Research · 12 min read

Who Else Finds Out When Health Records Leak

The person whose records these are is one recipient among several, and the thresholds deciding the others do not line up. A breach affecting exactly five hundred people reaches the regulator, the newsroom and the public list in three different ways.

Key takeaways

  • An individual notice is one output of a system that can also require media notice, notice to the Secretary, and notice passed between companies.
  • Media notice under the health privacy rule turns on more than five hundred residents of a single State or jurisdiction, counted by State rather than by total people.
  • The consumer-facing rule words its own media trigger as five hundred or more residents, so the two rules separate at exactly one person.
  • Notice to the Secretary is required for every breach; size decides only whether it is contemporaneous or reported in an annual batch within sixty days of year end.
  • The statutory duty to publish a list of entities is narrower still, reaching breaches of more than five hundred individuals.
  • A business associate must tell the covered entity and identify each affected individual to the extent possible, which is how a notice reaches you from a company you never chose.
  • A law enforcement statement can delay every notice in the subpart, for a specified period in writing or for no more than thirty days if made orally.

Answer first: the letter to you is one of four channels

A breach notice to an individual is the visible part of a system with several outputs.

Under the federal health privacy rules the same event can also require notice to prominent media outlets, notice to the Secretary, and notice travelling upstream from one company to another.

Each of those has its own trigger, and the triggers use different numbers. They are close enough to look identical and far enough apart to produce different outcomes on the same facts.

Reading them side by side is the fastest way to see why a breach can be reported and still never appear anywhere you would look.

The media rule, and the number written into it

The rule is short. For a breach of unsecured protected health information involving more than five hundred residents of a State or jurisdiction, a covered entity must notify prominent media outlets serving that State or jurisdiction.

The unit is residents of one State, not people overall. A breach touching thousands of people spread thinly across the country can fail that test everywhere.

Timing matches the individual notice. Notice goes out without unreasonable delay and in no case later than sixty calendar days after discovery, subject to the law enforcement exception.

Content matches it too. The media notification has to meet the same content requirements as the notice sent to individuals, so the same five elements apply.

The consumer-facing rule has a media provision of its own, and its threshold is written differently. It applies where the information of five hundred or more residents of a State or jurisdiction is, or is reasonably believed to have been, acquired.

More than five hundred, and five hundred or more, are not the same test. They separate at exactly one number.

The regulator, and the two speeds

Notice to the Secretary is required for every breach of unsecured protected health information, without a size threshold. What size decides is when.

For a breach involving five hundred or more individuals, the covered entity provides that notice contemporaneously with the notice to individuals, in the manner specified on the department's website.

For a breach involving fewer than five hundred individuals, the entity keeps a log or other documentation. It reports not later than sixty days after the end of each calendar year, for breaches discovered during the preceding year.

That second route is the one worth understanding. A small breach discovered in January can be reported in a batch the following March, entirely lawfully.

The consumer-facing rule sets the same two speeds toward the Commission instead. Five hundred or more is contemporaneous, and a log of anything smaller may be sent annually no later than sixty calendar days after the end of the calendar year.

The public list, and a third number

There is a statutory duty to publish, and it is worth reading closely because it is narrower than the reporting duty above it.

The Secretary must make available to the public, on the department's website, a list identifying each covered entity involved in a qualifying breach. It qualifies where the unsecured protected health information of more than five hundred individuals is acquired or disclosed.

So three thresholds sit within one system. Notice to the Secretary is due for any breach. Contemporaneous notice is due at five hundred or more. Publication is required at more than five hundred.

A breach affecting exactly five hundred individuals falls in the gap. It is reported at once and, on the face of the statute, is not within the publication duty.

The statute also asks for counting of a different kind. It directs an annual report to named congressional committees covering breaches for which notice was given to the Secretary, including the number and nature of those breaches and the actions taken in response.

Between the list and the report there is a real distinction. One names entities above a threshold; the other counts everything reported and does not name anyone.

The notice that travels between companies

Records are often held by a company you have never dealt with, and the rules build a link for that case.

