The HIPAA Breach Notification Rule
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
HIPAA does not just ask you to prevent breaches — it dictates exactly who you tell, and when, if one happens. Encryption is the safe harbour.
When it triggers
The Breach Notification Rule applies when there is a breach of unsecured protected health information — an impermissible use or disclosure that compromises the security or privacy of PHI. Not every incident is a notifiable breach; there is a risk assessment to determine whether PHI was actually compromised.
Who you notify and how fast
- Affected individuals: without unreasonable delay and no later than 60 days after discovery.
- HHS: for large breaches (500+ individuals), without unreasonable delay; smaller breaches are logged and reported annually.
- The media: for breaches affecting 500+ residents of a state or jurisdiction.
Business associates have obligations too
If you are a business associate and you discover a breach, you must notify the covered entity (your customer) — usually within timelines set in the BAA — so they can meet their own notification duties. Your incident process has to account for this upstream notification.
Encryption is the safe harbour
The rule applies to unsecured PHI. PHI that is encrypted to HHS-specified standards is generally not considered unsecured, so a breach of properly encrypted data typically does not trigger notification. That makes encryption not just a safeguard but a direct reducer of breach exposure. SentinelPanda tracks the breach/incident process and the encryption controls that underpin the safe harbour.