HIPAA Compliance After a Data Breach: Recovery and Remediation Steps

The hours after you discover a breach are not the time to learn what HIPAA expects of you. What makes post-breach compliance distinct from everyday HIPAA work is that a clock starts the moment a breach is discovered, and a separate set of obligations under the Breach Notification Rule (45 CFR §§ 164.400–414) overlays everything else you do. Recovery is not just restoring systems; it is documenting, notifying, and proving you fixed the underlying cause.

First: determine whether it is actually a reportable breach

Not every impermissible disclosure triggers notification. Under HIPAA, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you can document a four-factor risk assessment showing a low probability that the PHI was compromised: the nature and extent of the data involved, who used or received it, whether it was actually acquired or viewed, and how well the risk has been mitigated. If the data was encrypted to HHS standards, it is generally not “unsecured,” and the breach obligations may not apply. Document this analysis either way — the determination itself is part of your compliance record.

The notification timeline you have to hit

If it is a reportable breach, the size dictates the path. Breaches affecting fewer than 500 individuals require individual notice without unreasonable delay (and no later than 60 days from discovery) and are logged for an annual submission to HHS. Breaches affecting 500 or more residents of a state require individual notice, notice to prominent media in the affected area, and contemporaneous notice to HHS — all within 60 days. Affected business associates must notify covered entities so those clocks can start. Missing these windows is one of the most avoidable HIPAA violations.

Remediation: close the gap, do not just notify

Notification is the visible step; remediation is what actually satisfies HIPAA. The Security Rule requires a risk analysis under 45 CFR § 164.308(a)(1)(ii)(A), and after a breach that Security Risk Analysis becomes the centerpiece of your recovery. You use it to trace the breach to a root cause — an unpatched server, a phished credential, a missing business associate agreement — and then to drive a risk management plan that closes it. The Office for Civil Rights routinely requests your risk analysis and corrective-action evidence during an investigation, and a missing or outdated one is itself a common, citable finding. A breach where you can show you found and fixed the gap looks very different to OCR than one where you cannot.

What the proposed 2026 Security Rule update would change

HHS published a Notice of Proposed Rulemaking in December 2024 that would significantly strengthen the HIPAA Security Rule — making controls like encryption, multi-factor authentication, and more rigorous, regularly updated risk analyses explicit requirements rather than “addressable” ones. It is a proposal, not final: if adopted, organizations would have a 240-day compliance window once the final rule is published. Many of its provisions map directly to the failures that cause breaches in the first place, so aligning now both reduces breach risk and gets you ahead of the rule.

How Medcurity helps

Medcurity gives you a guided, audit-ready Security Risk Analysis and risk management workflow — the exact documentation OCR asks for after a breach — so you can show root-cause analysis and corrective action instead of scrambling to assemble it. The platform is $499/year (about $42/month) for most practices; larger or multi-entity organizations can request a quote. Building your risk analysis before an incident is what turns a breach response from chaos into a documented, defensible process. For prevention and response planning, see our HIPAA incident response plan guide and the HIPAA compliance checklist.

Frequently asked questions

How long do we have to notify patients after a breach?

For breaches affecting fewer than 500 individuals, you must notify each affected person without unreasonable delay and no later than 60 calendar days from discovery, and log the breach for the annual report to HHS. Breaches affecting 500 or more residents of a state or jurisdiction require notice to individuals and prominent media within 60 days, plus contemporaneous notice to HHS (not the annual log).

Is every loss of data automatically a reportable breach?

No. An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you document a four-factor risk assessment showing a low probability that the information was compromised. The factors are the nature and extent of the PHI, who received or accessed it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Properly encrypted data that is lost is generally not a reportable breach.

Does notifying patients close out our HIPAA obligation?

No. Notification is only the visible step. The Office for Civil Rights expects you to identify the root cause through your risk analysis, remediate the vulnerability that allowed the breach, update policies, and retrain workforce. OCR commonly requests your most recent Security Risk Analysis during a breach investigation, and a missing or stale one is itself a frequent finding.

What does OCR look for in a post-breach investigation?

OCR typically asks for your risk analysis, risk management plan, breach notification records, and evidence of corrective action. Demonstrating that you found the gap, fixed it, and can show documentation carries more weight than the breach itself. Cooperation and a current, enterprise-wide Security Risk Analysis materially affect the outcome.