Contact Us
IT Total Care

Blog

Caregiver holding an older adult's hand beside a walking cane during a home visit, the patient relationship behind HIPAA breach notification for home health agencies.

HIPAA Breach Notification for Home Health Agencies: 60 Days Is the Outer Limit

HIPAA breach notification for home health agencies has one federal deadline: 60 calendar days from the day a breach is discovered. That is the outer limit, not a target. An agency that sends notice on day 55 can still be found late if it had what it needed on day 12, and a California agency will usually have missed a shorter state deadline weeks before that.

The second clock is the one most San Francisco Bay Area agencies do not have on a calendar. Federal law sets a floor. California sets its own reporting obligation for licensed home health agencies and hospices, on a different trigger and in different units, and it runs out first.

What follows covers what the federal rule requires, when the clock actually starts, how the state deadline interacts with it, and what an agency needs in place before an incident rather than during one.

What Does HIPAA Breach Notification for Home Health Agencies Actually Require?

HIPAA breach notification for home health agencies is governed by the Breach Notification Rule at 45 CFR 164.400 through 164.414. It requires notice to affected individuals without unreasonable delay and in no case later than 60 calendar days after discovery of a breach of unsecured protected health information, or PHI.

The phrasing carries more weight than the number. Because the standard is without unreasonable delay and in no case later than 60 days, the 60th day is a ceiling on an obligation that may already have come due. Sixty days is the point at which a notice becomes indefensible, not the point at which it becomes due.

What Counts as a Breach?

An impermissible use or disclosure of unsecured PHI is presumed to be a breach. That presumption stands unless the agency demonstrates a low probability that the information was compromised, based on a documented risk assessment of four specific factors.

  • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification
  • The unauthorized person who used the information, or to whom the disclosure was made
  • Whether the information was actually acquired or viewed
  • The extent to which the risk to the information has been mitigated

Note which direction the burden runs. The agency is not asked to establish that a breach occurred. The agency is asked to establish that one did not, and HHS places the burden of that demonstration squarely on the covered entity.

Who Has to Be Notified, and at What Threshold?

Individual notice is always required. Two further obligations attach at scale, and their thresholds are close enough to be confused with each other and different enough that confusing them creates a compliance gap.

  • Breaches affecting 500 or more individuals must be reported to the HHS Office for Civil Rights within the same 60-day window, contemporaneously with individual notice
  • Breaches affecting more than 500 residents of a single state or jurisdiction also require notice to prominent media serving that area, on the same 60-day deadline
  • Breaches affecting fewer than 500 individuals are logged and reported to OCR annually, no later than 60 days after the end of the calendar year in which they were discovered

The annual log is the provision agencies most often forget applies to them, because a small incident feels closed once the patient has been told and the account has been shut off.

Which Term Applies: PHI, Medical Information, or ePHI?

Three terms govern this topic and they are not interchangeable. The federal Breach Notification Rule governs PHI. California’s licensing statute governs medical information, a category defined in state law. ePHI applies only where HIPAA Security Rule safeguards are the subject, such as encryption or audit controls on a clinician’s field device. Using the wrong one produces the wrong deadline.

When Does the Clock Start on HIPAA Breach Notification for Home Health Agencies?

The clock starts on discovery, not on confirmation. A breach is discovered on the first day the agency knew of it, or by exercising reasonable diligence would have known. Knowledge held by any workforce member other than the person who caused the breach counts as the agency’s knowledge.

That definition removes the option most agencies reach for instinctively, which is to wait until somebody can say with confidence what actually happened. Certainty is not the trigger. Awareness is.

Why Does Ransomware Start the Clock Before Anyone Knows What Was Taken?

Under OCR’s ransomware guidance, a ransomware infection involving ePHI is presumptively a breach from the moment it is detected. The clock therefore starts while the agency still has no idea which patient records were reached, and the forensic answer tends to arrive several weeks into a window that has already been running.

What Did the OSF Healthcare Settlement Establish?

On July 29, 2026, HHS OCR announced a $552,250 settlement with OSF Healthcare System over a 2021 ransomware incident. OSF discovered the infection in April 2021 and did not file its breach report or begin notifying the 53,907 affected individuals until October, roughly five months later, after its forensic investigation had concluded.

Among OCR’s findings were failure to provide timely breach notification to affected individuals and failure to provide timely notification to the Secretary of HHS. OSF agreed to a corrective action plan that OCR will monitor for two years. The instruction inside that outcome is plain enough: notify by day 60 with what is known and supplement as facts develop, rather than holding the notice until the picture is complete.

