HIPAA Breach Notification for Therapy Practices: The 4-Factor Test, the 60-Day Clock, and the 5 Incidents Practices Report Wrong (2026)

A HIPAA breach is any impermissible acquisition, access, use, or disclosure of unsecured protected health information. HIPAA presumes every impermissible disclosure is a breach unless you document a low probability of compromise using a four-factor risk assessment.

You must notify affected clients without unreasonable delay and no later than 60 calendar days after discovery.

That paragraph is the rule. It is also the part that gets practice owners in trouble, because 60 days is the point where the government stops tolerating you, not the point where it expects you to act.

The two questions that actually decide your exposure are narrower: when did your clock start, and did you write down the analysis that let you skip the notice?

This guide answers both, then walks through the five incidents I see solo and small-group practices misclassify every year.

What counts as a HIPAA breach in a therapy practice?

The Breach Notification Rule sits at 45 CFR 164.400 through 164.414.

It defines a breach as an acquisition, access, use, or disclosure of protected health information that the Privacy Rule does not permit, and that compromises the security or privacy of that information.

Three words carry all the weight.

  • Unsecured: The rule only covers unsecured PHI. If you encrypted the data to the standard HHS specifies, the information sits outside the definition entirely. An encrypted laptop stolen from your car is not a reportable breach. The same laptop with an unencrypted drive is.

  • Presumed: Every impermissible disclosure counts as a breach by default. You do not have to prove harm occurred. You have to prove compromise was unlikely, in writing, before you can decline to notify.

  • Discovery: Your 60-day clock starts on the first day the incident is known to you, or the first day you would have known it by exercising reasonable diligence. Not the day your IT vendor finishes a forensic report.

    In its July 2026 settlement with OSF Healthcare System, OCR cited two separate timing failures: late notice to individuals under 45 CFR 164.404(b) and late notice to the Secretary under 164.408(b), alongside the underlying security problems. OSF discovered the ransomware in April 2021 and filed its breach report in October, and that gap cost $552,250 plus two years of corrective action monitoring.

For a therapy practice, PHI is broader than the chart. A voicemail confirming an appointment, an intake form sitting in a shared inbox, a claim scrubbed with the wrong client's date of birth, a superbill emailed to a stale address. All of it counts.

What are the 3 exceptions to the HIPAA breach notification rule?

Before you run any risk assessment, check whether the incident falls outside the definition of breach altogether. There are exactly three exceptions, and they are narrow.

  1. Good-faith access by your own workforce: Your biller opens the wrong client's chart, realizes it in three seconds, and closes it. The access was unintentional, inside the scope of their job, and they did not use or share what they saw. Not a breach.

  2. Inadvertent disclosure between two authorized people: One credentialed clinician in your group forwards a case note to another clinician in the same practice who was not on that client's care team. Both are already authorized to access PHI at your organization. Nothing goes further. Not a breach.

  3. Good-faith belief the recipient could not retain the information: You hand a client the wrong appointment card and take it back before they read it. Not a breach.

Notice what all three share: the information never left your control in a usable form. The moment it does, the exceptions close. An email to the wrong client is not covered, because that client is not a member of your workforce.

How does the 4-factor breach risk assessment work?

If no exception applies, HIPAA presumes a breach. You can rebut that presumption only by documenting a low probability that the PHI was compromised, weighing four factors set out at 45 CFR 164.402.

  1. The nature and extent of the PHI: What was in it, and how easily could someone identify the person? A name plus an appointment time sits at one end. A name, diagnosis code, Social Security number, and insurance ID sits at the other. Behavioral health data pushes this factor higher than most medical data does, because the diagnosis itself is stigmatizing.

  2. Who received it: A disclosure to another HIPAA-covered provider, already bound by the same rules, lowers the risk. A disclosure to a stranger, an unknown email address, or the open internet raises it sharply.

