HITECH breach notification is the legal duty to tell affected people, federal regulators, and sometimes the media after a breach of unsecured protected health information, with the outer limit set at 60 calendar days from the day the breach is discovered. The HITECH Act folded this duty into HIPAA and made it enforceable against small vendors, not only hospitals. Most small firms we work with treat it as a single rule with one deadline. It is not. It is a staggered set of six separate obligations, each with its own clock and its own penalty for a miss. The clock starts on discovery, not on the day you finish investigating, and that gap is where firms lose the most time.
The 6 Things Small Firms Get Wrong About the 60-Day Clock
Small firms misread HITECH breach notification in a handful of predictable ways, and each one turns a survivable incident into a reportable violation. Here is the shape of the problem before we walk the six deadlines in detail.
- It is six deadlines, not one. Individuals, the federal government, the media, and your covered-entity clients each get notice on their own timeline, and each miss is counted separately.
- The clock starts at discovery. Discovery is the day you first knew, or reasonably should have known, about the incident, not the day your forensics wrap up.
- Business associates owe notice too. If you handle protected health information for a client, a breach on your side triggers a reporting duty back to that client under the HITECH Act.
- Under-500 breaches still get reported. A small breach is not exempt, it just reports to regulators on an annual log instead of within 60 days of discovery.
- “Unsecured” is the trigger word. Properly encrypted data that is lost is usually not a reportable breach, which is why encryption is the cheapest control you can buy.
- Your own contracts can shorten the clock. A negotiated business associate agreement often sets a 10-business-day internal deadline, and that self-imposed clock binds you first.
Why HITECH Breach Notification Trips Up Small Firms
HITECH breach notification catches small firms because the duty attaches the moment you touch regulated data, long before anyone hands you a compliance manual. The HITECH Act extended the HIPAA breach-notification rule directly to business associates, so an IT provider, a billing contractor, or a cloud backup vendor inherits the same reporting obligations a covered entity carries. I have sat with owners who assumed their client would handle all the paperwork, only to learn that the vendor owed its own notice on its own timeline.
There is a fair counterpoint worth holding. Enforcement does skew toward larger settlements, and the Office for Civil Rights has finite investigators, so a two-person practice feels statistically invisible. The honest read is that firm size changes the odds of an audit, not the legal standard applied when one lands. A missed deadline is a missed deadline whether you have five employees or five thousand. Our team treats the 60-day clock as live from day one, and we help clients build the reporting muscle before they need it through our cybersecurity compliance services. For the ground rules underneath all of this, our guide to what HIPAA is and why it matters sets the baseline.
The 6 HITECH Breach Notification Deadlines You Actually Owe
The six deadlines below are the operational heart of the rule, and the failure is almost never in misreading the statute. It is in starting the clock late or forgetting that one of the six even applies. Each deadline stands on its own, and satisfying one does nothing for the others.
Deadline 1: Notify Affected Individuals Within 60 Days
Affected individuals must be notified without unreasonable delay and no later than 60 calendar days after discovery of the breach. The notice goes by first-class mail, or by email if the person agreed to electronic notice, and it has to name what happened, the dates of the breach and its discovery, the types of protected health information involved, the steps the person should take to protect themselves, and a contact method such as a toll-free number. Some firms read “no later than 60 days” as a target and wait until day 59. We read the same language as an outer wall with an “unreasonable delay” standard sitting well inside it. Sixty days is the ceiling, not the plan. If you sit on notice for seven weeks while nothing blocks you, regulators can treat the delay itself as a violation even though you technically hit the date.
Deadline 2: Report 500-Plus Breaches to HHS Within 60 Days
Breaches affecting 500 or more individuals must be reported to the Secretary of Health and Human Services within 60 days of discovery, on the same clock as the individual notices. This is the report that lands a firm on the public breach portal often called the wall of shame, and it usually triggers a formal review. The debate we hear is whether to wait for a clean headcount before filing, since the 500 threshold decides which track you are on. Waiting is the wrong instinct. File on your best good-faith count and amend it, because the reporting duty runs from discovery regardless of how tidy your numbers are. A late large-breach report reads far worse in an investigation than an early estimate you corrected.
Deadline 3: Report Under-500 Breaches on the Annual Log
Breaches affecting fewer than 500 individuals are still reportable, just on a different schedule, submitted to HHS within 60 days after the end of the calendar year in which they were discovered. This is the deadline small firms forget most often because it feels optional next to the urgent individual notices. It is not optional. A cluster of small breaches you never logged becomes a pattern an investigator can line up against you all at once. Keep a running incident log the same day each event is discovered, so the year-end filing is a copy-and-submit task rather than a scramble to reconstruct what happened ten months ago. Our HIPAA compliance audit checklist gives you a log structure that holds up under review.
