Dental office security dashboard showing a breach notification countdown timer and reporting timeline

Every dental practice owner has heard some version of the rule. You have 60 days to report a breach. It gets repeated in trainings, in vendor webinars, and in more than one article sitting on the first page of Google right now.

The problem is that the HIPAA breach notification timeline is not one 60-day deadline, and two things about it are commonly reported backwards. For a breach of 500 or more people, the federal report does not get its own separate 60-day window. It is due contemporaneously with the letters to your patients, which for most practices means sooner. And for the breach a dental office actually has, one misdirected email or one lost laptop, the federal report may not be due for up to fourteen months, depending on when in the year it is discovered, on a schedule that depends on a log you are supposed to have been keeping all along.

Both of those are in the regulation. Neither shows up in most of what is written on this subject. We pulled the current text of the regulation and read it section by section. Here is what the rule actually requires, where the common version goes wrong, and what a practice or group should have in place before the clock starts.

The 60-Day Rule Is a Ceiling, Not an Allowance

Start with the sentence everyone half-remembers. Under 45 CFR 164.404(b), a covered entity must notify affected individuals:

“without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.”

Read the whole sentence, not the number at the end. The operative standard is “without unreasonable delay.” The 60 days is the outer boundary, the point past which delay is indefensible by definition. It is not a grace period you are entitled to spend.

That distinction matters when an investigator reconstructs your timeline afterward. If your practice identified affected patients on day four and mailed letters on day 58, you met the 60-day number and still may not have met the standard. The question is not whether you beat the deadline. It is whether anything about the delay was unreasonable.

There is a second thing buried in that sentence. The clock starts at discovery, not at the incident. A breach is treated as discovered on the first day it is known, or on the first day it would have been known by exercising reasonable diligence. A practice with no monitoring in place does not get a later start date because nobody was watching. If anything, weak monitoring makes the discovery date harder to defend, not easier.

Three Different Clocks, and They Do Not All Run the Same Way

Here is where the common version of the rule breaks down. Notifying patients, notifying the federal government, and notifying the media are three separate obligations with three different triggers. Most summaries collapse them into one 60-day deadline, which is right for individuals, right for the media on a per-state basis, and wrong for the federal report in both directions depending on the size of the breach.

1. Notifying affected individuals

This is the 60-day one, from 164.404. Without unreasonable delay, no later than 60 calendar days after discovery. The rule also specifies what the notice has to contain, including a brief description of what happened, the date of the breach and the date of discovery, the types of information involved, what individuals should do to protect themselves, and what the practice is doing about it.

2. Notifying the Secretary of HHS

This is the one that is most often reported incorrectly, and the error runs in the practice’s favor, which is what makes it dangerous. For breaches involving 500 or more individuals, 164.408(b) requires notification to the Secretary:

“contemporaneously with the notice required by 164.404(a) and in the manner specified on the HHS Web site.”

Contemporaneously. Not within 60 days of the federal notice as its own separate clock. At the same time you notify the individuals. If you notify patients on day 12, the federal report goes in on day 12. A practice that treats the HHS report as something it has a fresh 60 days to handle after the patient letters go out has misread the rule.

3. Notifying the media

Under 164.406, a breach involving more than 500 residents of a State or jurisdiction requires notifying prominent media outlets serving that state or jurisdiction, on the same without-unreasonable-delay, no-later-than-60-days timing.

Note that this threshold is worded differently from the HHS one. The federal reporting trigger is 500 or more individuals total. The media trigger is more than 500 residents of a single state. For a multi-location group operating across state lines, those two counts are not the same number, and one can be met while the other is not.

The Rule That Actually Governs Most Dental Breaches

Nearly everything written about dental data breaches is written about the enormous ones. Millions of records, a benefit administrator, a national headline. Those events are real, and we have catalogued the largest ones, but they are not what happens to an individual practice.

What happens to a practice is one email sent to the wrong recipient. One laptop gone from a car. One workstation with something on it that should not be there. Those breaches involve a handful of people, not 500. And they are governed by a provision that almost no article on this subject mentions.

45 CFR 164.408(c) covers breaches involving fewer than 500 individuals. For those, a covered entity:

“shall maintain a log or other documentation of such breaches and, not later than 60 days after the end of each calendar year, provide the notification required by paragraph (a) of this section for breaches discovered during the preceding calendar year.”

