The 72-hour breach notification requirement under HIPAA places direct accountability on healthcare organizations to report certain incidents to the Department of Health and Human Services within three days of discovery. The clock starts when the organization knows—or reasonably should know—that a breach has occurred. What creates friction in most organizations is not the mechanics of filing a report, but the absence of a clear decision-maker with authority to determine whether an incident qualifies as a reportable breach in the first place.

This article clarifies what constitutes a reportable breach, the sequence of decisions required in the first 72 hours, and who inside the organization should own that determination. It also explains how this requirement connects to broader incident readiness and why many healthcare organizations delegate breach assessment to parties who lack the authority or context to make regulatory judgments.

What the Rule Requires

Under the HIPAA Breach Notification Rule, a covered entity must report a breach affecting 500 or more individuals to HHS within 72 hours of discovery. A breach is defined as an impermissible use or disclosure of protected health information (PHI) that compromises the security or privacy of that information. Not every unauthorized access or disclosure meets this definition. The rule provides for exceptions when the entity can demonstrate, through a risk assessment, that there is a low probability the information has been compromised.

Discovery occurs when any person who is a workforce member or agent of the covered entity knows or should have known that a breach occurred. This means the 72-hour clock may start before leadership is informed, creating urgency around internal escalation procedures.

What Qualifies as a Reportable Breach

Determining whether an incident is reportable requires a structured risk assessment. The rule outlines four factors to evaluate:

  • The nature and extent of the PHI involved, including types of identifiers and likelihood of re-identification
  • The unauthorized person who used the PHI or to whom disclosure was made
  • Whether the PHI was actually acquired or viewed
  • The extent to which risk has been mitigated

This assessment must be documented and completed promptly. If the assessment cannot be finished within 72 hours, many organizations face the choice of reporting preemptively or documenting why they concluded no breach occurred. Both paths carry consequences if the reasoning is later challenged.

Who Decides and What Adequate Ownership Looks Like

The breach determination is a regulatory judgment, not a technical one. Many healthcare organizations default to IT teams or managed service providers to assess whether an incident is reportable. These parties can describe what occurred—which systems were accessed, what data may have been exposed, what containment steps were taken—but they typically lack the authority, legal context or regulatory positioning to decide whether those facts constitute a breach under HIPAA.

Adequate ownership requires a named executive with three attributes: sufficient understanding of the technical facts to evaluate them, authority to make a regulatory determination on behalf of the organization, and accountability for the decision if later questioned by regulators or counsel. In many organizations, this is the privacy officer or compliance leader. In others, it is general counsel. What creates risk is when no single role is clearly designated, or when the designated role lacks access to timely information during an active incident.

A virtual CISO can serve this function where internal capacity is limited. The vCISO translates technical findings into regulatory context, conducts or oversees the required risk assessment, and either makes the breach determination directly or provides the documented analysis leadership needs to make an informed decision. This model ensures the organization has executive-level security and compliance ownership without requiring a permanent hire.

How This Connects to Incident Readiness

The 72-hour requirement makes incident response planning a governance issue, not purely an operational one. An organization that waits until an incident occurs to decide who will conduct the breach assessment, what documentation is required, and who has authority to make the determination will struggle to meet the timeline. The regulation does not forgive late reporting because internal roles were unclear.

Effective incident readiness in this context includes a documented decision tree that maps technical findings to the four-factor risk assessment, a clear escalation path from detection to decision, and pre-identified roles with authority to interpret the facts under HIPAA. It also includes ensuring that third parties involved in detection or containment—whether MSPs, forensic firms or legal counsel—understand their role as information providers rather than decision-makers.

Organizations that rely on external IT providers for day-to-day security should separately establish who will own the breach determination. The provider can describe the incident; they cannot report on the organization's behalf or decide whether the legal threshold has been met. That responsibility remains with the covered entity.

Business Consequences of Misalignment

Late reporting carries regulatory consequences, but the operational risk often appears earlier. When an incident occurs and no one is clearly accountable for the breach determination, organizations experience decision paralysis. IT teams hesitate to escalate without knowing what threshold matters. Leadership hesitates to file a report without confidence in the underlying analysis. Hours pass while internal parties defer to one another, and the 72-hour window narrows.

The alternative—reporting every incident preemptively to avoid the risk of being late—creates its own problems. Frequent reporting of incidents that do not meet the breach threshold can erode regulator confidence and divert resources from genuine risk management. The regulation anticipates that organizations will exercise judgment, which requires someone with authority and context to exercise it.

What Leadership Should Do Next

Healthcare executives should confirm that a named individual inside the organization has authority to make breach determinations and that this person has timely access to the information required to complete the four-factor risk assessment. If that role does not exist or lacks the necessary context, the organization faces regulatory exposure that no amount of technical tooling will resolve.

Practical steps include:

  • Identify who is accountable for breach determinations and document that designation in writing.
  • Ensure that person has authority to access incident information in real time, not after IT or outside counsel has completed their work.
  • Map the technical incident response process to the regulatory decision sequence so that the four-factor assessment can begin as soon as an incident is detected.
  • Clarify in writing what information third parties are expected to provide and confirm they understand they are not making the breach determination.
  • Test the process with a tabletop exercise that includes the compliance officer, IT leadership and any external providers involved in detection or response.

Organizations that lack internal capacity to own this function should consider whether a [virtual CISO engagement](/vciso/) provides the regulatory and strategic leadership required to meet the standard. A vCISO can establish governance, conduct the necessary risk assessments during incidents, and ensure that breach determinations are documented in a manner that will withstand regulatory scrutiny.

If your organization does not have clear executive ownership of breach determinations, or if you are uncertain whether your current structure would meet the 72-hour timeline under pressure, a confidential consultation can clarify where the gaps exist and what governance model would address them. Heights Consulting Group offers these consultations to healthcare organizations seeking to resolve accountability questions before an incident tests them. You can reach the firm directly to discuss your situation in confidence.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Incident Readiness and Response Planning

A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.

Read about Incident Readiness and Response Planning