Your AI Vendor Had a Breach. What Does Your Practice Owe, and When?

A vendor breach does not become your problem when the vendor emails you. Under 45 CFR 164.410 and the agency rule at 78 FR 5566, it may already have been your problem for 45 days.

Ed

HIPAA Compliance, Agentic AI Security, Breach Notification, Business Associate Agreement, AI Voice Agent

The email arrives on a Tuesday. Your AI intake vendor writes that it "experienced a security incident affecting a subset of customer data" and that it is "conducting a thorough investigation." No numbers. No patient names. No date of discovery. Under 45 CFR §164.410(b), that vendor had up to 60 calendar days from its own discovery to send you that sentence. The question that decides your exposure is not what the vendor did wrong. It is what your practice owes, and from which day the counting started.

Most owners assume the answer is simple: the vendor breached, the vendor notifies, the vendor pays. The HIPAA Breach Notification Rule at 45 CFR Part 164 Subpart D says otherwise. In March 2026 the HHS Office for Civil Rights (OCR) settled with MMG Fusion, LLC, a dental software business associate, over a 2020 intrusion affecting roughly 15 million individuals, citing its failure to notify the covered entities involved. OCR Director Paula M. Stannard said that timeliness "is crucial for a covered entity to meet its own breach notification obligations."

The mechanic that decides your clock was printed in the Federal Register at 78 FR 5566, and it turns on a single word that vendor contracts rarely define: agency.

Whether Your Vendor Is Your Agent Decides Whether Its Discovery Date Is Also Yours

In the preamble to the Breach Notification Rule, HHS wrote that "if a business associate is acting as an agent of a covered entity ... the covered entity must provide notifications under §164.404(a) based on the time the business associate discovers the breach, not from the time the business associate notifies the covered entity. In contrast, if the business associate is not an agent ... the covered entity is required to provide notification based on the time the business associate notifies the covered entity of the breach" (78 FR 5566, at 5655).

One incident, two very different practices.

  • Agent. The day your vendor learned is the day you learned. If it held the news for 45 days, you have 15 left to reach every affected patient.

  • Not an agent. Your 60 days begin when the vendor tells you. Total elapsed time from compromise to a patient opening a letter can lawfully approach 120 days.

Which one applies is not decided by a clause. Under 45 CFR 160.402(c), agency is determined by the federal common law of agency, which looks at the right to control the manner and means of the work rather than at what the paperwork calls the parties. A vendor operating on your instruction, running your scripts, inside your workflows, may be your agent whatever label the agreement uses. The signature side of this is mapped in our piece on the BAA chain across an AI voice vendor stack.

There Are Four Clocks in the Rule, and Three of Them Run 60 Days

Most practices remember one deadline. The rule sets four.

  • Patients. 45 CFR §164.404(b) requires notice without unreasonable delay and no later than 60 calendar days after discovery. Sixty days is the outer wall, not the target.

  • Media. 45 CFR §164.406 requires notice to prominent media outlets when a breach involves more than 500 residents of a single State or jurisdiction, on the same 60-day limit.

  • HHS. 45 CFR §164.408(b) requires contemporaneous notice to the Secretary at 500 or more individuals. Under §164.408(c), breaches affecting fewer than 500 are logged and reported within 60 days of the end of the calendar year, so a CY2026 incident is due by 1 March 2027.

  • Your vendor to you. 45 CFR §164.410(b) requires the business associate to notify the covered entity without unreasonable delay and no later than 60 days after its discovery.

Notice what the fourth clock does to the first three. If the agency analysis lands against you, every day your vendor spends deciding whether to tell you is a day removed from your own runway, and that exposure is created before you know anything is wrong.

The Clock Starts on Knowledge of the Incident, Not on the Day Your Investigation Concludes

This is the most expensive misreading in the rule. HHS addressed it directly: the clock "begins upon knowledge of the incident, even if it is not yet clear whether the incident qualifies as a breach" (78 FR 5566, at 5656). Investigating carefully is correct. Treating the investigation as a pause button is not.

Two provisions make this harder still. Under 45 CFR §164.402, an impermissible use or disclosure of protected health information is presumed to be a breach unless the entity demonstrates a low probability of compromise through a four-factor risk assessment: the nature and extent of the PHI, who received or used it, whether it was actually acquired or viewed, and the extent of mitigation. Under 45 CFR §164.414(b), the burden of proof sits with the covered entity.

Read together: you are presumed to have had a breach, you must prove otherwise, and the days keep counting while you assemble that proof. A practice that cannot say which day it learned, from whom, and what it did next is reconstructing a position rather than defending a documented one. This is why the architectural questions outrank the policy binder, a distinction covered in architectural versus policy HIPAA compliance for PHI.

