HIPAA Breach Notification Deadline Calculator

Know your breach notification deadlines to the day.

Enter the date the breach was discovered and how many people are affected. The calculator shows federal outer-limit dates for individual and HHS notice and flags when you need a separate State-or-jurisdiction count for media notice. It also shows the rule behind each date and a live countdown. Free, private, and no account required.

60day federal outer limit
500HHS large-breach threshold
0data leaves your browser

The calculator

Calculate federal outer-limit dates from one date

Pick your role, enter the discovery date, and set the national number of individuals affected. The tool applies the HHS threshold, separately flags the media test, and shows how many days remain to each federal outer limit.
1. Who are you in this breach?

Your role decides who you must notify. A covered entity notifies individuals, HHS, and sometimes the media. A business associate notifies the covered entity it works for.

2. When was the breach discovered?

The clock starts on the day the breach is discovered, or the day you would have known with reasonable diligence, not the day it actually happened.

3. How many individuals are affected?

A national total of 500 changes the HHS reporting timeline. Media notice uses a separate test: more than 500 residents of one State or jurisdiction.

individuals affected

Exactly 500 affected: notify HHS on the individual-notice timeline. The federal media threshold is more than 500 residents of one State or jurisdiction, so this total alone cannot trigger media notice.

Deadlines are the federal outer limits in the HIPAA Breach Notification Rule at 45 CFR 164.404, 164.406, 164.408, and 164.410. Many state laws impose shorter notice windows and their own thresholds. Notification applies to a breach of unsecured PHI. Section 164.402 includes three exceptions and permits a documented four-factor assessment to rebut the presumption of breach by showing a low probability that PHI was compromised. This tool is educational, does not decide whether an incident is a breach, does not account for state law, and is not legal advice. Confirm your obligations with counsel.

What it shows

Six things this breach deadline tool makes clear

The calculator applies federal timing rules from the HIPAA Breach Notification Rule. It is a planning aid, not a determination that an incident is a reportable breach.

Discovery clock

When the 60 days actually start

The clock starts the day a breach is discovered, or the day it would have been known with reasonable diligence, not necessarily the incident date. The tool calculates federal outer limits from there.

Individual notice

The federal outer limit for individual notice

Written notice is due without unreasonable delay and no later than 60 calendar days after discovery under 45 CFR 164.404. The tool calculates that outer-limit date.

The 500 threshold

Two thresholds that must stay separate

HHS uses 500 or more affected individuals nationwide. Media notice uses more than 500 residents of one State or jurisdiction. The tool keeps those tests distinct.

HHS reporting

Two different HHS deadlines

Large breaches go to the HHS Secretary within 60 days. Smaller breaches go on a log submitted within 60 days after the end of the calendar year. The tool shows the one that applies to you.

Business associates

Your duty to the covered entity

A business associate notifies the covered entity it works for, no later than 60 days after discovery under 45 CFR 164.410. The tool covers both sides of that relationship.

Days remaining

A live countdown to each outer limit

Each calculated date shows how many days remain from today and flags dates within two weeks or already past. Notice may be required sooner because the rule also requires no unreasonable delay.

The full picture

How the HIPAA breach notification timeline actually works

A plain-English guide to discovery, individual and HHS notice, the separate media threshold, business associate duties, and the analysis needed before treating an incident as a reportable breach.

When the clock starts: the day of discovery

Every deadline in the HIPAA Breach Notification Rule runs from one moment: the day the breach is discovered. The rule, at 45 CFR 164.404(a)(2), defines that day precisely. A breach is treated as discovered on the first day it is known to the organization, or the first day it would have been known by exercising reasonable diligence. Just as important, the breach is treated as known to the organization if any workforce member or agent, other than the person who caused the breach, knew or reasonably should have known about it. In other words, the clock does not politely wait until the news climbs the org chart to the privacy officer. If a help-desk technician saw the alert in March, the organization discovered the breach in March, even if leadership only heard about it in May.

This is why the discovery date, and not the incident date, is the input that drives this calculator. An attacker may have been inside a system for months before anyone noticed, but the 60-day clock does not start at intrusion. It starts at detection, real or constructive. The practical takeaway is that the speed of your monitoring and the clarity of internal escalation affect how much time remains for analysis and notice. A delay between workforce discovery and escalation does not restart the federal clock, so incident procedures should route reports promptly to the people responsible for breach analysis and notification.

Notice to individuals: the core 60-day deadline

The central obligation, and the one the calculator surfaces first, is notice to the affected individuals. Under 45 CFR 164.404(b), a covered entity must notify each individual whose unsecured protected health information was, or is reasonably believed to have been, involved in the breach. The deadline is without unreasonable delay and in no case later than 60 calendar days after discovery. Notice normally goes by first-class mail to the individual's last known address, or by email if the individual previously agreed to electronic notice. When you lack current contact information for ten or more individuals, the rule requires substitute notice, such as a conspicuous posting on your website for 90 days or notice in major print or broadcast media in the area.

