Law / United States

HIPAA Breach Notification Rule

45 CFR Part 164, Subpart D (Sections 164.400-164.414)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 23 September 2009.

A breach notification rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • Notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information.
  • Notify HHS, and for a breach affecting more than 500 residents of a state, prominent media outlets serving that state.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Knowingly and in violation of HIPAA obtaining or disclosing individually identifiable health information, when done with intent to sell, transfer, or use it for commercial advantage, personal gain, or malicious harm, is a federal crime under 42 U.S.C. 1320d-6(b)(3): a fine of up to $250,000 and imprisonment of up to 10 years, or both.

Penalty structure

45 CFR 160.404 sets four culpability tiers per violation, adjusted for inflation annually and published at 45 CFR 102.3 (2025 figures shown): (i) no knowledge and no reasonable diligence would have revealed the violation, $145 to $73,011 per violation; (ii) reasonable cause, not willful neglect, $1,461 to $73,011; (iii) willful neglect, corrected within 30 days, $14,602 to $73,011; (iv) willful neglect, not corrected within 30 days, $73,011 up to the annual cap. Every tier is subject to a $2,190,294 annual cap for identical violations of the same administrative simplification provision in a calendar year.

Rule
Per violation only
As of
2 September 2026
Minimum
145
Currency
USD
Fixed cap
2,190,294
Per violation unit
Violation
Per violation amount
2,190,294

Who enforces it

Enforcement body

HHS Office for Civil Rights

Enforcement record

Counts resolution agreements and civil money penalties HHS OCR's own published Resolution Agreements list dates to calendar year 2025 (25 actions), the latest complete calendar year the list covers, up from 14 in 2024; 5 more had posted for 2026 by the list's last review date of August 27, 2026. OCR's separate Enforcement Highlights page states a cumulative program total, as of October 31, 2024, of 152 settlements or civil money penalties totaling $144,878,972 since the Privacy Rule's 2003 compliance date; that cumulative total is not used here because it predates the 2025 and 2026 actions counted above and the two pages are not reconciled to a single running total. No per-case fine amounts are aggregated into a fines total here.

As of
2 September 2026
Trend
Rising
Source link
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
Actions per year
25

What it reaches

Obligation class

Breach notice

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Requires a covered entity to notify each affected individual, and in some cases HHS and the media, following discovery of a breach of unsecured protected health information, without unreasonable delay and no later than 60 calendar days after discovery. First effective under a 2009 interim final rule; the 2013 Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule finalized these requirements with a general compliance date of September 23, 2013.

When LexLint raises it

  • handles_health_records

Read the law

eCFR, current regulatory text, 45 CFR Part 164 Subpart D

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app