Business Associates Filed 16 Percent of Large Breach Reports in CY2024 and Accounted for 85 Percent of the People Exposed

In its CY2024 Annual Report to Congress, OCR recorded 663 large breaches, those affecting 500 or more individuals, touching approximately 242,908,056 people.

  • Health care providers filed 505 reports, 76 percent by count, but accounted for 14 percent of affected individuals.

  • Business associates filed 106 reports, 16 percent by count, but accounted for 206,921,071 individuals, roughly 85 percent of everyone exposed.

  • Hacking and IT incidents made up 534 reports, 81 percent by count, and 99 percent of affected individuals.

Providers report more often. Vendors expose more people. And every practice behind a compromised platform still owes its own patients a letter.

HITECH Act §13402(e)(4) requires HHS to post large breaches, and the OCR portal is searchable by covered entity name and by business associate name. Your practice is listed alongside the vendor's.

MMG Fusion Prices Late Vendor Notice, and Presence Health Priced Late Practice Notice at $475,000

MMG Fusion, LLC. On 5 March 2026, OCR announced a $10,000 settlement and a three-year corrective action plan with the dental software vendor over a December 2020 intrusion affecting approximately 15,000,000 individuals. Among the cited failures: "Failing to notify covered entities affected by the incident of the breach." OCR Director Paula M. Stannard set out the standard: "When a breach occurs, business associates must notify affected covered entities without unreasonable delay and within 60 calendar days of discovery. This timeliness is crucial for a covered entity to meet its own breach notification obligations." The figure is small. The precedent is not: vendor silence is itself enforceable.

Presence Health. On 9 January 2017, OCR announced a $475,000 settlement, its first enforcement action premised on untimely notification alone. Per the HHS release, the entity discovered the breach on 22 October 2013 and OCR received the report on 31 January 2014. The violation was the calendar.

OCR has priced timeliness higher since: Sentara Hospitals, $2,175,000 in 2019, for failure to properly notify HHS. The ceiling is set by regulation. Penalty tiers sit at 45 CFR 160.404, with amounts in effect published at 91 FR 3665 on 28 January 2026: a maximum of $73,011 per violation and an annual cap of $2,190,294 per identical provision. Under 45 CFR §160.406, each day of a continuing violation counts as a separate violation. HHS has separately applied lower administrative caps under a 2019 enforcement discretion notice at 84 FR 18151, which is current practice rather than governing law.

A BAA Moves the Work of Notifying Patients, Not the Liability, and State Law Can Cut Your 60 Days to 30

HHS is explicit that a covered entity "may ... delegate the responsibility of providing the required notifications" to a business associate, while "a covered entity ultimately maintains the obligation" (78 FR 5566, at 5656). Delegation moves labour. No contract between two private parties moves a duty the regulation assigns to you.

What a business associate agreement can do is tighten the schedule. HHS confirms the parties "may negotiate stricter timeframes," and the ratchet runs one way: faster than 60 days is available, slower is not. The contractual hooks the rule provides are narrow, at 45 CFR §164.504(e)(2)(ii)(C) and §164.314(a)(2)(i)(C). Terms such as 24-hour notification windows and SOC 2 attestations are worth having, but they are commercial choices rather than HIPAA requirements.

HIPAA's 60 days is also a ceiling rather than a floor. More stringent state law survives under 45 CFR 160.203(b) and 42 U.S.C. 17951(a), so the practical deadline for a multi-state patient list is the shortest one applying to anyone on it.

  • Florida. Fla. Stat. §501.171 requires notice to individuals within 30 days and to the Attorney General within 30 days at 500 or more Florida residents. A third-party agent must notify the covered entity within 10 days. Under §501.171(6)(b), "an agent's failure to provide proper notice shall be deemed a violation of this section against the covered entity."

  • Colorado. C.R.S. §6-1-716 sets 30 days for individuals, with Attorney General notice at 500 or more Colorado residents. Under §6-1-716(3)(b), "the law or regulation with the shortest time frame for notice to the individual controls," and waiver of the section is void as against public policy.

  • Washington. RCW 19.255.010 sets 30 calendar days and requires a vendor to notify the data owner immediately following discovery.

Florida is the federal agency trap in different clothes: the vendor misses its deadline, and the statute records the failure against you.

The Verification Work That Decides the Outcome Happens Before the Incident

None of this is answerable in the 48 hours after a vendor email lands. All of it is answerable this month, in writing.

  • Fix the discovery definition. Have the vendor state in the agreement what event it treats as discovery, and commit to a window measured from that event, not from the close of its investigation.

  • Settle the agency question in advance. Document how much control your practice exercises over the vendor's manner and means, and plan on its discovery date being treated as yours.