The content of the notice is prescribed, not freeform. It must describe what happened and the date of the breach and its discovery, the types of information involved, the steps individuals should take to protect themselves, what the organization is doing to investigate and mitigate and prevent recurrence, and how to ask questions, including a toll-free number, email, website, or postal address. Writing that letter well takes time, legal review, and coordination with whatever credit monitoring or remediation you offer, which is one more reason the 60 days fills up faster than teams expect. The calculator dates the outer limit so you can work backward to when drafting and approval actually need to start.

The HHS and media thresholds are not the same

The total number of affected individuals determines which HHS reporting timeline applies. A breach affecting 500 or more individuals nationwide must be reported to the HHS Secretary contemporaneously with individual notice and no later than 60 days after discovery. A breach affecting fewer than 500 individuals follows the log and year-end reporting rule in 45 CFR 164.408(c).

Media notice uses different language and geography. Section 164.406 applies when a breach affects more than 500 residents of one State or jurisdiction. A nationwide total of exactly 500 triggers the contemporaneous HHS timeline but cannot trigger the media rule. A larger nationwide count may still fall below the media threshold in every jurisdiction. This calculator uses the nationwide total for HHS and flags the media question only when that total is high enough to make the separate test possible.

Notice to HHS: two very different deadlines

Reporting to the Secretary of Health and Human Services, handled through the Office for Civil Rights breach portal, runs on one of two timelines depending entirely on that 500 threshold. For a breach affecting 500 or more individuals, 45 CFR 164.408(b) requires you to notify the Secretary contemporaneously with the notice to individuals and in no case later than 60 days after discovery. HHS publishes information about reported breaches affecting 500 or more individuals on its breach portal.

For breaches affecting fewer than 500 individuals, 45 CFR 164.408(c) takes a different approach. You are not required to report each small breach to HHS within 60 days. Instead the covered entity must maintain a log of all breaches discovered during the calendar year and notify the Secretary no later than 60 days after the end of the calendar year. The calculator computes that year-end-plus-60 date for you when the affected count is below 500. The important distinction is that the year-end HHS timeline applies only to the HHS report. Individual notice for a small breach still runs on the same 60-day clock as a large one, and you should record each small breach in your log when it happens rather than scrambling to reconstruct a year of incidents the following February.

Notice to the media: a separate geographic test

Media notification under 45 CFR 164.406 applies only when a breach affects more than 500 residents of one State or jurisdiction. When that test is met, the covered entity must notify prominent media outlets serving that area, without unreasonable delay and no later than 60 days after discovery. The rule does not prescribe one universal communication format, so the entity should identify outlets that serve the affected area and confirm its approach with counsel. This is distinct from substitute individual notice under 45 CFR 164.404(d).

When the total affected population exceeds 500, the calculator asks for the largest number of affected residents in one State or jurisdiction. It shows media notice as applicable only when that geographic count is more than 500. Confirm the count and affected area before relying on the result.

Business associates: a separate clock that a contract may shorten

If you are a business associate rather than a covered entity, your obligation is different and the calculator reflects it. Under 45 CFR 164.410, a business associate that discovers a breach of unsecured protected health information must notify the covered entity, without unreasonable delay and no later than 60 days after discovery. The notice must identify each individual whose information was or is believed to have been involved, to the extent possible, and provide the other information the covered entity needs to make its own notifications. The business associate generally does not notify patients, HHS, or the media directly; it hands the covered entity what it needs to do so.

The federal outer limit is 60 days, but a business associate agreement may require earlier notice. When the agreement sets a shorter window, the parties must account for both regulatory and contractual duties. Review those terms before an incident and follow the applicable earlier requirement.

Before any clock runs: is it even a reportable breach?

Before using any date in this calculator, determine whether the incident involves unsecured PHI and whether it meets the definition of breach. Section 164.402 contains three exceptions. If no exception applies, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless the organization demonstrates a low probability that the PHI was compromised through a four-factor assessment. The factors address the nature and extent of the PHI, the unauthorized person, whether the PHI was acquired or viewed, and the extent of mitigation.

The three exceptions cover limited circumstances involving good-faith workforce access, certain inadvertent disclosures between authorized people, and disclosures where the recipient could not reasonably retain the information. Encryption removes data from unsecured-PHI status only when it uses an HHS-specified method that renders the information unusable, unreadable, or indecipherable and the confidential process or key was not also compromised. Keep a contemporaneous record of the facts, any exception, the four factors when used, and the resulting decision. This calculator does not make that legal determination.

