Compliance
HIPAA Breach Notification for MSPs: A Step-by-Step Guide to Handling Healthcare Data Breaches in 2026
September 29, 2026 · 8 min read · Brett Coffin
TLDR: When a healthcare client's data is breached, the 60-day notification clock starts at discovery — not when your forensic investigation finishes. MSPs classified as business associates carry their own notification obligations to covered-entity clients, and OCR is actively settling with business associates. This guide walks through what qualifies as a reportable breach, the three notification obligations, the BA's role, and how to package breach response as a recurring compliance service line.
2025 was the worst year on record for large healthcare data breaches. According to the HIPAA Journal, 772 healthcare data breaches affecting 500 or more individuals were reported to OCR in 2025 ([HIPAA Journal, 2025 Healthcare Data Breach Report](https://www.hipaajournal.com/2025-healthcare-data-breach-report/)). The average cost of a healthcare data breach reached $7.42 million — making healthcare the most expensive industry for breach response for the 14th consecutive year ([IBM/Ponemon Cost of a Data Breach Report 2025, via HIPAA Journal](https://www.hipaajournal.com/average-cost-of-a-healthcare-data-breach-2025/)). And OCR stepped up enforcement: 21 enforcement actions in 2025, up from 16 in 2024 ([HIPAA Journal, 2025 Healthcare Data Breach Report](https://www.hipaajournal.com/2025-healthcare-data-breach-report/)).
If you are managing healthcare clients, breach notification is not a theoretical procedure. It is the process you should have documented and tested before the breach occurs — because OCR does not accept "we were still investigating" as a defense when the 60-day window closes.
What the HIPAA Breach Notification Rule Requires
The Breach Notification Rule (45 CFR Part 164, Subpart D) requires covered entities and their business associates to provide notification following the discovery of a breach of unsecured protected health information (PHI).
Three groups must be notified after a reportable breach:
1. **Affected individuals** — written notice by first-class mail (or electronic notice if the individual has previously opted in), no later than 60 days after discovery.
2. **HHS OCR** — for breaches affecting 500 or more individuals, notification within 60 days of discovery via the HHS breach reporting portal. For breaches under 500 individuals, notification is due no later than 60 days after the end of the calendar year in which the breach was discovered.
3. **Prominent media outlets** — if 500 or more residents of a single state or jurisdiction are affected, the covered entity must notify prominent media outlets in that state within 60 days.
The 60-day clock starts at discovery — the first day any employee, officer, or agent of the covered entity or business associate knew, or reasonably should have known, about the incident. A pending forensic investigation does not pause the clock. OCR has consistently found that covered entities and business associates may not delay notification while awaiting investigation completion ([Crowell & Moring, 2025](https://www.crowell.com/en/insights/client-alerts/delayed-notification-of-cyberattacks-may-trigger-hipaa-breach-notification-rule)).
What Qualifies as a Reportable Breach
Not every security incident is a breach, and not every breach triggers notification. HIPAA includes four safe harbors that exclude certain events from the notification requirement:
- **Encrypted data.** PHI encrypted to NIST-approved standards where the decryption key was not also compromised is not "unsecured PHI" and is not subject to notification. Encryption is the most reliable safe harbor available.
- **Unintentional internal access.** An unintentional, good-faith access or use by an employee or contractor acting within the scope of their authority — provided the PHI was not further used or disclosed.
- **Inadvertent disclosure between authorized users.** A disclosure from one authorized person to another within the same covered entity or organized healthcare arrangement, where the information is not further used or disclosed.
- **Good faith belief the recipient could not retain the PHI.** A disclosure to an unauthorized person where there is good faith belief that person could not have retained the information.
If no safe harbor applies, the organization must apply a four-factor risk assessment to determine whether there is a low probability the PHI was compromised:
1. The nature and extent of the PHI involved (types of identifiers, financial or clinical sensitivity)
2. The identity of the unauthorized person and whether they could have acted on the data
3. Whether the PHI was actually acquired or viewed, or merely accessible
4. The extent to which the risk has been mitigated
A low-probability determination must be documented. If the covered entity or BA cannot demonstrate low probability, the incident is presumed a reportable breach. This assessment must be retained for six years and will be among the first items OCR requests in an investigation.
The Business Associate's Notification Obligations
If your MSP manages healthcare client environments — accessing ePHI through RMM tools, PSA software, backup platforms, or cloud services — you are almost certainly a HIPAA business associate. That classification carries direct breach notification obligations under the Breach Notification Rule.
A business associate that discovers a breach must:
- Notify the covered entity **without unreasonable delay and no later than 60 days** after discovery.
- Report the identities of affected individuals to the extent known.
- Cooperate with the covered entity's investigation and notification process.
The practical consequence: the covered entity's 60-day clock for notifying affected individuals runs from when the covered entity discovers the breach — which in most cases means from when the BA tells them. A business associate that waits 58 days to notify a covered entity leaves that client a two-day window to issue individual notifications, submit to HHS, and alert media outlets. That is not a survivable compliance posture.