  3. Whether the PHI was actually acquired or viewed: A fax that went to a wrong number and was confirmed shredded, unread, is different from a mailbox someone browsed for a week. You need evidence here, not assumption.

  4. How far you mitigated the risk: Did you get written confirmation of deletion? Recall the message? Retrieve the paper? Mitigation is the factor you have the most control over, and the one most practices never document.

You weigh all four together. If they support a low probability of compromise, you can decline notice, but you must keep the written analysis for six years.

The same six-year documentation logic that governs your therapy records retention requirements applies to your breach files.

Here is the operator's version: an undocumented risk assessment is functionally the same as no risk assessment. OCR has issued corrective actions over missing documentation on incidents that were minor on the facts.

What is the HIPAA 60-day rule for breach notification?

The 60-day rule is really five obligations triggered by one event, and they run on different clocks.

  • Affected individuals: Written notice by first-class mail, or email if the client agreed to electronic notice, without unreasonable delay and no later than 60 calendar days after discovery.

  • HHS, for breaches affecting 500 or more individuals: Report through the OCR breach portal contemporaneously with the individual notices, and in no case later than 60 days. This is not a second, separate 60-day allowance.

  • HHS, for breaches affecting fewer than 500 individuals: Log the incident and submit it no later than 60 days after the end of the calendar year in which you discovered it. You may file earlier, and I recommend you do, so nothing sits in a queue for eleven months.

  • Media: Required only when a breach affects more than 500 residents of a single state or jurisdiction. Almost no solo practice will ever hit this.

  • Business associates: Your billing company, your transcription vendor, your virtual assistant firm must notify you without unreasonable delay and no later than 60 days after they discover a breach.

    In March 2026, OCR settled with software business associate MMG Fusion over an intrusion affecting roughly 15 million individuals, and OCR Director Paula M. Stannard's public statement put the point plainly: a business associate's timeliness is what makes the covered entity's own deadlines possible.

If contact information is outdated for ten or more people, you owe substitute notice: a conspicuous posting on your website home page or major media notice, for at least 90 days, with a toll-free number active for the same period.


Not sure whether your practice would even catch a breach in time?

Most solo practices discover incidents by accident, weeks late, because nobody owns the inbox, the fax line, or the vendor list.

A 30-minute conversation is usually enough to find the gaps. Book a free consultation with HireGaynell, and we'll walk through your actual workflow, not a checklist.


What are the steps to respond to a HIPAA breach in a private practice?

Run this sequence the day you learn something went wrong.

Step 1: Write down the discovery date and time

Everything downstream anchors to this. Put it in a file before you do anything else.

Step 2: Stop the exposure

Recall the email, disable the account, retrieve the paper, take the exposed system offline.

Step 3: Scope it

Identify exactly whose PHI moved, what data elements were involved, and how many people. Estimate if you must, then update later.

Step 4: Check the three exceptions

If one applies cleanly, document why and stop. If it does not, keep going.

Step 5: Run and record the four-factor assessment

Rate each factor, state your reasoning in a paragraph each, reach a conclusion, sign and date it.

Step 6: Notify

Send individual letters, submit to HHS on the right track for your headcount, and add media notice only if you cross the 500-resident threshold.

Step 7: Fix the cause and retrain

OCR looks at what changed after the incident. Update the policy, retrain the person, tighten the workflow, and log all three.

Across the behavioral health practices HireGaynell supports, fewer than one in five arrive with a written breach response procedure already in place.

That gap, not the incident itself, is what turns a small mistake into an enforcement problem.

What must a HIPAA breach notification letter include?

Plain language, no legal padding, and these elements:

  • A brief description of what happened, including the date of the breach and the date you discovered it

  • The types of information involved, such as name, diagnosis, date of birth, insurance ID, or Social Security number

  • Steps the client should take to protect themselves

  • What your practice is doing to investigate, mitigate harm, and prevent a repeat

  • Contact procedures, including a toll-free number, email address, website, or postal address

Write it the way you would explain it in session. Clients who receive a defensive, lawyered letter about their mental health records file complaints. Clients who receive a clear one usually do not.