  • Know your shortest state clock. Run your patient roster against the states in it and work to the tightest deadline, not the federal one.

  • Pre-build the notification package. Letter template, substitute notice plan and HHS portal path, drafted while the calendar is calm.

  • Log discovery contemporaneously. Date, time, source and first action taken, recorded the day it happens. Under §164.414(b) that log is your evidence.

  • Confirm what the vendor retains. A vendor holding less has less to lose, which is the practical argument behind zero-retention handling of patient call data.

Consider the prepared version. The vendor email arrives. You have already settled the agency question, so you treat the vendor's discovery date as yours. You already know your shortest deadline is Colorado's 30 days under C.R.S. §6-1-716, not the federal 60. Your letter template exists. You notify inside three weeks, log every step, and stay out of the tier at 45 CFR 160.404 where each day of a continuing violation counts separately against a $73,011 per-violation maximum. Illustrative model - not a client result or guarantee.

One item belongs on the horizon. The HIPAA Security Rule notice of proposed rulemaking was published at 90 FR 898 on 6 January 2025 and remains proposed as of August 2026, carried in the Unified Agenda under RIN 0945-AA22 with final action projected for July 2027. If adopted as written it would require business associates to report contingency-plan activation within 24 hours, require annual written third-party verification of their technical safeguards, and add express language at proposed §164.308(b)(3) that delegation does not end liability. Proposed is not law, but it signals where the standard is heading. The questions worth asking a vendor today are set out in our AI voice agent vendor security questionnaire.

You already hold a business associate agreement with every vendor that touches protected health information. You already know which of them could reach your patient records if its own network were compromised. What most practices have never been given in writing is the date that vendor would call discovery, and that date decides how much of your 60 days actually exists. The same discipline applied to the intake layer is set out on our HIPAA-Compliant AI agent page.

Frequently asked questions

Our vendor notified us on day 50 of its own timeline. Do we still have a full 60 days?

It depends on agency. If the vendor acts as your agent, HHS states your obligation runs from the time the business associate discovered the breach rather than from the time it notified you (78 FR 5566, at 5655), leaving roughly 10 days. If it is not your agent, your 60 days start on the day it notified you. The determination is made under the federal common law of agency per 45 CFR 160.402(c), not by the contract's label.

Does the 60-day clock start once we confirm it was actually a breach?

No. HHS states the clock "begins upon knowledge of the incident, even if it is not yet clear whether the incident qualifies as a breach" (78 FR 5566, at 5656). Under 45 CFR §164.402 the incident is presumed to be a breach unless you demonstrate a low probability of compromise, and under §164.414(b) the burden of proof is yours.

Can our business associate agreement make the vendor responsible for notifying our patients?

It can make the vendor do the work. It cannot move the legal duty. HHS states a covered entity may delegate the responsibility of providing the required notifications while it "ultimately maintains the obligation" (78 FR 5566, at 5656). If the delegated notice is late or defective, the covered entity answers for it.

Fewer than 500 of our patients were affected. Do we still report to HHS?

Yes, on a different schedule. Under 45 CFR §164.408(c), breaches affecting fewer than 500 individuals are logged and submitted within 60 days of the end of the calendar year, so a CY2026 incident is due by 1 March 2027. Patient notice still runs on the §164.404(b) limit, and any shorter state deadline still applies.

References

  • 45 CFR Part 164, Subpart D, §§164.400-414; agency determination, 45 CFR 160.402(c); preemption, 45 CFR 160.203(b) and 42 U.S.C. 17951(a).

  • HHS Breach Notification Rule preamble, 78 FR 5566, discussion at 5655-5656.

  • HHS Office for Civil Rights: MMG Fusion, LLC resolution agreement and corrective action plan, 5 March 2026; Presence Health settlement, 9 January 2017; Sentara Hospitals settlement, 2019.

  • HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured PHI, CY2024. HITECH Act §13402(e)(4).

  • Penalty tiers, 45 CFR 160.404; continuing violations, 45 CFR 160.406; amounts in effect, 45 CFR 102.3 as adjusted at 91 FR 3665, 28 January 2026; enforcement discretion notice, 84 FR 18151.

  • HIPAA Security Rule notice of proposed rulemaking, 90 FR 898, 6 January 2025; Unified Agenda RIN 0945-AA22.

  • Fla. Stat. §501.171; Colo. Rev. Stat. §6-1-716; Wash. Rev. Code 19.255.010.

Next Step

If your premium practice runs more than 100 inbound consult inquiries a month and has no structured measurement of how many never reach a scheduled consultation, your pipeline is leaking revenue. We quantify this for your practice in a 30-minute Intake Leak Audit.