HIPAA Breach 60-Day Notification Clock
Compute the three statutory deadlines a covered entity faces under the HIPAA Breach Notification Rule (45 CFR §§164.404, 164.406, 164.408) from a single discovery date and the number of individuals affected.
Open the tool → Runs in your browser. Data leaves only if you deliberately send a problem report from the interactive tool.
Example
- Breach discovery date
- 2026-03-15
- Number of affected individuals
- 600
Result: Discovery 2026-03-15, >=500 affected: individual + media + HHS notice all due 2026-05-14.
The tool opens with these values already filled in. Replace them with your own.
What you enter
- Breach discovery date (YYYY-MM-DD)
- Number of affected individuals
What this is
Sophie Well returns the individual-notice deadline (no later than 60 calendar days after discovery), the media-notice deadline when >=500 residents of a state or jurisdiction are affected, and the HHS-notice deadline (within 60 days for >=500 affected; by the following March 1 for under 500).
When to use it
Use this the moment a privacy or security incident is escalated to the privacy office. The 60-day clock starts on discovery, not on confirmation, so the deadlines should be in the incident record before the root-cause investigation is finished. The output is a planning aid - the regulation also requires content-specific notice elements and law-enforcement delay handling that Sophie does not draft for you - but knowing the dates first is what keeps the response from slipping into willful neglect territory.
How this is calculated
HIPAA Breach Notification Rule, 45 CFR §§164.404, 164.406, 164.408. Individual + media + HHS deadlines computed from the discovery date.
A reference and educational tool. Not medical, legal, or financial advice, and not a substitute for clinician judgment.
More in Billing and coding.