HIPAA Breach Notification Requirements for Surgical Practices
A HIPAA breach is any impermissible use or disclosure of protected health information (PHI) that compromises the security or privacy of that information. Surgical practices handle high volumes of PHI across scheduling, billing, aftercare communications, and EHR systems. Knowing the exact regulatory requirements for breach notification prevents a manageable incident from becoming a six-figure penalty.
What Constitutes a Breach Under 45 CFR 164.402
A breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI. 'Unsecured PHI' means PHI that has not been rendered unusable, unreadable, or indecipherable through encryption or destruction per HHS guidance (45 CFR 164.402).
Three exceptions exist where an impermissible disclosure is NOT a reportable breach: (1) unintentional access by a workforce member acting in good faith within the scope of authority, with no further disclosure; (2) inadvertent disclosure between authorized persons at the same entity or business associate; (3) good-faith belief that the unauthorized recipient could not reasonably retain the information.
Common breach scenarios in surgical practices: misdirected fax or email containing operative reports, patient portal access errors exposing one patient's records to another, stolen unencrypted laptops containing patient scheduling data, ransomware encryption of the practice management system, and aftercare instruction emails sent to the wrong patient.
The Breach Notification Rule presumes that any impermissible disclosure is a breach unless the covered entity demonstrates through a risk assessment that there is a low probability the PHI was compromised (45 CFR 164.402(2)).
The Four-Factor Risk Assessment (45 CFR 164.402(2))
Factor 1: The nature and extent of the PHI involved. Assess what data elements were exposed. A patient name alone is less sensitive than a name combined with diagnosis, procedure codes, Social Security number, or financial information. The combination of identifiers and clinical data increases risk.
Factor 2: The unauthorized person who used or received the PHI. A misdirected fax to another healthcare provider carries lower risk than PHI posted publicly on a website or accessed by an unknown external attacker. Evaluate whether the recipient has obligations to protect the information (e.g., another covered entity).
Factor 3: Whether the PHI was actually acquired or viewed. Server access logs, email read receipts, and audit trails can demonstrate whether the unauthorized party actually accessed the data. A misdirected email that was returned undelivered or immediately deleted by the recipient supports a low-probability finding.
Factor 4: The extent to which the risk has been mitigated. Actions taken after the incident reduce risk: obtaining a written attestation of destruction from the unintended recipient, confirming the recipient did not copy or forward the data, revoking unauthorized access credentials, and verifying no further disclosure occurred. Document all mitigation steps.
Notification Timelines and Reporting Requirements
Individual notification: Within 60 calendar days of discovering the breach, notify each affected individual by first-class mail or email (if the individual previously agreed to electronic communication). The 60-day clock starts on the date the breach is discovered, not the date it occurred. The notice must include: a description of the breach, the types of PHI involved, steps the individual should take, what the practice is doing to mitigate harm, and contact information for questions (45 CFR 164.404).
HHS/OCR notification: If the breach affects 500 or more individuals, notify the HHS Office for Civil Rights within 60 days using the online breach portal (ocrportal.hhs.gov). Breaches affecting fewer than 500 individuals must be logged and reported to OCR annually, no later than 60 days after the end of the calendar year in which the breach was discovered (45 CFR 164.408).
Media notification: If the breach affects 500 or more residents of a single state or jurisdiction, you must notify prominent media outlets serving that area within 60 days (45 CFR 164.406). This typically means issuing a press release to local newspapers and television stations.
The OCR 'Wall of Shame' (officially the Breach Portal) publicly lists all breaches affecting 500 or more individuals. As of March 2026, the portal lists over 6,000 breach reports since 2009. Entries remain publicly accessible indefinitely and appear in web searches of your practice name.
Penalty Tiers and Enforcement Under the HITECH Act
Tier 1 (Lack of knowledge): The covered entity did not know and could not reasonably have known of the violation. Penalty: $137 to $68,928 per violation, with an annual cap of $2,067,813 for identical violations. These amounts are adjusted annually for inflation per 45 CFR 160.404.
Tier 2 (Reasonable cause): The violation was not due to willful neglect. Penalty: $1,379 to $68,928 per violation, annual cap of $2,067,813. Most small practice breaches resulting from human error (misdirected communications, lost devices) fall into this tier if the practice had reasonable safeguards in place.
Tier 3 (Willful neglect, corrected): The violation was due to willful neglect but was corrected within 30 days of discovery. Penalty: $13,785 to $68,928 per violation, annual cap of $2,067,813. Failure to encrypt laptops and mobile devices after a prior risk assessment identified the gap often triggers this tier.
Tier 4 (Willful neglect, not corrected): The violation was due to willful neglect and was not timely corrected. Penalty: $68,928 to $2,067,813 per violation. This tier also carries potential criminal referral to the Department of Justice. The largest HIPAA settlements (Anthem: $16 million in 2018, Premera: $6.85 million in 2020) involved prolonged failures to address known security vulnerabilities.
Does a misdirected fax always need to be reported as a breach?
Not always. Perform the four-factor risk assessment. If the fax went to another healthcare provider (who is also a covered entity), the recipient has their own HIPAA obligations, and you obtain written confirmation that they destroyed the fax without copying it, you may determine there is a low probability the PHI was compromised. Document your risk assessment findings and the mitigation steps regardless of whether you report the incident as a breach.
Is ransomware considered a HIPAA breach?
HHS issued guidance in July 2016 stating that a ransomware attack is presumed to be a breach unless the covered entity can demonstrate a low probability that PHI was accessed (not just encrypted). If the ransomware exfiltrated data before encryption, or if the entity cannot confirm through forensic analysis that data was only encrypted and not viewed or copied, it must be reported as a breach. Encryption of PHI by the attacker (ransomware) is different from encryption by the covered entity (a safeguard). The HHS guidance is clear that ransomware encryption does not make the PHI 'secured' under the HIPAA Security Rule.
What should our practice do in the first 24 hours after discovering a potential breach?
Contain the incident: revoke unauthorized access, retrieve misdirected information if possible, and preserve evidence (do not wipe affected systems before forensic analysis). Activate your incident response plan. Identify the scope: what PHI was involved, how many individuals are affected, and how the incident occurred. Begin the four-factor risk assessment. Notify your HIPAA privacy officer, practice legal counsel, and cyber insurance carrier (if applicable). Document every step with timestamps. Do not notify affected individuals or media until the risk assessment is complete and your legal team has reviewed the notification language.
Do we need cyber liability insurance for a small surgical practice?
Cyber liability insurance is not legally required under HIPAA, but it is strongly recommended. A breach affecting even a few hundred patients can cost $100,000 to $500,000 in notification costs, forensic investigation, legal fees, credit monitoring services, and potential OCR penalties. The Ponemon Institute's 2025 Cost of a Data Breach Report found the average per-record cost of a healthcare breach was $408, the highest of any industry. Policies typically cost $1,500 to $7,000 annually for small practices depending on revenue, patient volume, and security posture.
For practices
Bring this to your own practice.
QR Rx turns every procedure into a branded recovery plan that keeps patients engaged and brings them back. Start free in minutes, or see it live in a 20-minute demo.
This blog provides general information about healthcare compliance and aftercare best practices. It does not constitute legal, medical, or regulatory advice. Consult qualified professionals for guidance specific to your practice.