Skip to content
Redmoon Date Calculators

← Calculators

Compliance

HIPAA Breach Notification Deadline

60-day HIPAA breach notification clock.

Written and maintained by Paul Clark, Redmoon Software · Rules last verified · Sources

Friday, November 6, 2026
HIPAA breach notification deadlines
Discovery
Sep 7, 2026
Individuals notified by
Nov 6, 2026
HHS reported by
Feb 28, 2027

These calculators are for informational purposes only and do not constitute legal, financial, or professional advice.

How the HIPAA Breach Notification Deadline works

The HIPAA Breach Notification Deadline calculator resolves the two clocks that start the moment a covered entity discovers a breach of unsecured protected health information: when affected individuals must be notified, and when the breach must be reported to the Department of Health and Human Services. Enter the discovery date and say whether the breach affects fewer than 500 people or 500 or more. Those are the only two inputs, because those are the only two facts the deadlines turn on.

The individual-notification clock is the same either way: notice must go to affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery. Calendar days, not business days — weekends and holidays are inside the window, so a breach discovered on a Friday before a holiday weekend has exactly as long as one discovered on a Tuesday. The word doing the most work in that rule is "discovery," which means the first day the breach is known, or by exercising reasonable diligence would have been known, to anyone in the workforce other than the person who committed it. That is usually earlier than the day the incident-response report was finalised, and dating day zero from the report rather than from first knowledge is the single most common way this deadline gets missed.

The HHS clock is where breach size matters. For a breach affecting 500 or more individuals, the report to HHS is due on the same 60-day deadline as the individual notices, and media notice to prominent outlets serving the affected state or jurisdiction is required as well. Breaches affecting fewer than 500 individuals are instead logged and submitted annually, and the calculator returns 28 February of the following year for those — a deliberately conservative reading of the "within 60 days after the end of the calendar year" rule, which lands on 1 March in most years. Treat that as a safe internal target rather than the last possible day. Note too that the 60-day maximum is a ceiling, not a target: "without unreasonable delay" is the operative standard, and running the full 60 days on a breach you could have reported in two weeks is itself a compliance exposure.

Worked example

A practice discovers on Tuesday, 5 May 2026 that a laptop holding records for 1,200 patients was stolen. Both clocks are the 60-calendar-day one: individual notices and the HHS report are due by Saturday, 4 July 2026 — and because the count is in calendar days, the holiday weekend gives no relief. Change the breach size to fewer than 500 affected and the individual deadline stays at 4 July while the HHS obligation moves to the annual log, due 28 February 2027. Same incident, same discovery date; the reporting path is what changes.

Frequently asked questions

Is the 60-day HIPAA deadline in business days or calendar days?

Calendar days. The rule requires notice without unreasonable delay and in no case later than 60 calendar days after discovery of the breach, so weekends and public holidays fall inside the window rather than extending it. This is different from most deadlines on this site, which is exactly why it catches people out — a 60-day HIPAA window is genuinely about two months, not the roughly three months a 60-business-day count would give you.

When is a breach considered "discovered"?

On the first day the breach is known to the covered entity, or by exercising reasonable diligence would have been known — and knowledge of any workforce member or agent (other than the person who committed the breach) is imputed to the entity. That is typically well before the investigation concludes. Business associates have their own 60-day clock to notify the covered entity of a breach they discover, and the covered entity’s deadline is generally measured from the business associate’s discovery where the associate is acting as an agent.

Why does a small breach show a date in February of next year?

Because breaches affecting fewer than 500 individuals are not reported to HHS one at a time. They are recorded in an internal log and submitted annually for the preceding calendar year. The regulation allows 60 days after the calendar year ends, which is 1 March in a common year; the calculator returns 28 February to keep you a day inside it. The individual-notification deadline is unaffected by size and remains 60 days from discovery.

Does the 60 days run from the incident or from when we found it?

From discovery — the first day the breach is known, or by exercising reasonable diligence would have been known, to anyone in the workforce other than the person who caused it. That is usually earlier than the day the incident-response report was finalised, and dating day zero from the report is the most common way this deadline is missed.

What this calculator does not do

A limitation you know about costs far less than one you find after the deadline. These are the specific things this tool cannot work out for you.

  • It does not perform the four-factor risk assessment that decides whether an incident is a reportable breach at all. It assumes you have already concluded that it is.
  • Sixty days is a ceiling, not a target. The operative standard is "without unreasonable delay", and running the full window on a breach you could have reported in two weeks is itself an exposure.
  • State breach-notification laws run alongside HIPAA and several are shorter. The earliest applicable deadline governs.

Where these rules come from

The periods this calculator applies are taken from the primary sources below rather than from secondary summaries. Verify against them before relying on a date that matters.

  • 45 CFR § 164.404(b)

    Individual notice without unreasonable delay and no later than 60 calendar days after discovery.

  • 45 CFR § 164.408

    Notice to HHS: contemporaneous for 500+ individuals, annual for smaller breaches.

  • HHS Breach Portal

    Where the report is actually filed.

Related calculators

Send feedback

We read every message. Tell us what could be better or what you love.