Skip to content

HIPAA Breach Notification Rule

What is HIPAA Breach Notification Rule?

Requirements under HIPAA for covered entities and business associates to notify affected individuals, HHS, and media of breaches of unsecured PHI.

Compliance and Regulatory

Each of these is named in at least one of the same controls as hipaa breach notification rule. The number is how many controls name both.

What the standards actually require on hipaa breach notification rule

Requirements naming hipaa breach notification rule across 5 standards, quoted from the control text.

16 CFR 318.1 purpose + scope. APPLICABILITY: applies to (1) VENDORS OF PERSONAL HEALTH RECORDS (PHR) - entities offering PHR product or service to consumers + that obtain consumer health information from other sources (e.g. cross-source aggregation);

HBNR-Scope-PHR-Vendor · Scope, PHR Vendor and PHR-Related Entity Applicability (16 CFR 318.1)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

164.308(a)(6)(ii) · Response and Reporting (Required)
MARS-E1 control

Implement NIST 800-53 IR Incident Response family + breach notification process integrated across HIPAA + ACA + IRS Pub 1075. Incident response capability with 24x7 SOC + Computer Security Incident Response Team (CSIRT) + incident response plan + tabletop and...

MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT · MARS-E Incident Response + Breach Notification + IR Family + 45 CFR 164.400-414 + IRS Pub 1075 + CMS IRT

Implement HIPAA Security Rule Administrative Safeguards for incident response + contingency + evaluation. Security Incident Procedures per 45 CFR 164.308(a)(6): identify and respond to suspected or known security incidents + mitigate harmful effects + document...

NISTSP66-3 · Security Incident Procedures, Contingency Plan, and Evaluation

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

164.308(a)(6)(ii) · Response and Reporting (Required)

Questions people ask about hipaa breach notification rule

What is HIPAA Breach Notification Rule?
Requirements under HIPAA for covered entities and business associates to notify affected individuals, HHS, and media of breaches of unsecured PHI.
Why is HIPAA Breach Notification Rule important for compliance?
HIPAA Breach Notification Rule is a key concept in Compliance and Regulatory. Understanding hipaa breach notification rule helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address HIPAA Breach Notification Rule?
HIPAA Breach Notification Rule appears in the requirement text of FTC Health Breach Notification Rule, HIPAA Security Rule, MARS-E, NIST SP 800-66, NIST SP 800-66 Rev 2. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about HIPAA Breach Notification Rule?
Explore our compliance framework pages to see how hipaa breach notification rule applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how HIPAA Breach Notification Rule applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.