I treat HIPAA’s 60-day notice limit as a deadline - not a waiting period. If an AI vendor exposes protected health information (PHI), my first steps are to record discovery, preserve logs, and assign a notice owner. The clock starts at discovery, not when the investigation ends.
Here’s the approach I use:
- Set responsibilities: The vendor reports to the healthcare organization; the covered entity remains responsible for required notices, even when it delegates delivery.
- Check whether notice is required: Trace PHI through AI systems, review breach exceptions, and document the four-factor risk assessment.
- Track each deadline: Individual notices are due without unreasonable delay and within 60 calendar days. HHS reporting differs for breaches affecting 500 or more people, while media notice applies to more than 500 residents of one state or jurisdiction.
- Prepare and retain records: Explain what happened, what PHI was involved, and what people can do. Keep investigation findings, notice decisions, and delivery records.
- Follow through: Check BAA reporting terms, subcontractor duties, and corrective actions; use Censinet RiskOps to track vendor follow-up without unnecessary PHI exposure.
My rule: <u>keep contract reporting deadlines separate from HIPAA deadlines</u>, and don’t wait for a final forensic report before taking required action.
HIPAA Roles and AI Breach Review
HDO, AI Vendor, and Subcontractor Responsibilities
An AI vendor is a business associate when it creates, receives, maintains, or transmits PHI for a covered entity. Subcontractors that handle PHI for the vendor take on the same obligations.[6][8] BAAs should spell out permitted uses, safeguards, incident reporting, and downstream obligations.[7]
Assign investigation and notice tasks based on these roles.
| HDO / covered entity | AI vendor / business associate |
|---|---|
| Assign decision authority and oversee the breach review. | Investigate affected systems, PHI, access paths, and subcontractors. |
| Review evidence and direct mitigation. | Contain exposure, preserve evidence, and provide forensic findings. |
| Identify affected individuals and oversee individual, HHS, and applicable media notices. | Report incidents promptly and provide information needed for notices.[2][4] |
| Verify downstream controls and corrective action. | Require subcontractors to report to the vendor and pass required information upstream. |
An HDO acting as a business associate reports to its upstream covered entity. Delegation does not remove covered-entity responsibility. A vendor may investigate or submit an HHS report on the HDO’s behalf, but the covered entity remains accountable for required notices.[10]
Name an HDO decision owner and a vendor investigation lead. Require preliminary reporting rather than waiting for a final count of affected people. Then establish the timeline and evidence chain.
Track Discovery Dates, PHI Flows, and Evidence
Track event time, detection time, internal awareness, and HIPAA discovery separately. Record timestamps, time zones, who knew what, and when reasonable diligence should have revealed the breach. Assess agency relationships: an agent’s knowledge may affect the HDO’s discovery date, rather than the date its report arrives.[2][11]
Trace PHI through prompts, outputs, logs, training data, retrieval indexes, caches, backups, interfaces, support systems, and subprocessors. Verify actual contents, permitted uses, and de-identification status. A de-identified label is not enough.
Contain exposure while preserving evidence. Record who collected each item, when it was collected, where it was stored, and any changes. Use this record to assess whether the event meets HIPAA’s breach standard.
Determine Whether a Breach Requires Notice
The Breach Notification Rule, 45 C.F.R. §§ 164.400–414, applies to unsecured PHI.[2] A security incident is not automatically a breach. An impermissible use or disclosure is presumed to be a breach unless an exception applies or a documented assessment establishes a low probability of compromise.[2][5]
Test the narrow exceptions: authorized access within scope without further misuse, inadvertent disclosure between authorized persons without further misuse, or a good-faith belief that the recipient could not retain the information.[2][5]
Apply the four factors:
- The nature and extent of the PHI and the risk of re-identification.
- The unauthorized person or recipient.
- Whether the PHI was actually acquired or viewed.
