Business Associate (45 CFR §164.410)
Any business associate of Acme Health Systems Inc. that discovers a breach of unsecured PHI shall notify the affected covered entity of the breach without unreasonable delay and in no case later than 60 calendar days after discovery. The discovery rules mirror those for a covered entity: the breach is deemed discovered on the first day it is known, or by reasonable diligence would have been known, to the business associate or its agents. The notification to the covered entity shall include, to the extent possible, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach, together with any other available information the covered entity needs to make its own notifications. Business associate agreements shall specify prompter timelines where operationally necessary so the covered entity can meet its own 60-day deadline.
11. Law-Enforcement Delay (45 CFR §164.412)
If a law-enforcement official states that a notification, notice, or posting required by this Policy would impede a criminal investigation or cause damage to national security, Acme Health Systems Inc. shall delay the notification as follows: (a) if the statement is in writing and specifies the time for which a delay is required, for the time period specified; or (b) if the statement is made orally, Acme Health Systems Inc. shall document the statement, including the identity of the official, and delay the notification temporarily for no longer than 30 days from the date of the oral statement, unless a qualifying written statement is submitted during that period. Any such delay must be documented under Clause 12.
12. Documentation and Burden of Proof (45 CFR §164.414)
Acme Health Systems Inc. bears the burden of demonstrating that all required notifications were made, or that an impermissible use or disclosure did not constitute a breach because the PHI was secured, an exception applied, or the four-factor risk assessment showed a low probability of compromise. To satisfy this burden, Acme Health Systems Inc. shall retain, for at least six years, complete records of each incident, including: the risk assessment and its conclusions; the basis for any exception relied upon; copies of individual, media, and Secretary notifications and their dates; substitute-notice postings; and any law-enforcement delay statements. Acme Health Systems Inc. shall also comply with the applicable administrative requirements of 45 CFR §164.530 — including maintaining written policies and procedures, training the workforce, operating a complaint process, applying sanctions for violations, and prohibiting retaliation and waiver of rights.
13. State Breach Laws and Coordination
Many States impose their own breach-notification laws that may require faster notice, notice to the State Attorney General or consumer-protection agency, or additional content and remedies (such as credit monitoring). Acme Health Systems Inc. shall apply the stricter of HIPAA and applicable State law on every element — timing, recipients, and content — and shall coordinate a single, consistent response so that no obligation is missed. Whether to offer credit monitoring shall be decided case-by-case based on the risk assessment and the sensitivity of the data exposed.
14. Roles, Training, Enforcement, and Review
The Privacy Officer (Dana Whitfield ) owns this Policy, chairs the breach-response process, and approves all external notifications; the Security Officer (Marcus Lin ) leads technical containment and investigation. All workforce members shall be trained on this Policy at onboarding and at least annually, and shall report incidents to privacy@company.com . Failure to report or comply may result in disciplinary action up to and including termination. Dana Whitfield shall review this Policy at least annually, after any reportable breach, and upon any material change to 45 CFR Part 164 or applicable State law; the next scheduled review date is [Review Date].
NOTIFICATION DEADLINES AT A GLANCE Recipient Trigger Deadline Authority Affected individuals Any breach of unsecured PHI Without unreasonable delay; ≤ 60 days after discovery 45 CFR §164.404 Prominent media More than 500 residents of one State/jurisdiction Without unreasonable delay; ≤ 60 days after discovery 45 CFR §164.406 HHS Secretary — large breach 500 or more individuals Contemporaneously with individual notice; ≤ 60 days after discovery 45 CFR §164.408 HHS Secretary — small breach Fewer than 500 individuals Log and report ≤ 60 days after end of calendar year 45 CFR §164.408 Covered entity Breach discovered by a business associate Without unreasonable delay; ≤ 60 days after discovery 45 CFR §164.410
This HIPAA Breach Notification Policy has been approved by the management of Acme Health Systems Inc. and is effective from [Effective Date].
__GAP[hbn_approver_title|Chief Compliance Officer]__
Approving executive name (for sign-off)
______________________
Privacy Officer
Dana Whitfield
______________________