Two obligations sit inside that sentence, and practices tend to miss both.

The first is the log. It is maintained continuously, as breaches occur. It is not something you assemble in February. If a practice cannot produce a contemporaneous log of its small breaches, that gap is itself a documentation failure, separate from anything to do with the breaches in it.

The second is the deadline, which is not 60 days after discovery. It is 60 days after the end of the calendar year in which the breach was discovered. A small breach discovered in March is reported the following year, in the window that closes 60 days into the new year, March 1 in most years. That is a much longer runway than most people assume, and it is the exact reason the log matters. Nobody remembers a March incident accurately the following February without one.

Individual notification is unaffected by any of this. A breach affecting four people still requires notifying those four people without unreasonable delay and within 60 days. The annual schedule applies only to the federal report.

Before Any Clock Starts, You Have to Decide It Is a Breach

There is a step that comes before every deadline in this article, and it carries more operational weight than any of them. It is also the one we commonly see handled backwards.

Under 45 CFR 164.402, an impermissible use or disclosure of protected health information is presumed to be a breach. The practice does not get to decide an incident was minor and move on. The presumption is that it is reportable unless the covered entity:

“demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors”

The rule then lists the four factors:

  • The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification
  • The unauthorized person who used the protected health information or to whom the disclosure was made
  • Whether the protected health information was actually acquired or viewed
  • The extent to which the risk to the protected health information has been mitigated

The burden sits with the practice, and the verb is “demonstrates.” That means documentation. A risk assessment that happened in someone’s head, or a conclusion that an incident was probably fine, is not a demonstration of anything. If the practice cannot produce a written four-factor assessment, the presumption stands and the incident is a breach.

This inverts how most offices handle a small incident. The instinct is to ask whether there is a reason to report it. The rule asks whether you can document a reason not to.

Your IT Provider’s Discovery Date May Already Be Yours

This is the part that should matter most to anyone evaluating an IT partner, and most coverage of dental breach obligations skips it entirely.

Your IT provider is a business associate. Under 45 CFR 164.410, a business associate must notify the covered entity following discovery of a breach, and the rule defines that discovery the same way it defines yours:

“a breach shall be treated as discovered by a business associate as of the first day on which such breach is known to the business associate or, by exercising reasonable diligence, would have been known to the business associate.”

The rule goes further. A business associate is deemed to have knowledge of a breach if it is known, or would have been known through reasonable diligence, to any employee, officer or agent of that business associate other than the person who committed the breach.

Sit with what that means operationally. If an alert fired on your network in the second week of the month and your provider’s tooling captured it, the discovery date can attach then, not on the day someone finally called you. When a business associate is acting as your agent, its discovery is imputed to you. Your 60-day clock may have started while you were still unaware anything had happened.

That is a contractual and operational question, not a theoretical one. It is worth knowing exactly what your provider monitors, how quickly a signal reaches a human, and what their notification obligation to you says in writing. This is one of the more useful things to raise when you are evaluating dental IT support companies, because the answer separates a provider running real security operations from one that will discover your breach at the same time you do.

Tom says it this way: “If your IT partner can’t quantify performance, you’re not buying a managed service, you’re buying hope.” Breach discovery is where that stops being a philosophical point and starts being a date on a federal filing.

What the Clocks Actually Look Like, Side by Side

Here is every notification obligation in one place, with the provision each one comes from.

Obligation When it applies The actual deadline Where it comes from
Decide whether it is a breach at all Any impermissible use or disclosure of PHI Before any clock starts. Presumed a breach unless you document a four-factor risk assessment showing “a low probability that the protected health information has been compromised” 45 CFR 164.402
Notify affected individuals Every breach, any size “Without unreasonable delay and in no case later than 60 calendar days after discovery.” The 60 days is the ceiling, not the target 45 CFR 164.404(b)
Notify HHS, large breach 500 or more individuals “Contemporaneously with the notice required by 164.404(a).” Same time as the patient letters, not a separate 60-day window 45 CFR 164.408(b)
Notify HHS, small breach Fewer than 500 individuals Maintain a running log, then file “not later than 60 days after the end of each calendar year” for breaches discovered that year 45 CFR 164.408(c)
Notify the media More than 500 residents of one State or jurisdiction Same without-unreasonable-delay, no-later-than-60-day timing. Note this counts residents per state, not individuals overall 45 CFR 164.406
Business associate notifies you Breach at your IT provider, billing vendor or other BA The BA must notify you “without unreasonable delay and in no case later than 60 calendar days after discovery.” Discovery is the first day the breach is known, or would have been known by reasonable diligence, to any employee or agent of the BA, and when the BA is your agent that date is imputed to you 45 CFR 164.410
The one exception that pauses all of the above A law enforcement official states that notice would impede a criminal investigation or damage national security Every deadline above is written “except as provided in 164.412.” A written statement delays notice for the period it specifies. An oral statement must be documented and delays notice no longer than 30 days unless a written one follows 45 CFR 164.412