- Mitigation.[2][5]
Examine retained prompts, training exposure, output leakage, and derived copies. Missing access logs do not prove that no access occurred. Check encryption or destruction against HHS guidance. Assess compromised keys or decryption mechanisms rather than relying on encryption labels alone.[3][9]
Document the evidence, exceptions, assessment limits, mitigation, and approval - even when notice is not required.
sbb-itb-535baee
What Is HIPAA BAA Compliance For Third-party Vendor Access In Healthcare? - AI and Technology Law
HIPAA Notice Deadlines, Content, and Delivery
HIPAA AI Breach Notice Deadlines
Once an incident is classified as a reportable breach, start planning notices immediately as part of your third-party AI risk management strategy.
Vendor Breach Reporting and Joint Investigation
BAAs may require shorter reporting windows for suspected or confirmed PHI exposure. Keep incident-reporting duties separate and active, including reports of suspected exposure. Send a preliminary report with the facts needed for notice, then update it as facts are confirmed. Don't wait for the forensic investigation to finish. [1]
| Phase | Actions | Owners | Evidence | Escalation threshold |
|---|---|---|---|---|
| Detection and initial reporting | Alert the HDO; open a shared notice record; follow the BAA reporting window. | Vendor security and privacy leads; HDO privacy officer | Initial alert, report timestamps, known affected-person information | Suspected or confirmed PHI exposure; missed contractual deadline |
| Joint scoping | Identify affected people, locations, and notice obligations. | HDO and vendor privacy, security, and legal teams | Affected-person counts, residency information, PHI details | 500 or more affected people; more than 500 residents in one state or jurisdiction |
| Containment | Restrict affected AI access; protect clinical workflows. | Vendor engineering; HDO security and clinical operations | Containment facts needed for notices | Imminent misuse requiring urgent individual contact |
| Notice preparation and delivery | Check facts and addresses; approve and send required notices. | HDO privacy, legal, and communications teams; delegated vendor staff | Approved notices, recipient lists, delivery records | Any risk of missing a notice deadline |
| Follow-up | Update reports; correct material notice errors; send supplemental notices. | Vendor investigation lead; HDO privacy team | Updated reports, corrected notices, delivery records | New facts that affect notice content |
A service outage does not stop the notice clock. [1]
Deadlines for Individual, HHS, and Media Notices
For reportable breaches of unsecured PHI, discovery-based notices are due without unreasonable delay. The 60-day deadline is an outer limit - not a waiting period. The vendor reports the breach, while the covered entity sends the required HIPAA notices. A vendor may send notices or submit an HHS report under an agreed delegation, but the covered entity remains responsible. [1]
Track state-law duties separately. A delay under 45 C.F.R. § 164.412 requires a law-enforcement statement that notice would impede a criminal investigation or damage national security. [1]
The table below separates vendor reporting deadlines from covered-entity notice duties. [1]
| Recipient | Threshold | Responsible party | Deadline |
|---|---|---|---|
| HDO | Any reportable vendor breach | Business associate | Without unreasonable delay; within 60 calendar days of vendor discovery, or sooner under the BAA |
| Affected individuals | One or more affected people | Covered entity | Without unreasonable delay; within 60 calendar days of discovery |
| HHS | 500 or more affected people | Covered entity | Without unreasonable delay; within 60 calendar days of discovery, with individual notice |
| HHS | Fewer than 500 affected people | Covered entity | Within 60 calendar days after the discovery year ends: March 1, or February 29 in a leap year |
| Prominent media outlets | More than 500 residents of a state or jurisdiction | Covered entity | Without unreasonable delay; within 60 calendar days of discovery |
What Individual Notices Must Include and How to Send Them
Write notices in plain language. Explain what happened, which PHI was involved, and the breach and discovery dates, if known. Include steps individuals can take to protect themselves, mitigation measures, investigation and prevention measures, and contact information and procedures. Keep individual, HHS, and media notices consistent. [1]
Send notices by first-class mail or electronically if the individual agreed. When contact information is insufficient, use the required substitute notice. If misuse is imminent, make urgent contact - such as a telephone call - in addition to written notice. Send supplemental notices when new facts affect notice content. [1]
Document the notice package and retain it with the breach file.