This is not a new position. In January 2017, Presence Health paid $475,000 in the first OCR settlement based solely on untimely breach notification, after notifying affected individuals 101 days past discovery. The OSF settlement reaffirmed nine years later what that case established. Waiting for certainty remains the most common and the most expensive misreading of the rule.

Why Is 60 Days Rarely the Real Deadline for a California Agency?

Federal law sets a floor of protection rather than a ceiling on what states may require, and several states impose shorter breach reporting clocks. For a California licensed home health agency or hospice, the state deadline is 15 business days from detection, which expires roughly six weeks before the federal one.

How Do the Two Clocks Differ?

California Health and Safety Code section 1280.15 requires licensed home health agencies and hospices to report to the California Department of Public Health and to the affected patient within 15 business days of detecting unlawful or unauthorized access to a patient’s medical information. Fifteen business days is roughly 21 calendar days, set against 60 calendar days from discovery under the federal rule.

The two clocks do not merely differ in length. They run on different triggers and in different units, which is why an agency managing carefully to the federal deadline will still miss the state one. Detection starts the state clock and discovery starts the federal clock. One counts business days, the other counts calendar days. Neither conversion is intuitive under pressure.

What Does the State Obligation Reach That the Federal Rule Does Not?

The California obligation attaches to medical information rather than to unsecured PHI, and it runs independently of HIPAA. It therefore reaches incidents and agencies the federal rule does not, which means a determination that no federal notice is required does not end the analysis. The filing procedure itself, including what CDPH requires in the report and how the 15 days are counted, is a separate subject.

A separate California consumer-notice obligation also exists and runs on its own schedule.

Whether a properly encrypted device triggers any of this in the first place is a different question again, with a federal answer and a less settled state answer.

“HIPAA breach notifications can be complex. There are several government agencies that require notification that all have different timelines and ways they want to be notified. Our recommendation is to build your systems and agreements around the shortest deadline that is relevant to you.”

Brendan Duebner, President of IT Total Care

How Does a Home Health Agency Actually Discover a Breach?

Discovery in a home health agency rarely looks like a security alert. It looks like an ordinary operational oddity that turns out to be something else, noticed by a scheduler or a clinician rather than by anyone whose job title includes security.

A scheduler opens her mailbox on a Tuesday morning and finds sent items she did not send, with referral packets attached to them. Nothing is broken. Nobody is locked out. Her Monday looks exactly like her Friday. The federal clock started the moment she noticed, and the state clock started with it.

Where Else Does a Breach Surface in a Home Health Agency?

The other routes into discovery are just as quiet, and none of them look like a security event at the moment they happen. Each one starts the clock anyway.

  • A clinician reports a phone stolen from a car between visits, with the Axxess or WellSky app still signed in
  • The EMR vendor notifies the agency of an incident on its own side, and the agency’s clock starts on that notice rather than on the vendor’s investigation, which is one reason business associate agreement requirements for home health agencies deserve attention before an incident rather than after one
  • Ransomware locks the office file server on a Friday, and the agency spends the weekend restoring systems rather than documenting when the encryption was first noticed
  • A terminated clinician’s EMR access was never removed, and audit logs show patient visits opened after the last day worked

The common thread is that discovery rarely announces itself. Nobody in any of these situations is yet sure a breach occurred, which is precisely why the detection date has to be recorded the moment anything is noticed rather than once someone feels confident. Without a documented detection date, an agency cannot prove it met either clock, and the HIPAA risk assessment for home health agencies it relies on to explain the gap has to be documented alongside it.

How Should an Agency Run the Breach Risk Assessment?

Run it in writing, in order, starting from the presumption that a breach occurred. The four-factor assessment is not a judgment recorded after the fact. It is a document the agency may have to produce years later to explain to a regulator why it chose not to notify.

  • Record the detection date before anything else. Every downstream deadline runs from it, federal and state, and it is the one field nobody can reconstruct honestly later.
  • Document your way out, not in. The rule presumes a breach. The agency’s job is to demonstrate a low probability of compromise, not to build the case that something happened.
  • Work the four factors one at a time. Write the evidence for each factor separately rather than recording a single conclusion that gestures at all four.
  • Count only mitigation that actually happened. A remote wipe that completed and was logged is evidence. A wipe that was attempted is not.
  • Treat the determination as a record, not a meeting. A low-probability-of-compromise finding reached in conversation and never written down is, in an audit, a finding that was never made.
  • When the call is close, notify. The cost of an unnecessary notice is reputational. The cost of a late one is regulatory.

Where Do Agencies Get This Wrong on Their Own?