Deadline 4: Notify Prominent Media for Large State Breaches
When a breach affects more than 500 residents of a single state or jurisdiction, you owe notice to prominent media outlets serving that area, again within the 60-day window. Firms often miss this one entirely because it feels like a hospital-scale problem. The threshold is 500 residents of one state, which a regional vendor can cross faster than expected if its client base clusters geographically. The media notice runs alongside the individual and HHS notices, not after them, so build it into the same response track rather than treating it as a later step. A press statement drafted in advance and held as a template keeps this deadline from ambushing you mid-incident.
How Business Associates Fit the HITECH Breach Notification Rule
Business associates carry their own HITECH breach notification duty, and it runs to the covered entity that hired them rather than directly to the public. This is the fifth deadline, and it is the one most small vendors never realize they own until a client asks where their breach report is.
Deadline 5: Business Associate Notice to the Covered Entity
A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 days after discovery. From there the covered entity generally handles the downstream notices to individuals and regulators, but your duty to report up the chain is independent and mandatory. We have seen vendors assume silence buys time, when the opposite is true, since the covered entity cannot start its own 60-day clock until you tell it. If you provide managed services to a medical practice, walk our IT compliance for healthcare practices guide to see exactly where the handoff sits, and if you are the practice on the receiving end, our work across the healthcare industry shows how that reporting relationship should function.
Deadline 6: The Shorter Clock You Set in Your Own Contracts
The sixth deadline is one you write yourself, because most business associate agreements set a notification window shorter than the statutory 60 days, often 10 business days from discovery. That contractual clock binds you first, and breaching it is a contract violation on top of any regulatory exposure. The tension here is real: a tight internal deadline pressures you to report before the facts settle. The resolution is to separate the two obligations, sending prompt notice that a possible incident occurred to meet the contract, then supplementing with detail as the investigation matures. For how these windows get negotiated in the first place, our companion piece on business associate agreement traps small firms miss covers the language that quietly commits you to a faster clock.
What Happens Before the Clock Even Starts
The single strongest position is one where no deadline ever starts, and that turns on the word “unsecured.” The HITECH breach notification rule applies to unsecured protected health information, meaning data that has not been rendered unreadable through encryption or destruction to the federal standard. Lose an encrypted laptop and, in most cases, no reportable breach occurred, so no clock runs at all. That makes encryption the cheapest insurance against every deadline on this page. Pair it with a written incident-response plan so discovery-day actions are muscle memory, not improvisation. When an incident does hit, our data breach incident response service and emergency cybersecurity compliance support get the response and the reporting running in parallel, and our step-by-step guide to what to do after a data breach is worth reading before you need it. Regular cyber security audits surface the gaps that turn a minor event into a reportable one.
Frequently Asked Questions
When does the HITECH breach notification clock start?
The clock starts on the day the breach is discovered, defined as the first day you knew or reasonably should have known it occurred. It does not wait for your investigation to finish. Treating the investigation start as the discovery date is a common and costly mistake, because it quietly burns days off a 60-day limit.
Do small breaches under 500 people still require notification?
Yes. Breaches affecting fewer than 500 individuals are still reportable, just on an annual log submitted to HHS within 60 days after the end of the calendar year. Affected individuals still get their notice within 60 days of discovery. The smaller size changes the government reporting schedule, not whether you report.
Does a business associate have to report a breach?
Yes. A business associate must notify the covered entity it works for within 60 days of discovering a breach, and often sooner under the terms of its business associate agreement. That duty is independent of anything the covered entity does. Silence does not shift the obligation, it only delays the covered entity’s own required notices.
Can encryption remove the duty to notify?
Often, yes. The rule applies only to unsecured protected health information, so data encrypted to the recognized federal standard is generally not treated as breached when it is lost or stolen. This is why encryption is the most cost-effective control a small firm can adopt. It can retire the notification duty for an entire class of incidents.
Get Your Breach Notification Plan Ready Before You Need It
HITECH breach notification is survivable when the six deadlines are mapped before an incident and impossible to manage cleanly when you meet them for the first time on discovery day. The firms that come through an OCR review well are the ones that knew the clock started at discovery, kept a live incident log, wrote their notices as templates in advance, and understood which of the six obligations applied to their exact role. The firms that struggle are the ones that treated it as a single rule and found out too late that it was six. You do not need to become a compliance department overnight. You need a clear map of your duties and a response plan that starts the moment an incident is discovered. Our team builds that map with small firms every week, translating the statute into a plan your people can actually run under pressure. Book a free strategy call and we will walk your specific role, your contracts, and your data, then leave you with a breach-notification plan sized to your firm.