A business associate that discovers a breach of unsecured protected health information must notify the covered entity of it. Discovery is imputed the same way it is for a covered entity, through any employee, officer or other agent other than the person committing the breach.

The timing is the same sixty-day ceiling, running from the business associate's own discovery rather than from the covered entity's.

The content requirement is the part with practical weight. The notification must include, to the extent possible, the identification of each individual whose information has been or is reasonably believed to have been accessed, acquired, used or disclosed during the breach.

It must also supply any other available information the covered entity needs for its own notice to individuals, either at the same time or promptly as it becomes available.

The consumer-facing rule has a matching link for the companies inside its scope, running from a service provider up to the vendor or related entity it serves.

The delay that can hold all of it

One section can stop every notice in the subpart, and it is only a paragraph long.

If a law enforcement official states that a notification, notice or posting required under the subpart would impede a criminal investigation or cause damage to national security, the entity must delay it.

How long depends on the form the statement takes. Where the statement is in writing and specifies the time for which a delay is required, the entity delays for the period the official specified.

Where it is made orally, the entity documents the statement, including the identity of the official making it, and delays temporarily for no longer than thirty days from the date of the oral statement.

That thirty-day cap lifts only if a written statement arrives within the period. The consumer-facing rule carries the same exception and implements it by pointing at a provision of the health privacy rules.

It is a narrow power with a written record attached, and it is the reason a notice can arrive much later than the deadlines above would suggest.

Who acts on the consumer-facing rule

The rule states its own enforcement route rather than leaving it to inference.

Any violation of the part is treated as a violation of a rule promulgated under section eighteen of the Federal Trade Commission Act, regarding unfair or deceptive acts or practices. It is subject to civil penalties adjusted for inflation.

The section then says the Commission will enforce the part in the same manner, by the same means, and with the same jurisdiction, powers and duties available to it under that Act.

The statute behind the rule says the same thing in its own words, treating a violation as an unfair and deceptive act or practice in violation of a regulation under that section.

There is also a bridge between the two agencies that most descriptions leave out. On receiving a breach notification, the Commission notifies the Secretary of it.

One more feature of that statute is printed in its own title. It calls itself a temporary requirement, and the section provides that it stops applying if Congress enacts new legislation covering the same ground.

What federal law leaves to the states

The health privacy rules include a preemption section, and it is written as a general rule with a closed list of exceptions.

The general rule is that a standard, requirement or implementation specification adopted under the subchapter that is contrary to a provision of State law preempts that provision.

Contrary has its own definition, and it is a two-part test. Either a covered entity or business associate would find it impossible to comply with both. Or the State provision stands as an obstacle to the accomplishment and execution of the full purposes and objectives of the federal scheme.

Four conditions then take a State provision out of the general rule. A determination by the Secretary on named grounds. A provision whose principal purpose is regulating controlled substances. A provision for reporting disease or injury, child abuse, birth or death, or for public health surveillance, investigation or intervention. And a provision for health plan reporting for audits, program monitoring or licensure.

The fifth is the one everybody quotes, and it is worth reading letter by letter. It covers a State provision that relates to the privacy of individually identifiable health information and is more stringent than a standard, requirement or implementation specification adopted under subpart E of part 164.

Subpart E is the privacy rule. The breach notification rules are subpart D, and the definition of more stringent in the neighboring section is written against subpart E by name as well.

The consumer-facing rule points at the same machinery, stating that it preempts State law as set out in a named section of the statute behind it.

So the honest reading is a limit rather than a conclusion. The text sets out one general rule and a closed list of exceptions, and which of them reaches a State breach notification statute is not answered on the face of it.

What a reader can actually look at

Whether a company's privacy document names the entity that holds the record, since the upstream notice runs between companies and the one you contracted with may not be the one holding it.

Whether the document says anything about which vendors receive health information, because that is the population the business associate link is built for.

Whether a notice you receive names a State, since the media and publication duties are counted by residents of a State rather than by people overall.

