The Sixty-Day Rule for Health Information
The federal health rule fixes one outer limit and one trigger, and both are precise. A breach is discovered when any workforce member or agent knows of it, or would have known by exercising reasonable diligence, and notice follows within sixty calendar days.

The rule in short
A covered entity must notify each affected individual without unreasonable delay and in no case later than sixty calendar days after discovery of a breach of unsecured protected health information. Discovery is defined by knowledge attributed across the workforce, not by the moment senior management is briefed. Breaches touching five hundred or more individuals require contemporaneous notice to the Secretary and notice to prominent media; smaller ones are logged and reported annually.
The federal health rule is the most precisely drafted clock in this field. It fixes a single outer limit of sixty calendar days, defines the event that starts it, and states who carries the burden of showing the deadline was met. The precision is useful because the surrounding state statutes are anything but uniform, and an entity subject to both has one federal number it can rely on and a range of state numbers it cannot.
Discovery, and the diligence standard attached to it
A breach is treated as discovered on the first day on which it is known to the covered entity, or on which it would have been known by exercising reasonable diligence. That second branch does most of the work. It converts discovery from a fact about what management was told into a judgment about what a reasonably diligent organization would have noticed, which means an unread alert or an unexamined log can fix the date retrospectively.
Attribution is broad. The entity is deemed to have knowledge if the breach is known, or by reasonable diligence would have been known, to any person other than the one who committed it, provided that person is a workforce member or an agent determined under the federal common law of agency. A contractor acting as an agent is inside the circle. The consequence is that the sixty days may already have been running for some time before the incident reaches anyone whose job it is to count.
The rule also fixes the same discovery definition for the media provision and for reporting to the Secretary, so a single date governs all three obligations rather than each running from its own event. A business associate is treated the same way in its own provision, with knowledge attributed to any employee, officer or other agent other than the person who committed the breach. The practical effect is that an entity defending its timing has to reconstruct not when it decided a breach had occurred, but the earliest moment at which anyone inside the organization had, or should have had, the facts.
The outer limit and the standard that sits inside it
Notification to each affected individual must be provided without unreasonable delay and in no case later than sixty calendar days after discovery. The two requirements are cumulative. Sixty days is the point beyond which no justification is entertained, not an allowance the entity may spend at will, and the same pairing appears in the media provision and in the parallel duty owed by a business associate.
Only one provision suspends the limit. Where a law enforcement official states that notification would impede a criminal investigation or cause damage to national security, the notice is delayed for the period specified in a written statement, or for no more than thirty days from an oral statement unless a written one arrives inside that window. That mechanism is examined in the law enforcement delay and how the clock resumes.
| Recipient | Threshold | Timing | Provision |
|---|---|---|---|
| Affected individuals | Any breach of unsecured information | No later than sixty calendar days after discovery | Notification to individuals |
| Prominent media outlets | More than five hundred residents of one state or jurisdiction | No later than sixty calendar days after discovery | Notification to the media |
| The Secretary, larger breaches | Five hundred or more individuals | Contemporaneously with individual notice | Notification to the Secretary |
| The Secretary, smaller breaches | Fewer than five hundred individuals | Within sixty days after the end of the calendar year | Notification to the Secretary |
| The covered entity, by a vendor | Any breach at a business associate | No later than sixty calendar days after the vendor's discovery | Notification by a business associate |
The five hundred threshold and the annual log
Two separate five hundred thresholds operate, and they are counted differently. Media notice turns on more than five hundred residents of a single state or jurisdiction, so a national incident may cross the line in three states and not in the rest. Reporting to the Secretary turns on five hundred or more individuals in total, without regard to where they live.
Below that total, the entity maintains a log or other documentation of the breaches and reports them to the Secretary not later than sixty days after the end of each calendar year, for breaches discovered during the preceding year. The log defers only the report to the Secretary. Individual notice remains due on the ordinary sixty-day clock, and the media provision is unaffected. An entity that treats a small breach as a logging matter and skips the individual letters has misread which obligation the log replaces.
The annual report covers breaches discovered during the preceding calendar year. An incident that happened in one year and came to light in the next belongs to the later report. Entities that organize their log by incident date rather than discovery date routinely file a breach in the wrong year, and the correction is visible on the face of the submission.
What the notice says and how it is delivered
The content elements are fixed: a brief description of what happened, including the date of the breach and the date of discovery if known; the types of information involved; the steps individuals should take to protect themselves; a description of what the entity is doing to investigate, mitigate and protect against further breaches; and contact procedures including a toll-free number, an email address, a website or a postal address. The notification must be written in plain language.
Written notice goes by first-class mail to the last known address, or by electronic mail where the individual has agreed to it and has not withdrawn the agreement. Where contact information is insufficient or out of date for ten or more individuals, substitute notice requires either a conspicuous posting for ninety days on the home page of the entity's website or conspicuous notice in major print or broadcast media where the affected people likely reside, together with a toll-free number active for at least ninety days. For fewer than ten, an alternative written form, telephone or other means will do.