OCR is actively enforcing BA notification obligations. In January 2025, a Massachusetts BA providing cloud-based EHR services settled with OCR for $80,000 after a ransomware attack exposed the ePHI of 31,248 patients. That same month, USR Holdings — a BA managing mental health and substance abuse treatment facilities — settled for $337,750 after unauthorized parties accessed records affecting 2,903 individuals. Both settlements cited inadequate risk analysis alongside the breach response failures (HHS OCR Enforcement Actions, January 2025).
For a complete breakdown of what every MSP BA must include in HIPAA agreements and how to close the subcontractor gap, see our guide to HIPAA BAA management for MSPs.
The Five Phases of a HIPAA Breach Response
A HIPAA-compliant breach response has a defined structure. Each phase produces documentation that OCR may request during an investigation or audit.
Phase 1 — Containment (Days 1–3)
Isolate affected systems to stop further unauthorized access. Do not wipe or reimage affected systems until forensic evidence has been captured — the risk assessment requires demonstrating what data was accessed, and destroying that evidence can turn a limited incident into an uncontrolled one. Notify your cyber insurance carrier immediately. Most policies require prompt notification and can deploy breach response counsel and forensic investigators within covered costs. See our cyber insurance checklist for MSPs for how to make sure insurance coverage actually pays out when a breach occurs.
Phase 2 — Forensic Investigation (Days 1–30)
Determine what happened, when, which systems were affected, and whether PHI was acquired or viewed. Establish whether an encryption safe harbor applies. Document the methodology and findings in a format that can be produced to OCR on request.
Phase 3 — Low-Probability Assessment (Days 10–30)
Apply the four-factor risk assessment to each identified element of PHI. Document the analysis and the conclusion. If low probability cannot be established, begin the notification process. This document must be retained for six years and is the primary evidence that the covered entity made a good-faith determination rather than simply deciding not to notify.
Phase 4 — Notifications (by Day 60)
If the incident is a reportable breach, issue:
- Individual notifications describing the incident, the types of PHI involved, protective steps individuals should take, what the organization is doing, and contact information for questions.
- HHS OCR submission via the breach portal.
- State media notification if 500 or more residents of a single state are affected.
- Notification to the covered entity if you are the BA — this must happen as early as possible, not on day 59.
Phase 5 — Post-Incident Remediation (Days 60–90+)
Document the full incident timeline, root cause, and safeguard improvements implemented in response. OCR's enforcement data shows that organizations who breach once and update their risk management plan with documented improvements rarely breach again under the same cause. Those who breach and do not update their program are common repeat enforcement targets.
Packaging Breach Response as a Recurring MSP Service
The MSPs building durable compliance revenue treat breach response as a continuous service component, not a reactive project.
Breach Response Retainer ($1,500–$3,000/month): A standing agreement providing pre-negotiated response support — containment coordination, risk assessment documentation, notification drafting, and OCR submission assistance — within a defined response time. Clients pay for readiness; the alternative is scrambling to find breach counsel at 2 a.m. at emergency billing rates.
Annual Breach Response Plan Review ($1,000–$2,500/year): A structured annual update to documented incident response and breach notification procedures, and after any significant change to the environment. The documented policy update is itself compliance evidence.
Tabletop Breach Scenario Exercise ($2,000–$4,000): A structured walkthrough of a simulated breach from discovery to notification, with the covered entity's team. The exercise produces documented findings and a remediation plan that satisfies HIPAA, SOC 2, PCI DSS, and insurance testing requirements. For a guide to designing and selling tabletop exercises as a service, see [Tabletop Exercises for MSPs](/blog/tabletop-exercise-msp-guide-2026).
Breach response documentation — risk assessments, notification records, remediation logs — also feeds the evidence libraries used in HIPAA audit prep and SOC 2 compliance. These programs share the same underlying documentation; organizing it once serves multiple use cases simultaneously.
The Proposed 72-Hour Reporting Window
The HIPAA Security Rule NPRM published in January 2025 proposes shortening HHS OCR reporting to 72 hours from discovery for breaches affecting 500 or more individuals, replacing the current 60-day window for large breaches. As of September 2026, this change has not been finalized. However, the regulatory direction is clear.
MSPs whose breach response procedures are built around a 60-day timeline should begin designing for 72-hour readiness now. The five phases above can be compressed to 72 hours if the procedures, templates, and escalation paths are pre-built — not assembled under pressure after a breach has already occurred.
Track Breach Readiness Across Your Healthcare Portfolio
Nuronus tracks HIPAA control status — including breach notification procedures, incident response plan completion, risk assessment documentation status, and BAA inventory — across every healthcare client from a single multi-tenant dashboard. When a covered entity receives an OCR inquiry, you can generate a compliance gap summary showing what documentation is in place and what needs work, in the format investigators expect.
Start free with up to two clients — no credit card required.
*Ready to build a HIPAA breach response practice? Nuronus makes breach readiness trackable across every healthcare client in your portfolio.*
Ready to Add Compliance Services to Your MSP?
Free forever for 2 clients. All features included. No credit card required.
Get Started Free
Brett Coffin
Founder, Nuronus
20+ years in IT infrastructure and security. Built Nuronus after watching MSPs leave compliance revenue on the table because the tooling made it impossible to deliver profitably.