Guide

The small-practice breach: assessment, notification, the annual log

Summary

For a small practice, most breaches affect fewer than 500 people — and that number sets your reporting path, not your total patient count. You still notify each affected individual in writing without unreasonable delay and within sixty days of discovery. But you report the breach to HHS on an annual log, within sixty days after the year ends, rather than immediately. First, though, run and document the four-factor risk assessment: an encrypted, secured device usually is not a breach at all.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What counts as a breach — and the presumption

A breach is an impermissible use or disclosure of unsecured protected health information — and the rule presumes it is a reportable breach unless you can show, through a documented risk assessment, a low probability that the information was compromised 12. The word doing the work is unsecured: the breach rules reach only information that was not encrypted or otherwise rendered unusable. That presumption is the default you have to overcome, in writing, case by case.

So a breach is not automatically a catastrophe and not automatically reportable. It is a trigger to assess. What separates a solo practice that handles one well from one that does not is having decided the sequence — assess, then notify or document — before the incident, not during it.

The secured-PHI safe harbor

Encryption is the single most valuable control a solo practice owns, because secured information is outside the breach rules entirely. If a laptop, phone, or drive holding patient information is encrypted to the recognized standard and the key was not also lost, losing the device is not a reportable breach — the data is unreadable 3. This is the encryption safe harbor, and it converts the lost laptop from a disaster into a documented non-event.

The corollary is the reason unencrypted devices are so dangerous: the same lost laptop, unencrypted, is presumed a breach of every record it held. For a one-person practice, full-disk encryption on every device that ever touches patient information is the highest-leverage hour you will spend on compliance.

The four-factor risk assessment

When information is unsecured and there has been an impermissible disclosure, you decide whether it is reportable by running the four-factor risk assessment the rule specifies 2. The four factors are the nature and extent of the information involved, who received or used it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Weigh all four and write down where you land.

The facts can move the needle. A misdirected fax pulled back within minutes from a fellow covered entity, with written confirmation it was destroyed, may land at a low probability of compromise once you weigh who received it and how fast it was contained. The assessment is your record that you weighed the facts honestly — not a formality you skip because the answer felt obvious.

Notification: individuals, and the annual HHS log

If the assessment does not clear the low-probability bar, notification follows on two separate tracks. You must notify each affected individual in writing, without unreasonable delay and no later than sixty days after you discover the breach, describing what happened, what information was involved, what steps they should take, and what you are doing 1. For a small practice, the number affected is almost always under 500, which sets the government track.

That is the key distinction the 500 threshold draws — and it counts individuals affected by the breach, not your total patient panel. For breaches affecting fewer than 500 people, you keep a log and report those breaches to HHS within sixty days after the end of the calendar year in which you discovered them, through the OCR breach portal. Only a breach affecting 500 or more triggers immediate HHS notice and media notice — a threshold most solo incidents never reach.

Ransomware and business-associate breaches

Two situations rewrite the timeline for a solo practice. A ransomware attack that encrypts patient information is presumed to be a reportable breach unless your documented risk assessment shows a low probability of compromise — the encryption by the attacker is itself an unauthorized acquisition 4. And when the breach happens at a business associate — your biller, your cloud vendor — that vendor must notify you, and your clock to notify patients generally starts then.

Both cases reward preparation. A tested, offline backup is what lets you refuse a ransom and rebuild, and a business associate agreement that requires prompt breach notice is what keeps a vendor's incident from quietly eating your sixty-day window before you even hear about it.

Prevent, document, and the cost of getting it wrong

The cheapest breach is the one your safeguards prevent, and the required prevention has a free tool. Conduct the risk analysis the Security Rule demands using the Security Risk Assessment tool sized for small practices, and encrypt your devices so a loss stays inside the safe harbor 5. Keep your breach documentation — the assessments, the notices, the log — for the six years the rule requires.

OCR investigates breaches and has resolved cases against very small practices, not only large systems 6, and the civil-money-penalty framework escalates with the degree of culpability 7. That is why a documented, timely response matters more than a spotless prevention record: regulators look hardest at whether you assessed, notified, and logged on time — the things fully within a one-person practice's control.

Common questions

No. The 500 threshold counts the individuals affected by a single breach, not your total patient panel. A solo practice with a few hundred patients will almost always have a breach affecting fewer than 500 people. That number decides how you report to HHS — an annual log for breaches under 500, immediate notice plus media for 500 or more — not whether the breach counts at all.

Without unreasonable delay, and no later than sixty days after you discover the breach. The written notice has to describe what happened, the types of information involved, the steps individuals should take to protect themselves, and what your practice is doing about it. Sixty days is the outer limit, not a target — notify as soon as you reasonably can, and document the date you discovered it.

Not if it was encrypted. Encrypted, secured information falls outside the breach rules, so a lost or stolen device whose data is unreadable — and whose key was not also lost — is generally not a reportable breach. That is the encryption safe harbor. An unencrypted device holding patient information is the opposite: presume a breach and run the four-factor risk assessment.

For breaches affecting fewer than 500 people, you do not report each one to HHS immediately. Instead you keep a log and submit those breaches to HHS within sixty days after the end of the calendar year in which they were discovered, through the OCR breach portal. You still notify the affected individuals within sixty days of discovery — only the government reporting is deferred.

Your business associate must notify you of a breach on its side, and your obligation to notify affected patients generally runs from that notification. Your business associate agreement should require prompt notice and cooperation. You remain responsible to your patients, so treat a vendor breach as your incident too: run the risk assessment, notify individuals, and log it for the annual HHS report.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThe breach definition, the presumption of breach, individual-notice timing, and the annual-log path for breaches affecting fewer than 500 individuals.
  2. 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe operative breach-notification rule text, the four-factor risk assessment, and the six-year documentation-retention requirement in 45 CFR Part 164.
  3. 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's safeguards, including encryption as a technical safeguard, render information secured and outside the breach rules.
  4. 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat a ransomware encryption of ePHI is presumed a reportable breach absent a documented low-probability risk assessment.
  5. 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat the free ONC/OCR Security Risk Assessment tool helps a small practice conduct the required risk analysis.
  6. 6.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR investigates breaches and has resolved cases against very small practices.
  7. 7.Office of the Federal Register (2026). 45 CFR Part 160 — General Administrative Requirements. eCFR. linkThe civil-money-penalty framework and the definition of unsecured PHI in 45 CFR Part 160.

https://www.gale.care/for-providers/hip-breach-small-practice · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)