HIPAA Breach 60-Day Notification Clock

Compute the three statutory deadlines a covered entity faces under the HIPAA Breach Notification Rule (45 CFR §§164.404, 164.406, 164.408) from a single discovery date and the number of individuals affected.

Open the tool → Runs in your browser. Data leaves only if you deliberately send a problem report from the interactive tool.

Example

Breach discovery date
2026-03-15
Number of affected individuals
600

Result: Discovery 2026-03-15, >=500 affected: individual + media + HHS notice all due 2026-05-14.

The tool opens with these values already filled in. Replace them with your own.

What you enter

  • Breach discovery date (YYYY-MM-DD)
  • Number of affected individuals

What this is

Sophie Well returns the individual-notice deadline (no later than 60 calendar days after discovery), the media-notice deadline when >=500 residents of a state or jurisdiction are affected, and the HHS-notice deadline (within 60 days for >=500 affected; by the following March 1 for under 500).

When to use it

Use this the moment a privacy or security incident is escalated to the privacy office. The 60-day clock starts on discovery, not on confirmation, so the deadlines should be in the incident record before the root-cause investigation is finished. The output is a planning aid - the regulation also requires content-specific notice elements and law-enforcement delay handling that Sophie does not draft for you - but knowing the dates first is what keeps the response from slipping into willful neglect territory.

How this is calculated

HIPAA Breach Notification Rule, 45 CFR §§164.404, 164.406, 164.408. Individual + media + HHS deadlines computed from the discovery date.

A reference and educational tool. Not medical, legal, or financial advice, and not a substitute for clinician judgment.

More in Billing and coding.

Browse all tools

Built by Clay Good. Source on GitHub.