Two smaller rules sit alongside the main method. Where the entity knows an individual has died and holds an address for the next of kin or personal representative, written notice goes there instead, and substitute notice is not required if that address is itself insufficient. And in a case the entity judges urgent because of possible imminent misuse, it may add telephone or other contact on top of the written notice rather than in place of it. Neither provision changes the sixty days; both change what the entity has to be able to show it did inside them.
Who has to prove the deadline was met
The rule assigns the burden expressly. In the event of a use or disclosure in violation of the privacy subpart, the covered entity or business associate carries the burden of demonstrating that all notifications were made as required, or that the use or disclosure did not amount to a breach as defined. That allocation is what makes the risk assessment a document rather than a conclusion, since an incident file with no assessment leaves the presumption of compromise unrebutted. The record-keeping side of that duty is treated in documenting a decision not to notify.
The same allocation shapes how the sixty days is defended. The evidence that matters is the internal record of when the incident became known within the organization, which is why the definitional question examined in what counts as a breach and the discovery question are worked through together rather than in sequence.
Points to carry away
- Notice to individuals is due without unreasonable delay and in no case later than sixty calendar days after discovery.
- A breach is treated as discovered on the first day it is known, or would have been known by exercising reasonable diligence.
- Knowledge of any workforce member or agent other than the person who caused the breach is attributed to the entity.
- Breaches involving five hundred or more individuals require notice to the Secretary contemporaneously with individual notice.
- Breaches involving fewer than five hundred individuals are logged and reported within sixty days after the end of the calendar year.
- The entity carries the burden of demonstrating that every required notification was made.
Questions readers ask
Is sixty days a target or a ceiling?
A ceiling. The rule states two requirements joined together: without unreasonable delay, and in no case later than sixty calendar days after discovery. An entity that completed its investigation in two weeks and mailed on day fifty-eight has met the number and can still be found to have delayed unreasonably. The sixty days is the point past which no explanation is accepted, not a period the entity is entitled to consume. Where a state statute sets a shorter outer limit for the same individuals, the shorter one governs that population.
How does the annual log work for smaller incidents?
For breaches involving fewer than five hundred individuals, the covered entity maintains a log or other documentation and reports those breaches to the Secretary not later than sixty days after the end of the calendar year in which they were discovered. Individual notice is not deferred by this; affected people still receive notice on the ordinary sixty-day clock. The log covers the reporting to the Secretary only, and it is organized by the year of discovery rather than the year the incident occurred.
Who counts as a workforce member for discovery purposes?
The rule attributes knowledge to the covered entity if a breach is known, or by exercising reasonable diligence would have been known, to any person who is a workforce member or agent, determined under the federal common law of agency. The one exception is the person who committed the breach. This means a help desk ticket, a security alert reviewed by a contractor acting as an agent, or a report to a supervisor can each start the clock, whether or not the compliance function was told.
Sources
- 45 CFR 164.404 — Notification to individualsSets the sixty calendar day outer limit, defines when a breach is treated as discovered and lists the required content.
- 45 CFR 164.406 — Notification to the mediaRequires notice to prominent media outlets for breaches involving more than five hundred residents of a state or jurisdiction.
- 45 CFR 164.408 — Notification to the SecretaryDistinguishes contemporaneous reporting at five hundred or more individuals from the annual log for smaller breaches.
- 45 CFR 164.402 — DefinitionsDefines breach and unsecured protected health information and supplies the four-factor risk assessment.
- 45 CFR 164.414 — Administrative requirements and burden of proofPlaces on the entity the burden of demonstrating that all notifications were made or that no breach occurred.
- 45 CFR 164.412 — Law enforcement delayThe only provision that suspends the sixty-day limit, and it sets thirty days for an oral request.
Rapid Response Law is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.
More in Breach Notification
The State Clocks and Where They Differ
State notification statutes fall into two families. One family sets an outer limit in days, counted either from discovery of the breach or from the determination that a breach occurred. The other family requires notice in the most expedient time possible and without unreasonable delay, with no number at all. Several states in the first family have moved to thirty days, others sit at forty-five or sixty, and the counting event differs even among statutes that share a number.
Notifying a Regulator and the Threshold That Triggers It
Most states require a filing with the attorney general once a set number of that state's residents must be notified. Five hundred is the most common figure, but the clock attached to it varies: some states measure from discovery, one measures from the date consumer notice goes out, and one requires a preliminary description long before consumers hear anything. Consumer reporting agencies form a third tier with higher counts and different content.
Substitute Notice When People Cannot Be Reached
Where direct notice is not feasible, most state statutes permit a substitute consisting of email where addresses are held, a conspicuous posting on the entity's own website, and notification to major statewide media. The gateway is fixed: cost above two hundred fifty thousand dollars, an affected class above five hundred thousand, or insufficient contact information. The federal health rule uses a different gateway entirely, turning on whether contact details fail for ten or more individuals.