Whether a notice explains its own timing, since a late letter can be lawful under the delay provision and there is no way to tell from the letter unless it says so.

And whether a company publishes any privacy contact at all. Every route described here starts with knowing which organization to ask.

What this does not decide

It does not say which federal rule reaches any particular company, or that either one does. That is a legal conclusion about a specific business.

It does not say that any company has experienced a breach, appeared on any list, or delayed any notice. No such claim is made and none is implied.

It does not describe what the department's public list currently contains, and it gives no address for it. What is described is the statutory duty to publish one.

It does not say whether any State notification statute survives preemption, because the text quoted here does not answer that question.

And it is not legal advice. It reports what four sections of a federal rule, two preemption sections and two statutes say.

Sources

  1. 45 CFR 164.406, "Notification to the media"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 74 FR 42767, Aug. 24, 2009, as amended at 78 FR 5695, Jan. 25, 2013 · Retrieved September 2026Paragraph (a), requiring a covered entity to notify prominent media outlets serving a State or jurisdiction for a breach of unsecured protected health information involving more than 500 residents of that State or jurisdiction, following discovery as provided in the individual notification section. Paragraph (b), the timeliness requirement of without unreasonable delay and in no case later than 60 calendar days after discovery, subject to the law enforcement delay section. Paragraph (c), requiring the media notification to meet the content requirements of the individual notification section.
  2. 45 CFR 164.408, "Notification to the Secretary"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 74 FR 42767, Aug. 24, 2009, as amended at 78 FR 5695, Jan. 25, 2013 · Retrieved September 2026Paragraph (a), requiring a covered entity to notify the Secretary following discovery of a breach of unsecured protected health information, with no size threshold in the standard itself. Paragraph (b), requiring notice contemporaneously with the notice to individuals, in the manner specified on the department's website, for breaches involving 500 or more individuals. Paragraph (c), requiring a log or other documentation for breaches involving fewer than 500 individuals, with the notification provided not later than 60 days after the end of each calendar year for breaches discovered during the preceding calendar year.
  3. 45 CFR 164.410, "Notification by a business associate"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 74 FR 42767, Aug. 24, 2009, as amended at 78 FR 5695, Jan. 25, 2013 · Retrieved September 2026Paragraph (a)(1), requiring a business associate to notify the covered entity following the discovery of a breach of unsecured protected health information. Paragraph (a)(2), imputing discovery through any employee, officer or other agent of the business associate other than the person committing the breach, determined in accordance with the federal common law of agency. Paragraph (b), the timeliness requirement running from the business associate's own discovery. Paragraph (c)(1), requiring the notification to include, to the extent possible, the identification of each individual whose unsecured protected health information has been, or is reasonably believed to have been, accessed, acquired, used or disclosed during the breach. Paragraph (c)(2), requiring the business associate to provide any other available information the covered entity must include in its notification to individuals, at that time or promptly as it becomes available.
  4. 45 CFR 164.412, "Law enforcement delay"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed for subpart D: 74 FR 42767, Aug. 24, 2009 · Retrieved September 2026The whole section: the trigger, a statement by a law enforcement official that a notification, notice or posting required under the subpart would impede a criminal investigation or cause damage to national security; paragraph (a), delay for the time period specified where the statement is in writing and specifies one; and paragraph (b), documentation of an oral statement including the identity of the official who made it, with a temporary delay of no longer than 30 days from the date of the oral statement unless a written statement is submitted during that time.
  5. 16 CFR 318.4, "Timeliness of notification"Federal Trade Commission, via the Electronic Code of Federal Regulations · Source note printed on the part: 74 FR 42980, Aug. 25, 2009, as amended at 89 FR 47054, May 30, 2024 · Retrieved September 2026Paragraph (b) only, which the sibling article on notice contents does not use: notice to the Commission involving the information of 500 or more individuals provided contemporaneously with the notice to individuals, and logged notifications involving fewer than 500 individuals sent annually no later than 60 calendar days following the end of the calendar year.
  6. 16 CFR 318.5, "Methods of notice"Federal Trade Commission, via the Electronic Code of Federal Regulations · Source note printed on the part: 74 FR 42980, Aug. 25, 2009, as amended at 89 FR 47054, May 30, 2024 · Retrieved September 2026Paragraph (b) only, which the sibling article on notice contents does not use: notice to prominent media outlets serving a State or jurisdiction where the unsecured PHR identifiable health information of 500 or more residents of that State or jurisdiction is, or is reasonably believed to have been, acquired during the breach. Paragraph (c), the notice to the Commission and the option of an annual log for a breach involving fewer than 500 individuals.
