HIPAA Breach Notification Rule
What it does, who it protects, and how to invoke it. Plain English.
Who it protects
Patients of any HIPAA-covered entity (hospitals, doctors' offices, EMS services, health plans). For first responders treated at covered facilities: you are the patient too.
What it does
Requires covered entities to notify you in writing within 60 days when your protected health information is breached. Breaches affecting 500 or more people also trigger notice to HHS and to a major media outlet in the affected area.
How to invoke it
Passive. The rule binds the covered entity, not you. If you suspect a breach happened and you weren't notified, file a complaint with the HHS Office for Civil Rights at hhs.gov/ocr. The complaint can trigger an OCR investigation.
Enforcement reality
OCR investigates and can impose civil penalties up to roughly $2M per violation category per year. Settlements have ranged from low six figures to $16M (Anthem, 2018). No private right of action under HIPAA itself; some states (CA, IL) have parallel laws that do allow private suits.
What the Breach Notification Rule does
The HIPAA Breach Notification Rule (45 CFR §§ 164.400-414) was added to HIPAA in 2009 by the HITECH Act. In plain terms: when a hospital, clinic, EMS service, insurer, or any other HIPAA-covered entity has your medical data exposed, they have to tell you in writing within 60 days.
Notification is mandatory. The covered entity has to tell each affected patient by mail, or by email if you've consented to electronic notice. If the breach involved more than 500 people, they also have to notify the U.S. Department of Health and Human Services and a major media outlet in the affected area. HHS posts breaches of 500 or more records to its public breach portal at ocrportal.hhs.gov.
The data that gets exposed is exactly the data first responders try to keep private: home address, date of birth, Social Security number, insurance ID, sometimes diagnoses and treatment history. The notice is the trigger that lets you do everything downstream: broker opt-outs, fraud alerts, and credit freezes.
Why this matters for nurses and EMS specifically
Nurses, paramedics, EMTs, and any first responder treated at a covered facility sit on both sides of the rule. You're a provider when you're working. You're a patient when you've been to the ER, when your insurer ran your annual labs, or when you delivered your kid at the hospital where you happen to also work.
That dual exposure matters because most healthcare breaches start on the employer or insurer side. The 2024 Change Healthcare breach hit roughly 190 million people through their insurers and providers, the largest healthcare breach on record. The 2015 Anthem breach exposed 79 million records and produced a $16M HHS settlement. Healthcare workers were inside both numbers, both as employees of the affected entity and as patients in the affected population.
If your hospital system or insurer is breached, you'll get the notice as a patient. The notice is your trigger. Don't ignore it.
What the notification has to tell you
The rule is specific. Each notice must include:
- A brief description of what happened
- The types of information involved (name, address, SSN, diagnosis, and so on)
- Steps you should take to protect yourself
- What the covered entity is doing to investigate, mitigate, and prevent recurrence
- Contact information so you can ask questions
If a notice is missing any of those, that's a separate Breach Notification Rule violation. The inadequate notification is a second hook for OCR, on top of the breach itself.
How to invoke
You don't invoke this rule directly. The rule binds the covered entity, and they have to notify you. Your role is reactive, with two paths:
- You got a notice. Document it. Save the letter and note the date. Use the disclosed data categories to decide what downstream action to take: a broker sweep, a credit freeze, fraud alerts, or a change of insurance ID where possible.
- You suspect a breach happened and you weren't notified. File a complaint with the HHS Office for Civil Rights at hhs.gov/ocr. The complaint form is online. OCR reviews it and decides whether to investigate.
Either way, the breach notice is one piece of evidence. It tells you what data was exposed. It does not tell you whether that data made it into the broker pipeline. Run a scan after a breach notice. If your address shows on a broker site that wasn't carrying it before, the breach may have traveled.
Enforcement reality
The HHS Office for Civil Rights investigates. Civil penalties run up to roughly $2M per violation category per calendar year. Settlements vary widely:
- Anthem (2018): $16M, 79 million records, the largest HIPAA settlement on record
- Premera Blue Cross (2020): $6.85M, 10.4 million records
- Excellus Health Plan (2021): $5.1M, 9.3 million records
- Memorial Healthcare System (2017): $5.5M
The pattern: large breaches draw million-dollar settlements. Smaller breaches at clinics and small practices tend to draw six-figure settlements or corrective action plans without a financial penalty.
There is no private right of action under HIPAA itself. You cannot sue your hospital under federal HIPAA when they breach your data. You can only file with OCR.
Some states do allow private suits under parallel statutes. California (CMIA) and Illinois (BIPA, where biometrics are involved) are the two most active. If you live in those states and your covered entity was breached, ask a privacy attorney whether you have a state claim that HIPAA itself wouldn't give you.
Where it doesn't reach
The rule binds covered entities and their business associates. It does not reach:
- Direct-to-consumer health apps. Fitness trackers, period-tracking apps, and mental health platforms that aren't tied to a covered entity run under FTC rules, not HIPAA.
- Genetic testing services. 23andMe and similar services are not HIPAA-covered. The 2023 23andMe breach was handled under state breach laws, not HIPAA.
- Data the covered entity legitimately disclosed. If your hospital sold de-identified data to a research aggregator and the aggregator was breached, that's a different chain of liability.
- Public-records exposures. If your home address and DOB show on a broker site, HIPAA doesn't reach that. Broker opt-outs do.
What to do after a breach notice
The 60-day clock starts when the covered entity discovers the breach. By the time you get the notice, the data has been exposed for somewhere between a few days and a few months.
Your downstream steps:
- Read the notice. Note exactly which data categories were exposed: SSN, address, DOB, insurance ID, diagnosis.
- Place a credit freeze at all three bureaus. It's free and takes about 10 minutes per bureau. See the FCRA page for the mechanics.
- Run a broker scan. Compare it to any prior scan you have. If new addresses or new aggregations appear, the breach data may have entered the broker pipeline.
- File the OCR complaint if the notice was late, incomplete, or you suspect the breach was larger than disclosed. The complaint form is at hhs.gov/ocr.
- Save the letter. A breach notice is the documentary trigger for any state civil claim you might pursue.
What we do
We can't file the HIPAA complaint for you. That's the patient's path through HHS. We do run the downstream broker side. After a healthcare breach, the address and date-of-birth pair is the highest-value combination attackers reuse. We check broker sites on a continuous basis and refile when your information reappears. If you've gotten a breach letter recently, run a scan and we'll show you what's already exposed.