Notification Deadlines Calendar
Note: Deadlines represent the maximum allowable time. Notifications must always be provided "without unreasonable delay."
| Required Notification | Regulatory Deadline (No Later Than) | Status |
|---|
Individual Notice Content Checklist
Under 45 CFR 164.404(c), individual notifications must be written in plain language and include the following elements:
- A brief description of what happened, including the date of the breach and the date of discovery, if known.
- A description of the types of unsecured protected health information (PHI) that were involved in the breach (e.g., full name, SSN, DOB, home address, account number, diagnosis, disability code).
- Any steps individuals should take to protect themselves from potential harm resulting from the breach.
- A brief description of what the covered entity is doing to investigate the breach, to mitigate harm to individuals, and to protect against any further breaches.
- Contact procedures for individuals to ask questions or learn additional information, which shall include a toll-free telephone number, an email address, Web site, or postal address.