What a Violation Actually Costs Now

A maximum penalty of $50,000 per violation and an annual cap of $1.5 million get quoted constantly in dental compliance content. Those were the figures Congress wrote in 2009, and they still appear in the body of the regulation itself. They are not the amounts actually enforced today.

45 CFR 160.404 says so directly. It sets out the tiers, then states that the amounts “were adjusted in accordance with the Federal Civil Monetary Penalty Inflation Adjustment Act” and “appear at 45 CFR part 102,” where they are “updated annually.”

The current adjusted amounts published in 45 CFR 102.3 are materially higher:

  • Did not know: minimum $145, maximum $73,011 per violation, calendar-year cap $2,190,294
  • Reasonable cause: minimum $1,461, maximum $73,011 per violation, calendar-year cap $2,190,294
  • Willful neglect, corrected within 30 days: minimum $14,602, maximum $73,011 per violation, calendar-year cap $2,190,294
  • Willful neglect, not corrected: minimum $73,011 per violation, maximum $2,190,294 per violation, calendar-year cap $2,190,294

The tier structure is worth reading closely, because the practice’s own conduct determines which one applies. The bottom tier turns on whether you knew or, by exercising reasonable diligence, would have known. The top tier is reserved for willful neglect left uncorrected, where the minimum is $73,011.

Note also that the 30-day correction window in the willful neglect tiers runs from the first date the practice knew, or by exercising reasonable diligence would have known, that the violation occurred. That is the same reasonable-diligence standard that governs breach discovery. It shows up throughout this rule, and it consistently favors the organization that was actually paying attention.

The table these figures come from was published on January 28, 2026, and the amounts are adjusted annually, so the next revision is due around January 2027. Verify the current figures at 45 CFR 102.3 before relying on them; the table is updated annually.

What to Have Ready Before the Clock Starts

Every deadline in this article assumes you can answer basic questions quickly. Most practices cannot, and that is what turns a manageable incident into a bad one.

A written incident response plan that names people. Not a binder. A short document that says who decides whether an incident happened, who runs the four-factor assessment, who signs off on notification, and who calls counsel. The 60-day ceiling is generous until you spend the first three weeks deciding who is in charge.

The breach log, maintained now. The under-500 requirement is a running obligation. Starting a log the year you need one does not satisfy a rule that asks you to have been keeping it.

Logging and monitoring good enough to establish a discovery date. Reasonable diligence is the standard on both the breach clock and the penalty tiers. A practice that can show what happened, when it was detected, and what was done about it is in a different position from one reconstructing events from memory.

A BAA with every vendor that touches patient data, and a real read of the notification clause. The agreement is required regardless. What varies, and what matters here, is how fast the business associate has to tell you and what they commit to monitoring. If you are also weighing cyber liability coverage for the aftermath, the interaction between your controls and your policy is worth understanding before you need either.

Documentation retained for six years. Risk assessments, log entries, notification copies, decisions not to notify and the reasoning behind them. The decision not to report is the one you will most need to defend, and it is only defensible in writing.

For groups running multiple locations, all of this multiplies. The discovery date, the counting of affected individuals, the per-state media threshold, and the four-factor assessment all have to work consistently across every site. When each location handles incidents its own way, you do not have one breach response process, you have as many as you have offices, which is exactly the fragmentation that makes an incident harder to contain and harder to explain afterward.

Where the Numbers Come From on Our Side

Everything above is about what happens after an incident. The more useful question is how many incidents reach that point at all, and that is measurable.