Do SUD records change your breach reporting duties in 2026?

Yes, and this is the change most therapy practices missed.

The 2024 final rule aligning 42 CFR Part 2 with HIPAA reached its compliance date on February 16, 2026. From that date, the HIPAA breach notification framework applies to Part 2 records, and OCR launched a civil enforcement program that accepts both complaints and breach reports for substance use disorder patient records.

If your practice provides SUD diagnosis, treatment, or referral for treatment and receives federal assistance, an unauthorized use or disclosure of a Part 2 record now requires its own breach evaluation.

HHS also directs that information which is both PHI and a Part 2 record be reported separately as a HIPAA breach and a Part 2 breach.
Practices running integrated behavioral health and addiction services should treat this as a second reporting track, not a footnote.

What are the most common HIPAA breaches in therapy practices?

After years inside behavioral health operations, the pattern barely changes. In the incident reviews HireGaynell runs for client practices, roughly six in ten involve a misdirected message rather than anything a hacker did.

  1. The group email with visible addresses. A clinician emails twelve waitlisted clients and puts them in the To field instead of BCC. Every recipient now knows eleven other people are seeking therapy. This is one reason careful therapy practice waitlist management treats contact handling as a compliance task, not an admin chore.

  2. The wrong-client attachment. A superbill or treatment summary attached to the wrong outgoing message inside SimplePractice or TherapyNotes.

  3. The over-released record. A records request answered in full when the authorization only covered a date range. Most of these trace back to a defective form, which is why the rules governing release of information requests matter operationally, not just legally.

  4. The unsecured personal device. A clinician checks the EHR on an unencrypted phone with no passcode, then loses it.

  5. The vendor with no signed BAA. A scheduler, transcription tool, or assistant touching PHI without an executed business associate agreement. The exposure is yours, and the fix belongs in your HIPAA-compliant administrative support structure before anyone touches a chart.

Notice that four of the five are workflow failures, not technology failures. That is the honest news, because workflow is fixable this month.

How HireGaynell keeps breach risk out of your admin workflow

HireGaynell provides done-for-you administrative, credentialing, billing, and intake support for solo and small-group behavioral health practices across the US. We work with LCSWs, LPCs, LMFTs, psychologists, and psychiatrists who bill insurance and run without a front desk.

We don't sell breach prevention. It is a byproduct of how we run the back office.

When we take over client intake, PHI stops living in a personal inbox and starts flowing through your EHR. When we handle SimplePractice billing, claims and superbills go out through the platform's audited channels instead of ad-hoc email. When we manage provider enrollment, paneling, and CAQH ProView re-attestation, credentialing documents stop circulating as loose attachments. When we onboard, we sign a business associate agreement first, because a vendor without one is the single most common compliance hole we find.

We also build the thing most practices lack: a written incident procedure with a named owner, a discovery log, and a four-factor assessment template already filled out with your practice's details. It takes one afternoon to create, and it changes what happens on the worst day of your year.

If a misdirected email or a missing BAA has you rethinking who touches your client data, that is exactly the ground HireGaynell's virtual assistant and practice administration services cover.

Conclusion

In my experience running behavioral health operations, the practices that survive a breach cleanly are never the ones with the best software. They are the ones who wrote down the discovery date on day one and finished the four-factor assessment by day three, whether or not they ended up sending a single letter. Sixty days is not your deadline. It is the outer edge of the government's patience, and OCR has now shown twice this year that it counts calendar days, not good intentions. Build the procedure while nothing is wrong, name the person who owns it, and the worst day of your practice year becomes a two-hour task instead of an enforcement file.



Next
Next

Sliding-Scale Fees for Therapists: How to Build the Tiers, Write the Policy, and Avoid the One Discount That Breaches Your Payer Contract (2026)