Skip to main content
—
Framework library
Framework module · hipaa-breach-notification

HIPAA Breach Notification Rule

What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.

45 CFR §§ 164.400–414 · HHS Office for Civil Rights

Standing today
Directory entry

00Answer

from the registry record
What is HIPAA Breach Notification Rule?
What a covered entity or business associate must tell individuals, the media, and HHS after a breach of unsecured protected health information, and how fast.
Who does HIPAA Breach Notification Rule apply to?
HIPAA Breach Notification Rule applies to healthcare, US, per HHS Office for Civil Rights.
What is the current version of HIPAA Breach Notification Rule?
The current edition is 45 CFR §§ 164.400–414, issued by HHS Office for Civil Rights. Source: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html.
What does an assessment under HIPAA Breach Notification Rule require?
No control catalog has been ingested for HIPAA Breach Notification Rule yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

HIPAA Breach Notification Rule is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the current codified notification duties are not ingested or modeled.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Individual notice · Media notice · Secretary notice · Business associate notice
Applies to
healthcare · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

1 edition
45 CFR §§ 164.400–414Current editiondate not published

06Related frameworks

scored from registry facts
  1. HIPAA Security Rule45 CFR Part 164 Subparts A and C

    Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

  2. 42 CFR Part 22024 final rule

    Also applies to healthcare · Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.

  3. HIPAA Privacy Rule45 CFR Part 160 and Part 164 Subparts A and E

    Also applies to healthcare · The federal rule governing permitted uses and disclosures of protected health information, minimum-necessary practices, notices, and individual privacy rights for covered entities and business associates.

  4. Also applies to healthcare · Colorado's AI law, rewritten. SB 26-189 repealed and reenacted the 2024 statute, dropping the high-risk-AI regime for narrower notice and disclosure duties on automated decision-making technology used in consequential decisions.

HIPAA Breach Notification Rule | ControlFrame