The misdirected fax happened in April. An after-visit summary went to the wrong pharmacy, the pharmacy called, the practice confirmed it was shredded, wrote the patient a letter, and moved on. In August a biller mailed a statement to a former address and it came back opened. In November somebody left a printed schedule on the counter of a shared-building lobby overnight. Each incident was handled properly on its own. Then it is February, and a new office manager asks a question nobody has asked before: did anyone tell HHS?
Nobody did, and that is fine, as long as two things are true. The practice kept a log, and it files before the deadline. Breaches affecting fewer than 500 people run on a different calendar from the ones that make the news, and the rule that sets it is short enough to quote in full. This article covers that rule, how to decide whether an incident was a breach at all, what the log must hold, how the annual filing works, what business associates owe you, and what to write into the policy so February stops being a surprise.
HIPAA Small Breach Reporting: What 45 CFR 164.408(c) Requires
The Breach Notification Rule requires notice to the Secretary of HHS for every breach of unsecured P.H.I. (Protected Health Information). The timing depends on size. For breaches involving 500 or more individuals, 164.408(b) requires notice "contemporaneously with the notice required by § 164.404(a)," meaning at the same time the patients are told. For the smaller ones, 164.408(c) says:
"For breaches of unsecured protected health information involving less than 500 individuals, a covered entity shall maintain a log or other documentation of such breaches and, not later than 60 days after the end of each calendar year, provide the notification required by paragraph (a) of this section for breaches discovered during the preceding calendar year, in the manner specified on the HHS web site."
Two obligations, then. Keep a log. File it within 60 days after the end of the calendar year in which the breaches were discovered. Sixty days after December 31 is March 1 in a non-leap year (February 29 in a leap year). For breaches discovered in 2026, the filing is due by March 1, 2027. The practice may file earlier, and each breach is its own event on the log; the rule only sets the outside date.
First, Decide Whether It Was a Breach
Not every incident is a breach, and the log is only for the ones that are. 164.402 defines a breach as "the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information." It then carves out three situations that are not breaches: an unintentional, good-faith access by a workforce member acting within their authority that goes no further; an inadvertent disclosure between two people at the same practice who are both authorized to see PHI; and a disclosure where the practice "has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information."
Outside those three, the rule flips the burden. An impermissible disclosure "is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors": the nature and extent of the PHI, the unauthorized person who received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. That four-factor assessment is a written document, and 164.414(b) puts the burden of proof on the practice to show either that notices were made or that the incident was not a breach.
One more definition matters. The rule covers unsecured PHI, meaning PHI "not rendered unusable, unreadable, or indecipherable to unauthorized persons" through the technology HHS has specified. A lost laptop with full-disk encryption may not be a reportable breach; a lost unencrypted USB drive almost always is. The encryption side is covered in HIPAA encryption requirements, and the first-day response to a missing device is in the lost device incident guide.
Patients Do Not Wait for March
The annual filing is only the HHS piece. The patients themselves are on the normal clock: 164.404(b) requires individual notice "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." Discovery, under 164.404(a)(2), is "the first day on which such breach is known to the covered entity, or, by exercising reasonable diligence would have been known," and the practice is deemed to know what any workforce member knows other than the person who caused the breach. The front desk clerk who noticed the fax error on a Tuesday started the clock on Tuesday.
| Breach size | Notice to individuals | Notice to HHS | Notice to media |
|---|---|---|---|
| Fewer than 500 individuals | Without unreasonable delay, no later than 60 calendar days after discovery (164.404(b)) | Logged; filed within 60 days after the end of the calendar year of discovery (164.408(c)) | Not required |
| 500 or more individuals | Same 60-day rule (164.404(b)) | At the same time as individual notice (164.408(b)) | Required when more than 500 residents of a state or jurisdiction are affected (164.406) |
The individual letter has required contents under 164.404(c): what happened with the dates of breach and discovery, the types of PHI involved, steps the patient should take, what the practice is doing to investigate, mitigate, and prevent recurrence, and contact procedures including "a toll-free telephone number, an e-mail address, Web site, or postal address." It must be "written in plain language" and sent by first-class mail unless the patient has agreed to email. The full notification workflow is in the Breach Notification Rule compliance guide.
What the Log Must Hold
The rule says "a log or other documentation," and leaves the format to the practice. The practical test is whether the log can produce, months later, everything the year-end filing and an OCR inquiry would ask for. That means each row should capture:
- Date of the breach and date of discovery.
- Number of individuals affected, and their names in a linked list.
- What happened: loss, theft, unauthorized access, improper disposal, misdirected communication, hacking.
- Where the PHI was: paper, email, portable device, EHR, a business associate's system.
- Types of PHI involved, mirroring the categories in 164.404(c)(1)(B).
- The four-factor risk assessment, its conclusion, and who signed it.
- Dates and method of individual notice, and a copy of the letter.
- Mitigation taken and safeguards added afterward.
- Whether a business associate was involved and when it notified the practice.
Incidents that were assessed and found not to be breaches belong in a companion incident log with the risk assessment attached, because 164.414(b) makes that assessment the practice's proof. The two logs together are the incident-management record described in the HIPAA incident management guide.