Breach Records, Contracts, and Vendor Oversight
Once notice decisions are made, keep the incident file active to support remediation, contract enforcement, and future risk reviews.
Keep Breach Decisions and Notice Records
Keep a decision file that includes the incident timeline, BAA, PHI involved, risk assessment, forensic findings, approvals, and remediation evidence. Document the basis for the notice decision, and link later findings to the same incident so the record stays complete.
Set BAA and AI Contract Response Requirements
Use the BAA and AI contract to spell out cooperation duties for incident discovery, escalation, reporting, evidence-sharing, forensic investigation, and remediation. Contractual discovery terms must not change HIPAA’s discovery standard.
Retain audit rights for SOC 2 reports, penetration test results, and security policies. Require access to evidence and assign each corrective action an owner, completion date, and validation evidence. Bring in data scientists and clinicians when model behavior or patient impact affects the review.
Update Vendor Risk Records With Censinet RiskOps
Once remediation starts, use Censinet’s Censinet RiskOps™ to update third-party and enterprise risk records, track corrective actions and supporting evidence, and inform renewal decisions without unnecessarily exposing PHI.
Review access controls, integration data flows, and fourth-party relationships to determine whether PHI use can continue. When needed to define the incident’s scope and corrective actions, require disclosures of AI training data sources, model governance practices, and bias testing methods. Use the platform as the source of truth for follow-up oversight and renewal decisions.
Conclusion: Assign Owners, Meet Deadlines, and Preserve Evidence
Give each responsibility a clear owner. The HDO coordinates required notices, while the AI business associate and its subcontractors supply incident facts and evidence. Put one person in charge of notice decisions and deadlines. Treat 60-day deadlines as outer limits; act sooner when facts are known. [1] Before closing the file, assign the notice owner, investigation lead, and evidence custodian.
Test for prompt injection, output leakage, and data exfiltration. Save prompt logs and API responses because model outputs may not be reproducible. Record the discovery date and document the breach decision before coordinating notices. [1]
At the final review, confirm that owners are assigned, deadline tracking is in place, and evidence is secured.
Before the next incident, confirm these controls:
- BAAs: Verify subcontractor reporting and cooperation duties.
- Contacts: Test the notice team’s contact details, including those for data scientists and clinicians. [1]
- Reporting: Simulate reporting from subcontractor to vendor to HDO. [1]
- Records: Retain the breach file. [1]
- Monitoring: Continuously monitor API activity and data flows alongside vendor reporting. [1]
FAQs
What if my AI vendor reports a breach late?
Your covered entity remains legally responsible for meeting HIPAA notification deadlines, even if your AI vendor reports a breach late. The 60-day clock for notifying individuals and the Department of Health and Human Services starts when either party discovers - or reasonably should have discovered - the breach. You can’t delay notification while waiting for the vendor to finish its investigation.
Your Business Associate Agreement should define discovery as the point when the vendor becomes aware of the breach and require reporting within 24 to 72 hours.
How do I assess a breach without AI access logs?
When AI access logs aren’t available, vendor contracts should require access to raw logs, indicators of compromise, and system images during an incident. They should also require vendors to preserve prompt logs, API response logs, and model version records before an incident occurs.
If those records are missing, conduct a four-factor risk assessment using the evidence you have: internal incident reports, system configuration changes, and vendor forensic data. Use this assessment to determine whether a breach of unsecured protected health information (PHI) occurred.
What if the affected patient count changes after notice?
If you don’t know the exact number of people affected when you first report a breach, provide an estimate [1]. You can revise that count as your investigation progresses [1].
Submit updates or clarifications through the Office for Civil Rights (OCR) electronic breach notification portal, using the transaction number from your original submission [1]. Keep accurate records and update the count as needed to meet your HIPAA notification obligations [1].