HIPAA Breach 60-Day Notification Clock

HIPAA Breach 60-Day Notification Clock - a deterministic tool in Sophie Well's Workflow & Documentation group.

Open the HIPAA Breach 60-Day Notification Clock → Runs in your browser. No signup, no tracking.

What this is

Compute the three statutory deadlines a covered entity faces under the HIPAA Breach Notification Rule (45 CFR §§164.404, 164.406, 164.408) from a single discovery date and the number of individuals affected. Sophie Well returns the individual-notice deadline (no later than 60 calendar days after discovery), the media-notice deadline when >=500 residents of a state or jurisdiction are affected, and the HHS-notice deadline (within 60 days for >=500 affected; by the following March 1 for under 500).

When to use it

Use this the moment a privacy or security incident is escalated to the privacy office. The 60-day clock starts on discovery, not on confirmation, so the deadlines should be in the incident record before the root-cause investigation is finished. The output is a planning aid - the regulation also requires content-specific notice elements and law-enforcement delay handling that Sophie does not draft for you - but knowing the dates first is what keeps the response from slipping into willful neglect territory.

References

HIPAA Breach Notification Rule, 45 CFR §§164.404, 164.406, 164.408. Individual + media + HHS deadlines computed from the discovery date.

Worked example: Discovery 2026-03-15, >=500 affected: individual + media + HHS notice all due 2026-05-14.

Sophie Well is a reference and educational tool. Not medical, legal, or financial advice. Does not replace clinician judgment, professional billing review, or legal counsel.

Built by Clay Good. Source on GitHub.