How the Annual Filing Works
"The manner specified on the HHS web site" is the OCR Breach Portal. The portal's own instructions state that OCR "investigates all breaches of protected health information (PHI) and Part 2 records that affect 500 or more individuals," and that "breaches affecting fewer than 500 individuals may be investigated based on Departmental resources and enforcement priorities." The same page notes that a breach of information that is both PHI and a 42 CFR Part 2 record "should be reported separately as a HIPAA breach and a Part 2 breach."
The filing is done by the privacy officer, from the log, in January or February. Each breach on the log is entered as its own report. Keep a copy or screenshot of each confirmation with the log; that confirmation is the practice's proof that 164.408(c) was met. A calendar reminder on the first business day of January, owned by the privacy officer, is the entire system.
What Business Associates Owe You
When the breach happens at a vendor, the vendor's duty is to tell you, and yours is to notify patients and HHS. 164.410(b) requires a business associate to notify the covered entity "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach," and 164.410(c) requires it to identify each affected individual and supply the details the practice needs for its own letters. The annual small-breach filing under 164.408 is written to the covered entity; the practice files, not the vendor.
Sixty days is the regulatory ceiling for the vendor's notice, and it consumes the practice's entire 60-day patient-notice window. Every B.A.A. (Business Associate Agreement) should therefore require notice in days, not weeks. The terms and the pitfalls are in the business associate agreement guide.
OCR Enforces the Small Ones Too
The "fewer than 500" category is not an enforcement-free zone. HHS announced its first HIPAA breach settlement involving fewer than 500 patients on December 31, 2012. Notification timing has been a stand-alone finding since the first enforcement action for lack of timely breach notification settled for $475,000 (January 9, 2017), and OCR secured a $2.175 million settlement after hospitals failed to properly notify HHS of a breach of unsecured PHI (November 26, 2019). As recently as July 29, 2026, a $552,250 ransomware settlement with a healthcare system included late notification to individuals and to HHS among its findings. The pattern OCR punishes is not the incident; it is the incident nobody logged and nobody reported.
State Law Runs on Its Own Clock
The federal 60-day rule is a ceiling, and state breach laws often set shorter deadlines, separate attorney general notices, or different thresholds. The HIPAA log should record which state notices were made and when. The interaction is explained in state privacy laws vs HIPAA; for the specific state, check the statute or ask counsel.
What to Write Into the Policy
- Reporting inside the practice. Every workforce member reports a suspected incident to the privacy officer the same day, because discovery is measured from what any workforce member knew.
- Assessment. The four-factor risk assessment is completed in writing within a set number of days, with the 164.402 exclusions considered first, and signed by the privacy officer.
- Two logs. An incident log for everything reported, and a breach log for the incidents that met the definition, with the fields listed above.
- Individual notice. Letters within 60 days of discovery, sooner where practical, with the 164.404(c) contents, by first-class mail; substitute notice rules for bad addresses.
- Annual HHS filing. Owner, calendar date in early January, portal filing of every breach on the prior year's log before the 60-day mark, confirmations retained.
- Business associates. BAA notice terms shorter than 60 days; vendor breaches entered on the practice's log.
- Retention. Logs, assessments, letters, and filing confirmations kept six years under 164.530(j), which 164.414(a) applies to the Breach Notification Rule.
Three small incidents in a year is normal for a busy practice. Three small incidents with no log and no filing is a finding. The log takes an hour to set up, the filing takes twenty minutes, and the incident management process behind both is the part of a compliance program that gets tested by reality rather than by an auditor.
---
FAQ
When do breaches affecting fewer than 500 people have to be reported to HHS?
Within 60 days after the end of the calendar year in which they were discovered, under 45 CFR 164.408(c). That is March 1 in a non-leap year (February 29 in a leap year). Breaches discovered in 2026 are due by March 1, 2027.
Do patients still have to be notified of a small breach right away?
Yes. 164.404(b) requires individual notice without unreasonable delay and no later than 60 calendar days after discovery, regardless of size. Only the notice to HHS is deferred to the annual filing.
What has to be in the breach log?
The rule requires a log or other documentation. In practice it should hold the dates of breach and discovery, the number of people, what happened and where, the types of PHI, the four-factor risk assessment, notification dates and letters, and mitigation, so the year-end filing and any OCR inquiry can be answered from it.
Is every incident a breach?
No. 164.402 excludes three good-faith situations, and an impermissible disclosure is presumed a breach unless a documented four-factor risk assessment shows a low probability that the PHI was compromised. Incidents found not to be breaches still need the written assessment kept on file.
Does a business associate file the annual small-breach report?
No. 164.408 is written to the covered entity. The business associate must notify the covered entity under 164.410 without unreasonable delay and within 60 days of discovery; the covered entity notifies patients and files with HHS.
Conclusion
The small-breach obligation is a log, a calendar entry, and a 20-minute portal filing once a year, and the practices that miss it are the ones with no log. One Guy Consulting's Full-Scope plan includes the incident management system, the breach notification and incident response policy, and a December reminder to file with OCR for any organization that logged an incident that year, plus consulting time when an incident is a judgment call. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 164.408 (notification to the Secretary)
- 45 CFR 164.402 (breach and unsecured PHI definitions)
- 45 CFR 164.404 (notification to individuals)
- 45 CFR 164.410 (notification by a business associate)
- HHS OCR Breach Portal (what you should know before filing)
Related Reading