HIPAA Breach 60-Day Notification Clock
HIPAA Breach 60-Day Notification Clock - a deterministic tool in Sophie Well's Workflow & Documentation group.
Open the HIPAA Breach 60-Day Notification Clock → Runs in your browser. No signup, no tracking.
What this is
Compute the three statutory deadlines a covered entity faces under the HIPAA Breach Notification Rule (45 CFR §§164.404, 164.406, 164.408) from a single discovery date and the number of individuals affected. Sophie Well returns the individual-notice deadline (no later than 60 calendar days after discovery), the media-notice deadline when >=500 residents of a state or jurisdiction are affected, and the HHS-notice deadline (within 60 days for >=500 affected; by the following March 1 for under 500).
When to use it
Use this the moment a privacy or security incident is escalated to the privacy office. The 60-day clock starts on discovery, not on confirmation, so the deadlines should be in the incident record before the root-cause investigation is finished. The output is a planning aid - the regulation also requires content-specific notice elements and law-enforcement delay handling that Sophie does not draft for you - but knowing the dates first is what keeps the response from slipping into willful neglect territory.
References
HIPAA Breach Notification Rule, 45 CFR §§164.404, 164.406, 164.408. Individual + media + HHS deadlines computed from the discovery date.
Worked example: Discovery 2026-03-15, >=500 affected: individual + media + HHS notice all due 2026-05-14.
Sophie Well is a reference and educational tool. Not medical, legal, or financial advice. Does not replace clinician judgment, professional billing review, or legal counsel.