WikiFrameworksHIPAABreach notice identification of individuals

Breach notice identification of individuals

Updated: 2026-05-05

Plain English Translation

Breach notifications from a business associate to the covered entity must include, to the extent possible, the identity of each individual whose unsecured PHI was accessed, acquired, used, or disclosed during the breach. This information enables the covered entity to fulfill its own notification obligations.

Executive Takeaway

Business associates must explicitly identify every individual affected by a PHI breach to enable covered entities to perform patient outreach.

ImpactHigh
ComplexityMedium

Why This Matters

  • Bullet 1: Covered entities cannot fulfill their legal duty to notify patients without accurate identification data from their vendors.
  • Bullet 2: Failure to thoroughly identify affected individuals compounds the risk of identity theft and subsequent class-action lawsuits.
  • Bullet 3: Incomplete breach notifications directly violate HIPAA requirements, inviting steep financial penalties from federal regulators.

What “Good” Looks Like

  • Comprehensive data mapping and logging that immediately links compromised systems back to specific patient records; tools like WatchDog Security's Asset Inventory can help maintain cloud, SaaS, and identity context for faster breach scoping.
  • Pre-established breach notification templates shared between the organization and vendors outlining required data fields.
  • Clear incident response procedures detailing how to securely transmit lists of affected individuals; tools like WatchDog Security's Secure File Sharing can support encrypted transfer, TOTP verification, and audit logs for sensitive breach materials.

Under HIPAA 164.410, a business associate must notify the covered entity of any breach of unsecured protected health information without unreasonable delay.

Yes, to the extent possible, the business associate must identify each individual whose unsecured protected health information has been accessed or acquired.

The notice must include the identification of each affected individual and any other available information the covered entity is required to include in their patient notification.

The organization must provide notification to the covered entity without unreasonable delay and in no case later than 60 calendar days after discovering the breach.

Unsecured protected health information is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through approved methodologies.

The covered entity ultimately bears the legal responsibility for notifying the affected individuals, although they completely rely on the business associate to identify who was compromised.

The business associate must identify individuals to the extent possible. If exact identification is impossible, they must provide the covered entity with the best available data.

HIPAA views these actions as unauthorized interactions with protected health information that compromise the security or privacy of the data, triggering the notification mandate.

A checklist should include steps for identifying the breach, determining the scope of compromised PHI, identifying affected individuals, logging discovery dates, and drafting the notice.

Covered entities should maintain a centralized security incident log and coordinate closely with the vendor to ensure all provided identities are accurately cross-referenced.

The hard part is connecting a compromised system, table, file, or account back to specific patient records quickly enough to support HIPAA notification timelines. Tools like WatchDog Security's Asset Inventory can help by maintaining system ownership, SaaS inventory, cloud asset context, and identity mapping so incident teams have a clearer starting point for determining which individuals may have been affected.

Affected-individual lists often contain sensitive PHI or identifiers, so sending them through ordinary email can create additional exposure and audit issues. Tools like WatchDog Security's Secure File Sharing can support encrypted transfer, TOTP verification, and audit logs when a business associate needs to provide breach-scope information to a covered entity.

HIPAA 164.410

"A business associate's breach notification includes, to the extent possible, the identification of each individual whose unsecured protected health information has been, or is reasonably believed by the business associate to have been, accessed, acquired, used, or disclosed during the breach."

VersionDateAuthorDescription
1.0.02026-05-05Compliance TeamInitial publication