The failures cluster in four places, and none of them involve anyone behaving carelessly. Each is a small process gap that stays invisible until a deadline has already passed, at which point it cannot be corrected. These are the four an agency handling breach response internally is most likely to hit.

  • No recorded detection date. Nobody wrote down when the incident was first noticed, so the agency cannot establish either clock, in either direction.
  • The federal calendar is managed and the state one is not. The team tracks 60 days attentively and discovers the 15-business-day obligation on day 40, three weeks after it expired.
  • The agency waits for the forensic report. This is the exact failure OCR penalized in the OSF case, and it remains the most common reason a notification goes out late.
  • Encryption is assumed rather than confirmed. The agency concludes no notice is needed because the device was encrypted, without confirming the encryption method or the state of the keys.

What Can an IT Partner Do, and What Can It Not Do?

An IT provider cannot make the breach determination and cannot file on the agency’s behalf. Notification is the covered entity’s legal obligation and it does not transfer to a vendor. What a partner supplies is the detection, the timeline, and the technical evidence the agency’s own determination rests on.

The boundaries are worth going over because vendors in this market are not always careful about them:

  • An IT provider cannot decide whether an incident is a reportable breach, and cannot submit the notice for you
  • An IT provider cannot tell you whether California’s medical information statute recognizes the federal encryption safe harbor. That is a question for counsel, and an IT provider who answers it confidently is telling you something about the provider
  • A vendor that discovers an incident inside your environment owes you notice that starts your own clock, which is something your business associate agreement should already require
  • Agencies should expect an IT partner to help support HIPAA compliance, not to assume the notification obligation

Establishing a Defensible Detection Date

A defensible detection date is a timestamped record produced by a system, not a recollection of when somebody noticed something odd. It is the single piece of evidence both clocks depend on, and it is the one an agency cannot create retroactively.

  • Monitoring that produces a timestamped detection record rather than an account of when the office started worrying
  • Alerting that surfaces an incident on the day it happens rather than on the Monday after
  • An incident log the agency can still produce years later, showing what was detected, when, and by whom
  • Both clocks started from the same recorded date, so the federal and state calendars run in parallel instead of one being discovered late

Producing the Evidence the Determination Rests On

The four-factor assessment is only as good as the technical evidence underneath it. Most of that evidence has to be captured while the incident is live, because it cannot be reconstructed once systems have been restored and devices have been replaced.

  • Audit logs from the EMR showing whether patient information was actually accessed or only exposed, which is the third of the four factors
  • Scope reconstruction to the patient level, meaning which patients, which records, and which systems, rather than an estimate
  • Encryption status per device at the time of loss, retrievable from management records in Intune, JumpCloud, or Apple Business Manager rather than asserted afterward
  • Remote wipe executed and the completion recorded, so mitigation counts as evidence rather than as intention
  • Account and session state at the moment of the incident, from Microsoft 365 or Entra ID sign-in logs, since a locked encrypted device and an unlocked signed-in one are different determinations

Keeping Both Clocks on One Calendar

An incident response runbook should name the 15-business-day state deadline and the 60-calendar-day federal deadline side by side, with the earlier one driving the schedule. Two deadlines tracked in two places is functionally one deadline tracked and one missed.

The runbook also has to be rehearsed rather than written. An agency reading its incident response procedure for the first time during a ransomware weekend will miss dates, and that weekend is the entire reason the procedure exists.

What Should You Ask an IT Provider Before Signing?

Four questions separate a provider who can support a breach determination from one who can only confirm that a ticket was opened. Ask them before the contract is signed, because the answers cannot be improved once an incident is underway and the evidence you need was never being collected.

  • Can you give us a defensible detection timestamp, or only a ticket date?
  • Can you produce per-device encryption status as it stood on the day a device went missing?
  • How fast will you notify us of an incident on your side, and is that commitment written into our business associate agreement?

Ready to Put Both Breach Clocks on One Calendar?

Sixty days is the outer limit under federal law, and for a licensed home health agency or hospice in California it is not the deadline that will be missed first. The 15-business-day state clock expires roughly six weeks earlier, on a different trigger, and an agency without a recorded detection date cannot prove it met either one. Almost everything that determines the outcome is decided before the incident, not during it.

IT Total Care works with home health and hospice agencies across the San Francisco Bay Area, from Foster City through San Mateo and Santa Clara counties, on the detection, evidence, and documentation that breach notification decisions depend on. Our home-based care IT support covers monitoring and alerting, incident logging, per-device encryption and wipe records, and scope reconstruction to the patient level. Learn more about our approach to healthcare IT.

Contact Us to talk through what your agency needs.

Leave a Comment

Your email address will not be published. Required fields are marked *