  7. 16 CFR 318.7, "Enforcement"Federal Trade Commission, via the Electronic Code of Federal Regulations · Source note printed on the part: 74 FR 42980, Aug. 25, 2009, as amended at 89 FR 47054, May 30, 2024 · Retrieved September 2026The whole section: a violation of the part treated as a violation of a rule promulgated under section 18 of the Federal Trade Commission Act, 15 U.S.C. 57a, regarding unfair or deceptive acts or practices, subject to civil penalties as adjusted for inflation, with the Commission enforcing the part in the same manner, by the same means, and with the same jurisdiction, powers and duties available to it under the Federal Trade Commission Act.
  8. 16 CFR 318.1, "Purpose and scope"Federal Trade Commission, via the Electronic Code of Federal Regulations · Source note printed on the part: 74 FR 42980, Aug. 25, 2009, as amended at 89 FR 47054, May 30, 2024 · Retrieved September 2026Paragraph (b) only, the sentence stating that the part preempts State law as set forth in a named section of the American Recovery and Reinvestment Act of 2009. Paragraph (a), the scope sentence, is used by a separate article and is not relied on here.
  9. 45 CFR 160.203, "General rule and exceptions"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 65 FR 82798, Dec. 28, 2000, as amended at 67 FR 53266, Aug. 14, 2002 · Retrieved September 2026The general rule that a standard, requirement or implementation specification adopted under the subchapter that is contrary to a provision of State law preempts that provision, and the four lettered conditions that take a State provision out of it: a determination by the Secretary on the named grounds; a provision whose principal purpose is the regulation of controlled substances; a provision for reporting of disease or injury, child abuse, birth or death, or for public health surveillance, investigation or intervention; and a provision requiring a health plan to report or provide access to information for management or financial audits, program monitoring and evaluation, or licensure or certification. Paragraph (b), the exception for a State provision that relates to the privacy of individually identifiable health information and is more stringent than a standard, requirement or implementation specification adopted under subpart E of part 164 — the paragraph whose own words name subpart E rather than the breach subpart.
  10. 45 CFR 160.202, "Definitions"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 65 FR 82798, Dec. 28, 2000, as amended at 67 FR 53266, Aug. 14, 2002; 74 FR 42767, Aug. 24, 2009; 78 FR 5689, Jan. 25, 2013 · Retrieved September 2026The definition of contrary, in two limbs: that a covered entity or business associate would find it impossible to comply with both the State and Federal requirements, or that the provision of State law stands as an obstacle to the accomplishment and execution of the full purposes and objectives of the named federal provisions. The definition of more stringent, whose opening words scope the comparison to a standard, requirement or implementation specification adopted under subpart E of part 164. The definition of relates to the privacy of individually identifiable health information, as a State law with the specific purpose of protecting the privacy of health information or affecting it in a direct, clear and substantial way.
  11. 42 U.S.C. 17932, "Notification in the case of breach"Office of the Law Revision Counsel, United States Code · Statutory credit printed on the section: Pub. L. 111-5, div. A, title XIII, § 13402, Feb. 17, 2009 · Retrieved September 2026Subsection (e)(2), media notice where the unsecured protected health information of more than 500 residents of a State or jurisdiction is or is reasonably believed to have been accessed, acquired or disclosed. Subsection (e)(3), notice to the Secretary, with an immediate route for a breach involving 500 or more individuals and an annual log permitted below that. Subsection (e)(4), the duty on the Secretary to make available to the public on the department's website a list identifying each covered entity involved in a breach in which the unsecured protected health information of more than 500 individuals is acquired or disclosed. Subsection (i), the annual report to named congressional committees on breaches for which notice was provided to the Secretary, covering the number and nature of such breaches and the actions taken in response.
  12. 42 U.S.C. 17937, "Temporary breach notification requirement for vendors of personal health records and other non-HIPAA covered entities"Office of the Law Revision Counsel, United States Code · Statutory credit printed on the section: Pub. L. 111-5, div. A, title XIII, § 13407, Feb. 17, 2009 · Retrieved September 2026The section's own printed title, which describes the requirement as temporary. Subsection (b), the duty on a third party service provider to notify the vendor of personal health records or related entity it serves, including the identification of each individual whose information has been or is reasonably believed to have been accessed, acquired or disclosed. Subsection (d), requiring the Federal Trade Commission, on receipt of a breach notification, to notify the Secretary of the breach. Subsection (e), treating a violation as an unfair and deceptive act or practice in violation of a regulation under section 57a(a)(1)(B) of title 15. Subsection (g)(2), the sunset provision under which the section stops applying to breaches discovered on or after the effective date of regulations implementing new legislation on the same subject.