Turning the deadlines into a plan

Federal outer-limit dates help assign owners and plan several possible notice streams under time pressure. Use the calculator after identifying the discovery date: enter that date, set the nationwide affected count, and review the dates and conditional media check. Then account for the rule's no-unreasonable-delay standard, state law, contractual duties, fact development, legal review, and operational lead time. A worked example shows why the dates matter. Say a clinic discovers on March 1 that a vendor exposed records for 1,200 patients in a single state. The calculator shows April 30 as the federal outer limit for individual, HHS, and media notice. That date does not authorize waiting until then. The response may require confirmation of scope, an executive briefing, legal review of the letter, a vendor for printing and mailing, a call center for questions, and coordination of media notice. Assign owners and sequence that work based on the facts.

Preparation cannot guarantee that an incident will not occur, but it can reduce preventable handling errors and shorten the time between discovery and escalation. Use a risk analysis to prioritize safeguards, give workforce members a clear reporting process, document role-relevant training, and assign owners for each notice stream before an incident. Those controls support a faster, better documented response without treating training as a substitute for technical safeguards, vendor oversight, or legal review.

Keep going

Guides and tools for the rest of the response

Once you know the deadlines, these pages help you decide whether an incident is reportable, document the risk analysis, close the gaps that cause breaches, and train the team that has to catch them.

Breach notification FAQ

Common questions about HIPAA breach notification deadlines

Is this HIPAA breach notification calculator free?

Yes. The calculator is free, runs entirely in your browser, and needs no account or email. Choose your role, enter the discovery date and nationwide number of affected individuals, and it calculates federal outer-limit dates with a conditional media check. Nothing you enter leaves your device.

When does the 60-day clock actually start?

It starts on the day the breach is discovered, which the rule defines as the first day the breach is known, or by exercising reasonable diligence would have been known, to the covered entity or business associate. A breach is treated as discovered by the organization if any workforce member or agent, other than the person who committed the breach, knew or should have known about it. The clock does not wait for senior leadership to be told, so your detection and internal escalation speed matters as much as the calendar.

Is the deadline really 60 days, or sooner?

Sixty calendar days is the federal outer limit, not a waiting period. Sections 164.404, 164.406, and 164.410 require applicable notice without unreasonable delay and no later than 60 days after discovery. Use the calculated date for planning, then determine the earliest reasonable timing from the facts, your contract, and any shorter state-law requirement.

What changes when 500 or more individuals are affected?

At 500 or more affected individuals nationwide, the covered entity must notify the HHS Secretary contemporaneously with individual notice and no later than 60 days after discovery rather than using the year-end reporting timeline. Media notice has a different test: it applies only when more than 500 residents of one State or jurisdiction are affected. A total of exactly 500 cannot meet that media threshold.

How do I report a breach affecting fewer than 500 people?

You still must notify affected individuals without unreasonable delay and no later than 60 days after discovery. Under 45 CFR 164.408(c), the covered entity must maintain a log of breaches affecting fewer than 500 individuals and notify the HHS Secretary no later than 60 days after the end of the calendar year in which each breach was discovered. You may report earlier and should record each event when it occurs.

What is the deadline for a business associate?

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery under 45 CFR 164.410. The notice must identify each affected individual to the extent possible and provide available information the covered entity needs for its notices. A business associate agreement may require earlier reporting, so review both the rule and the contract.

Does every security incident require notification?

No. The Breach Notification Rule applies to breaches of unsecured PHI and 45 CFR 164.402 contains three exceptions. When an impermissible use or disclosure of unsecured PHI does not fit an exception, it is presumed to be a breach unless a documented four-factor assessment demonstrates a low probability that the PHI was compromised. Encryption avoids unsecured-PHI status only when the data is rendered unusable, unreadable, or indecipherable using an HHS-specified method and the confidential process or key was not also compromised. Document the analysis.

What happens if we miss a notification deadline?

Missing a deadline can be a separate HIPAA violation, and a pattern of late or absent notice can increase enforcement risk and may bear on culpability depending on the facts. Late notice can also add state-law, litigation, and trust consequences. A documented incident-response plan should assign owners to each notice stream, while workforce training should give people a clear path to escalate possible incidents early enough to leave time for the required analysis and notices.

Prepare the people who may need to recognize and escalate an incident. Start with HIPAA certification or plan a team rollout for everyone who touches PHI.

Prepare the workforce

Training helps teams recognize and escalate incidents.

Role-relevant training gives workforce members a process for recognizing and escalating possible incidents. Train your team with a course that produces dated, verifiable certificates, and keep those records with your incident-response documentation.