HIPAA Breach Notification Rule
45 CFR Part 164, Subpart D (Sections 164.400-164.414)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 23 September 2009.
A breach notification rule binding public and private bodies.
As of 23 August 2026.
What it requires
- Notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information.
- Notify HHS, and for a breach affecting more than 500 residents of a state, prominent media outlets serving that state.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Knowingly and in violation of HIPAA obtaining or disclosing individually identifiable health information, when done with intent to sell, transfer, or use it for commercial advantage, personal gain, or malicious harm, is a federal crime under 42 U.S.C. 1320d-6(b)(3): a fine of up to $250,000 and imprisonment of up to 10 years, or both.
Penalty structure
45 CFR 160.404 sets four culpability tiers per violation, adjusted for inflation annually and published at 45 CFR 102.3 (2025 figures shown): (i) no knowledge and no reasonable diligence would have revealed the violation, $145 to $73,011 per violation; (ii) reasonable cause, not willful neglect, $1,461 to $73,011; (iii) willful neglect, corrected within 30 days, $14,602 to $73,011; (iv) willful neglect, not corrected within 30 days, $73,011 up to the annual cap. Every tier is subject to a $2,190,294 annual cap for identical violations of the same administrative simplification provision in a calendar year.
- Rule
- Per violation only
- As of
- 2 September 2026
- Minimum
- 145
- Currency
- USD
- Fixed cap
- 2,190,294
- Per violation unit
- Violation
- Per violation amount
- 2,190,294
Who enforces it
Enforcement body
HHS Office for Civil Rights
Enforcement record
Counts resolution agreements and civil money penalties HHS OCR's own published Resolution Agreements list dates to calendar year 2025 (25 actions), the latest complete calendar year the list covers, up from 14 in 2024; 5 more had posted for 2026 by the list's last review date of August 27, 2026. OCR's separate Enforcement Highlights page states a cumulative program total, as of October 31, 2024, of 152 settlements or civil money penalties totaling $144,878,972 since the Privacy Rule's 2003 compliance date; that cumulative total is not used here because it predates the 2025 and 2026 actions counted above and the two pages are not reconciled to a single running total. No per-case fine amounts are aggregated into a fines total here.
- As of
- 2 September 2026
- Trend
- Rising
- Source link
- https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
- Actions per year
- 25
What it reaches
Obligation class
Breach notice
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Requires a covered entity to notify each affected individual, and in some cases HHS and the media, following discovery of a breach of unsecured protected health information, without unreasonable delay and no later than 60 calendar days after discovery. First effective under a 2009 interim final rule; the 2013 Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule finalized these requirements with a general compliance date of September 23, 2013.
When LexLint raises it
handles_health_records
Read the law
eCFR, current regulatory text, 45 CFR Part 164 Subpart D
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.