Frequently asked questions

Why would a breach be reported and still never become public?

Because the reporting duty and the publication duty use different thresholds. Notice to the Secretary is required for every breach of unsecured protected health information, with size deciding only whether it goes at once or in an annual batch. The statutory publication duty is narrower: the Secretary must publish a list identifying each covered entity involved in a breach in which the information of more than five hundred individuals is acquired or disclosed. A breach below that line is reported and, on the face of the statute, sits outside the publication duty.

What happens with a small breach?

It goes into a log. For breaches involving fewer than five hundred individuals, the covered entity maintains a log or other documentation. The notification then goes not later than sixty days after the end of each calendar year, for breaches discovered during the preceding calendar year. Individual notice is not affected by that; the annual route governs the report to the Secretary. The consumer-facing rule uses the same structure toward the Commission. A log of breaches involving fewer than five hundred individuals may be sent annually, within sixty calendar days after the end of the calendar year.

When do the news media get told?

Under the health privacy rule, one threshold governs. Where a breach of unsecured protected health information involves more than five hundred residents of a State or jurisdiction, the covered entity must notify prominent media outlets serving that State or jurisdiction. Timing is the same as for individual notice, and the content has to meet the same requirements. Note the unit: residents of one State, not people in total. The consumer-facing rule words its own media provision as five hundred or more residents of a State or jurisdiction, so the two rules separate at exactly one person.

What if the company that lost my records is not the one I signed up with?

The rules build a link for that. A business associate that discovers a breach of unsecured protected health information must notify the covered entity, without unreasonable delay and in no case later than sixty calendar days after its own discovery. That notification must include, to the extent possible, the identification of each individual whose information has been or is reasonably believed to have been accessed, acquired, used or disclosed. It must also supply any other available information the covered entity needs for its notice to individuals. The consumer-facing rule has a matching link from a service provider upward.

Can a notice be legally delayed?

Yes, and by one specific route. If a law enforcement official states that a notification, notice or posting would impede a criminal investigation or cause damage to national security, the entity must delay it. A written statement specifying a period holds the notice for that period. An oral statement is documented, including the identity of the official who made it. It holds the notice temporarily for no longer than thirty days from the date it was made, unless a written statement arrives within that time. The consumer-facing rule carries the same exception.

Does my state's breach law still apply?

The text quoted here does not answer that, and saying otherwise would go past what it says. The health privacy rules set a general preemption rule for a federal standard contrary to State law, with contrary itself defined as impossibility of dual compliance or as an obstacle to the federal purposes. Four conditions then take a State provision out of the general rule. A fifth covers a State provision relating to the privacy of individually identifiable health information that is more stringent than a standard adopted under subpart E of part 164. Subpart E is the privacy rule; the breach rules are subpart D.