The HIPAA Breach Notification Clock: 60 Days, and the Deadline People Forget
When a covered entity or business associate discovers a breach of unsecured protected health information, the HIPAA Breach Notification Rule starts a clock. Most people remember the headline number — 60 days — but they remember it wrong in two ways: they miscount when the clock starts, and they assume the same 60 days covers everyone who has to be told. It doesn't. The deadline to notify the people affected and the deadline to notify the federal government are governed by different rules, and for smaller breaches the government deadline lands on an entirely separate calendar.
Day zero is the day of discovery, not the day of the breach
The 60-day period runs from the day the breach is discovered, not the day it happened. And "discovered" has a specific meaning: a breach is treated as discovered on the first day it is known, or reasonably should have been known, to the organisation. That second clause matters. You cannot stop the clock by routing the incident slowly, by leaving it unexamined, or by arguing that the right person hadn't been told yet. Knowledge held by any workforce member or agent (other than the person who committed the breach) is imputed to the entity. In practice, log the discovery date the moment anyone in the organisation has reason to know — that is day zero, and every downstream deadline counts from it.
Individuals: 60 calendar days, without unreasonable delay
Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery. The 60 days is an outer limit, not a target — "without unreasonable delay" means you can't sit on a fully-investigated breach for 59 days just because you're allowed to. The count is in calendar days, so weekends and holidays are included; there is no business-day adjustment the way there is for, say, an I-9 deadline. A breach discovered on 1 April is due to individuals by 31 May.
HHS: the 500-person fork in the road
Notifying the Secretary of Health and Human Services is where most people get the timing wrong, because there are two completely different deadlines depending on the size of the breach.
- 500 or more individuals affected: you must notify HHS contemporaneously with notifying individuals — that is, within the same 60-day window from discovery. A large breach discovered on 1 April is reportable to HHS by 31 May, the same date as the individual notices. Large breaches in a single state or jurisdiction also trigger a media notice to prominent outlets serving that area, again within 60 days.
- Fewer than 500 individuals affected: you are not required to report to HHS within 60 days at all. Instead, smaller breaches go into an annual log, which is submitted to HHS no later than 60 days after the end of the calendar year in which the breach was discovered. A small breach discovered in April 2026 isn't reported to HHS until early 2027 — by the end of February following year-end.
That difference is easy to miss because the individual-notification deadline looks identical in both cases. It's the government deadline that forks: same 60 days for a large breach, but a year-end roll-up for a small one. Misclassifying a breach — or assuming the 60-day individual deadline is also your HHS deadline — is how organisations either report late or scramble unnecessarily.
Counting from the right date matters more than it looks
None of these rules involve skipping weekends, so the arithmetic seems trivial — "just add 60 days." The trouble is that the 60 days is anchored to the discovery date, and the small-breach HHS deadline is anchored to the end of the year, so you are tracking two clocks at once with two different start points. A breach discovered on 5 November affects both the 60-day individual deadline (early January of the following year) and, if it's small, the annual-log deadline (end of February of that same following year) — two dates only weeks apart but derived completely differently. Getting either one wrong is a reportable compliance failure, and the burden of proving timely notification sits with you.
Pin down both deadlines from the discovery date
The HIPAA Breach Notification Deadline calculator takes the discovery date and the breach size and returns the individual-notification deadline, the HHS reporting deadline for that size, and the discovery date itself for your records — so you're not mentally juggling a 60-day count and a year-end roll-up at the same time. Fix the discovery date first, classify the breach by headcount, and let the calculator turn both into concrete dates you can put on an incident-response timeline.
General information, not legal advice. HIPAA breach rules turn on facts specific to each incident and are enforced by HHS — confirm any real deadline against the current Breach Notification Rule (45 CFR §§ 164.400–414) and your own counsel or privacy officer.