In our June 2026 Dental Cybersecurity Data Report, our security operations analyzed 2,579,269,005 events across the practices and DSOs we protect. That filtered down to 43,483 signals worth a closer look, 108 that a human analyst investigated, and 13 confirmed incidents that required remediation. Ransomware incidents across 10,795 protected endpoints: zero.

The reason to publish that funnel is not the zero at the end. It is the shape of it. Two and a half billion events became 13 real incidents because something was watching continuously and someone was reviewing what the tooling escalated. That is also what produces a defensible discovery date. A practice with monitoring knows when something started. A practice without it is left arguing about when it reasonably should have known, which is a much worse conversation to have with a regulator.

Tom’s Take on the Clock

The 60-day number is the least important thing in this rule, and it gets all the attention.

What actually determines how a breach goes for a dental practice is decided long before the deadline matters. Whether anyone was watching closely enough to establish when it started. Whether there is a written process that says who does what. Whether the four-factor assessment gets documented or improvised. Whether the log has been kept all along. Whether the business associate agreement obligates your provider to tell you quickly, and whether that provider is running the kind of operation that would notice in the first place.

Practices that have those things treat a breach as a difficult week with a clear sequence. Practices that do not spend the first two weeks of a 60-day window figuring out what they are even looking at, and then discover the clock started earlier than they thought.

If you want a second set of eyes on your incident response plan, your BAAs, or what your current provider actually monitors, we are happy to compare notes. It is a much better conversation to have now than on day one of a real incident.

Dental Breach Notification FAQs

Does a dental practice really have 60 days to report a breach to HHS?

Not as a general rule. For a breach involving 500 or more individuals, 45 CFR 164.408(b) requires notifying the Secretary contemporaneously with the notice to affected individuals, meaning at the same time, not on a separate 60-day clock. For a breach involving fewer than 500 individuals, the federal report is filed not later than 60 days after the end of the calendar year in which the breach was discovered. The 60-day figure most people remember is the outer limit for notifying affected individuals under 164.404(b).

Can a breach be discovered on a weekend or a holiday?

Yes, and the deadline is measured in calendar days, not business days. 45 CFR 164.404(b) says “60 calendar days,” so weekends, holidays and office closures all count against the clock. A breach discovered the Friday before a holiday week does not get those days back. This is one practical reason the incident response plan should name a backup decision-maker rather than a single person.

Is every lost laptop a reportable breach if the device was encrypted?

Encryption is what changes the answer here. The rule applies to unsecured protected health information, which 45 CFR 164.402 defines as information not rendered unusable, unreadable or indecipherable through a technology or methodology specified by the Secretary. A properly encrypted laptop with the key not also lost is generally outside the breach notification requirements entirely. An unencrypted one is presumed to be a breach unless the practice documents a four-factor risk assessment showing a low probability of compromise. That single control decides whether a lost device is an inconvenience or a notification event.

What does a HIPAA violation cost a dental practice today?

The commonly quoted $50,000 per violation and $1.5 million annual cap are the unadjusted 2009 statutory figures. The current inflation-adjusted amounts are published at 45 CFR 102.3 and updated annually. Penalties are tiered by culpability: the per-violation maximum is $73,011 on the first three tiers, rising to $2,190,294 for willful neglect left uncorrected, with a $2,190,294 calendar-year cap for identical violations across all tiers.

What happens if we cannot reach some of the affected patients?

The rule anticipates this. Where contact information is out of date, 45 CFR 164.404(d) requires substitute notice. If that involves ten or more individuals, the substitute notice must be either a conspicuous posting for 90 days on the home page of the practice website or a conspicuous notice in major print or broadcast media where the affected individuals likely reside, and it must include a toll-free number that stays active for at least 90 days. That is a meaningful operational commitment, and it is a good argument for keeping patient contact records current before anything goes wrong.

Can law enforcement delay our notification?

Yes, and it is the one recognized exception to the timelines in this article. Every deadline under 164.404, 164.406 and 164.408 is written “except as provided in 164.412,” which allows a delay when a law enforcement official states that notification would impede a criminal investigation or damage national security. If that statement is in writing and specifies a time period, the delay runs for that period. If it is made orally, the practice documents who said it and may delay no longer than 30 days unless a written statement follows. It does not apply to the ordinary case where a practice simply wants more time to investigate.

Posted in Dental Cybersecurity

Filter By: