The small-practice breach: assessment, notification, the annual log
Summary
For a small practice, most breaches affect fewer than 500 people — and that number sets your reporting path, not your total patient count. You still notify each affected individual in writing without unreasonable delay and within sixty days of discovery. But you report the breach to HHS on an annual log, within sixty days after the year ends, rather than immediately. First, though, run and document the four-factor risk assessment: an encrypted, secured device usually is not a breach at all.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
What counts as a breach — and the presumption
A breach is an impermissible use or disclosure of unsecured protected health information — and the rule presumes it is a reportable breach unless you can show, through a documented risk assessment, a low probability that the information was compromised 1Ref 1HHS Office for Civil Rights (2026).Breach Notification Rule.The breach definition, the presumption of breach, individual-notice timing, and the annual-log path for breaches affecting fewer than 500 individuals.2Ref 2Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The operative breach-notification rule text, the four-factor risk assessment, and the six-year documentation-retention requirement in 45 CFR Part 164.. The word doing the work is unsecured: the breach rules reach only information that was not encrypted or otherwise rendered unusable. That presumption is the default you have to overcome, in writing, case by case.
So a breach is not automatically a catastrophe and not automatically reportable. It is a trigger to assess. What separates a solo practice that handles one well from one that does not is having decided the sequence — assess, then notify or document — before the incident, not during it.
The secured-PHI safe harbor
Encryption is the single most valuable control a solo practice owns, because secured information is outside the breach rules entirely. If a laptop, phone, or drive holding patient information is encrypted to the recognized standard and the key was not also lost, losing the device is not a reportable breach — the data is unreadable 3Ref 3HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule's safeguards, including encryption as a technical safeguard, render information secured and outside the breach rules.. This is the encryption safe harbor, and it converts the lost laptop from a disaster into a documented non-event.
The corollary is the reason unencrypted devices are so dangerous: the same lost laptop, unencrypted, is presumed a breach of every record it held. For a one-person practice, full-disk encryption on every device that ever touches patient information is the highest-leverage hour you will spend on compliance.
The four-factor risk assessment
When information is unsecured and there has been an impermissible disclosure, you decide whether it is reportable by running the four-factor risk assessment the rule specifies 2Ref 2Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The operative breach-notification rule text, the four-factor risk assessment, and the six-year documentation-retention requirement in 45 CFR Part 164.. The four factors are the nature and extent of the information involved, who received or used it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated. Weigh all four and write down where you land.
The facts can move the needle. A misdirected fax pulled back within minutes from a fellow covered entity, with written confirmation it was destroyed, may land at a low probability of compromise once you weigh who received it and how fast it was contained. The assessment is your record that you weighed the facts honestly — not a formality you skip because the answer felt obvious.
Notification: individuals, and the annual HHS log
If the assessment does not clear the low-probability bar, notification follows on two separate tracks. You must notify each affected individual in writing, without unreasonable delay and no later than sixty days after you discover the breach, describing what happened, what information was involved, what steps they should take, and what you are doing 1Ref 1HHS Office for Civil Rights (2026).Breach Notification Rule.The breach definition, the presumption of breach, individual-notice timing, and the annual-log path for breaches affecting fewer than 500 individuals.. For a small practice, the number affected is almost always under 500, which sets the government track.
That is the key distinction the 500 threshold draws — and it counts individuals affected by the breach, not your total patient panel. For breaches affecting fewer than 500 people, you keep a log and report those breaches to HHS within sixty days after the end of the calendar year in which you discovered them, through the OCR breach portal. Only a breach affecting 500 or more triggers immediate HHS notice and media notice — a threshold most solo incidents never reach.
Ransomware and business-associate breaches
Two situations rewrite the timeline for a solo practice. A ransomware attack that encrypts patient information is presumed to be a reportable breach unless your documented risk assessment shows a low probability of compromise — the encryption by the attacker is itself an unauthorized acquisition 4Ref 4HHS Office for Civil Rights (2016).FACT SHEET: Ransomware and HIPAA.That a ransomware encryption of ePHI is presumed a reportable breach absent a documented low-probability risk assessment.. And when the breach happens at a business associate — your biller, your cloud vendor — that vendor must notify you, and your clock to notify patients generally starts then.
Both cases reward preparation. A tested, offline backup is what lets you refuse a ransom and rebuild, and a business associate agreement that requires prompt breach notice is what keeps a vendor's incident from quietly eating your sixty-day window before you even hear about it.
Prevent, document, and the cost of getting it wrong
The cheapest breach is the one your safeguards prevent, and the required prevention has a free tool. Conduct the risk analysis the Security Rule demands using the Security Risk Assessment tool sized for small practices, and encrypt your devices so a loss stays inside the safe harbor 5Ref 5Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That the free ONC/OCR Security Risk Assessment tool helps a small practice conduct the required risk analysis.. Keep your breach documentation — the assessments, the notices, the log — for the six years the rule requires.
OCR investigates breaches and has resolved cases against very small practices, not only large systems 6Ref 6HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.That OCR investigates breaches and has resolved cases against very small practices., and the civil-money-penalty framework escalates with the degree of culpability 7Ref 7Office of the Federal Register (2026).45 CFR Part 160 — General Administrative Requirements.The civil-money-penalty framework and the definition of unsecured PHI in 45 CFR Part 160.. That is why a documented, timely response matters more than a spotless prevention record: regulators look hardest at whether you assessed, notified, and logged on time — the things fully within a one-person practice's control.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkThe breach definition, the presumption of breach, individual-notice timing, and the annual-log path for breaches affecting fewer than 500 individuals.
- 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The operative breach-notification rule text, the four-factor risk assessment, and the six-year documentation-retention requirement in 45 CFR Part 164.
- 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's safeguards, including encryption as a technical safeguard, render information secured and outside the breach rules.
- 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. link ✓That a ransomware encryption of ePHI is presumed a reportable breach absent a documented low-probability risk assessment.
- 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That the free ONC/OCR Security Risk Assessment tool helps a small practice conduct the required risk analysis.
- 6.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR investigates breaches and has resolved cases against very small practices.
- 7.Office of the Federal Register (2026). 45 CFR Part 160 — General Administrative Requirements. eCFR. link ✓The civil-money-penalty framework and the definition of unsecured PHI in 45 CFR Part 160.
https://www.gale.care/for-providers/hip-breach-small-practice · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.