Guide · 5 pages

Patient Data Breach Notification Guide for Dental Practices

What HIPAA's Breach Notification Rule actually requires, on what timeline, and who has to be told when patient data is exposed.

Breach notification is one of the most time-sensitive and easiest-to-get-wrong parts of a security incident. The technical cleanup -- restoring systems, resetting passwords, rebuilding a server -- can take as long as it takes. Notification cannot. The clock on your legal obligations starts the moment your practice discovers, or reasonably should have discovered, that patient data may have been exposed, and it keeps running whether or not you have decided what happened yet.

The mistakes we see are rarely about bad intentions. They are about sequence: a practice spends three weeks confirming exactly what was accessed before telling anyone, not realizing the notification clock started on day one. Or a practice assumes a stolen laptop is automatically a breach, without checking whether the drive was encrypted, which under federal law can make the difference between no obligation at all and notifying every patient on it.

This guide walks through the decision points in order: whether you have a reportable breach, who you have to notify and by when, and what to keep on file afterward. It is a map, not a legal opinion on your specific incident.

Not every security incident is a reportable breach. HIPAA presumes an impermissible use or disclosure of unsecured PHI is a breach unless a documented risk assessment shows a low probability the data was compromised. The presumption runs against you -- you have to prove the low-risk case, not the other way around.

Work through these four questions in order, and write down your reasoning as you go. This becomes your risk assessment, and it is the document an investigator or your attorney will ask for first.

When in doubt, treat it as reportable If you cannot document a low-probability-of-compromise finding for all four factors, the safer and legally correct posture is to treat the incident as a reportable breach and move on to notification. A defensible "we assessed it and it wasn't reportable" file protects you; a guess does not.

  • Is it a reportable breach? 45 CFR 164.402
  • Was PHI actually acquired, accessed, or viewed -- not just theoretically exposed? An unlocked cabinet nobody opened is different from one a former employee photographed. If you can show, with evidence, that no one actually acquired or viewed the data, that weighs toward low risk. "We don't think so" without evidence does not.
  • Was the data encrypted, or otherwise rendered unreadable, at the time of exposure? This is the single biggest factor. Properly encrypted PHI on a lost or stolen device is generally not a reportable breach at all, because it meets HIPAA's safe harbor for unsecured PHI. Unencrypted, the same lost laptop is presumed reportable.
  • Who received or could have accessed the information -- another covered entity, a stranger, or the public internet? Data sent to the wrong provider's office under a Business Associate Agreement is lower risk than the same data posted publicly or sent to an unknown outside party. Consider whether the recipient had any independent obligation to protect it.
  • Has the risk been mitigated -- for example, was the device recovered, was access revoked, or did the recipient confirm deletion? A wrong-recipient email where the recipient confirmed deletion in writing before opening it is a materially different situation than one where you never heard back. Document what you did and when.

Notifying patients

Once you have determined a breach occurred, patient notification is not optional and it is not something to delay while you finish investigating. The clock starts at discovery, not at the conclusion of your investigation.

You must notify each affected individual without unreasonable delay, and no later than 60 calendar days after discovery of the breach. "Discovery" is the date the breach became known, or reasonably should have

become known -- not the date you finished figuring out exactly what happened. If your investigation is still open on day 55, you still notify by day 60 with the best information you have, and follow up if the picture changes.

What the notification letter must include • A brief description of what happened, including the date of the breach and the date it was discovered, if known. • A description of the types of information involved (name, Social Security number, diagnosis, treatment information, insurance details, and so on). • Steps the individual should take to protect themselves from potential harm. • A description of what the practice is doing to investigate, mitigate harm, and prevent further breaches. • Contact information for questions, including a toll-free number, email address, website, or postal address.

Delivery method • First-class mail to the individual's last known address is the default method, addressed to the individual (or, for a deceased individual, to the next of kin or personal representative if known). • Email is permitted only if the individual has previously agreed to receive notices electronically and that agreement has not been withdrawn. • For an urgent situation involving possible imminent misuse of the information, notice may also be provided by telephone or other means, in addition to -- not instead of -- written notice.

Substitute notice, when contact information is insufficient If you lack current contact information for ten or more affected individuals, substitute notice must include either a conspicuous posting on your website's home page for at least 90 days, or notice in major print or broadcast media in the geographic areas where the individuals likely reside, plus a toll-free number active for at least 90 days. For fewer than ten individuals with insufficient contact information, an alternative form of written notice, telephone call, or other means is acceptable.

Notifying HHS

Every breach of unsecured PHI must be reported to the Department of Health and Human Services -- the question is only when, and it depends entirely on how many individuals were affected.

Breaches are reported to HHS through the Office for Civil Rights breach portal. The size of the breach determines the timeline, and getting this wrong -- treating a 500+ breach like a small one -- is a common and costly mistake.

BREACH SIZE WHO TO NOTIFY DEADLINE

500 or more HHS (individual report, not the annual log) and Within 60 days of discovery individuals prominent media outlets serving the affected state or jurisdiction

BREACH SIZE WHO TO NOTIFY DEADLINE

Fewer than 500 HHS, via the annual breach log Within 60 days after the end of the individuals calendar year in which the breach was discovered

Any size Affected patients (see Section 2) Within 60 days of discovery, regardless of breach size

Keep a running log all year Even a single small breach in January needs to be on the annual log HHS expects the following spring. Start the log the moment the first incident happens, rather than trying to reconstruct the year from memory in December.

Notifying the media

The step practices are most likely to forget, because it only applies once a breach crosses the 500- person threshold -- and by then, everything else in the response is already consuming attention.

If a breach affects 500 or more residents of a single state or jurisdiction, you must also notify prominent media outlets serving that state or jurisdiction, in addition to notifying HHS and the affected individuals directly. This typically means a press release to major television, radio, or newspaper outlets covering the area, provided without unreasonable delay and no later than 60 days after discovery -- the same clock as patient notification, run in parallel, not after it.

This step is often missed Practices that clear the 500-person threshold usually remember to notify HHS and patients, because those obligations are the ones most often discussed. Media notification gets overlooked, partly because it feels counterintuitive to publicize a breach and partly because it simply is not top of mind under pressure. Skipping it is a separate compliance failure on top of the breach itself -- confirm the threshold early, and if you are close to 500, plan for it rather than finding out afterward that you needed to.

Documentation to keep

HIPAA requires breach-related documentation to be retained for six years from the date it was created or the date it was last in effect, whichever is later. Build the file as you go -- reconstructing it afterward from memory is much harder and much less convincing.

• The written risk assessment used to determine whether the incident was a reportable breach, including the reasoning for each of the four factors. • Copies of every patient notification letter sent, along with the date and method of delivery for each. • Proof of substitute notice, if used -- screenshots of the website posting with dates, or records of media/ toll-free-line placement.

• Confirmation of the HHS submission -- the individual breach report for a 500+ incident, or the completed entry on the annual log for a smaller one. • Proof of media notification, for breaches affecting 500 or more individuals in one state or jurisdiction. • A record of the remediation steps taken -- what was fixed, patched, re-secured, or changed as a result of the incident. • Any communications with your cyber liability insurance carrier and with legal counsel regarding the incident. • A timeline of the incident itself: date of the underlying event, date of discovery, and dates of each notification sent.

Want the printable version?

Get the full guide as a free PDF

Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.

Download the free PDF
Call Book a Fit Call