Your Breach Clock Starts When Your Vendor Tells You
Most breach notification planning assumes the organization discovers its own breach. Someone in security sees something, the clock starts, and sixty days later the notices go out.
That is not how it usually happens. Most healthcare breaches now originate at a vendor, which means the covered entity learns about it secondhand, on a timeline it does not control. And the two notification clocks involved do not run in parallel. They run in sequence, from the same finite budget of days.
When does the HIPAA breach clock start?
For a covered entity, on discovery. The Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 calendar days from discovery.
For a business associate, the same 60-day ceiling applies, but the notification runs to the covered entity rather than to individuals.
Here is the part that matters operationally. A business associate that takes 50 days to notify has not violated the rule. It has, however, left the covered entity with ten days to investigate, determine scope, identify affected individuals, prepare notices, and send them.
The two clocks are not additive from the covered entity's perspective. Whatever the vendor uses, you do not get.
Is OCR actually enforcing this?
Yes, and the enforcement pattern shifted noticeably over the past eighteen months.
In March 2026, OCR announced a settlement with MMG Fusion, a Maryland software company operating as a business associate. Announcing it, OCR Director Paula M. Stannard framed the issue as notification timing specifically, noting that prompt notice from a business associate is what allows a covered entity to meet its own obligations to HHS and to individuals.
That is a meaningful framing. The enforcement interest is not only in the breach. It is in the delay between the vendor knowing and the customer knowing.
MMG Fusion is not isolated. Business associates that have settled with OCR across 2025 and 2026 include an accounting firm, a dental technology company, an information systems provider, a VPN services company, a corporate wellness provider, and a billing company. That is a broad definition of "vendor" and a deliberate one.
Two further changes worth tracking. OCR has indicated it will expand its risk analysis enforcement initiative in 2026 to cover risk management, meaning the question moves from whether you assessed risk to whether you acted on what you found. And OCR began enforcing the 42 CFR Part 2 regulations under newly delegated authority in February 2026, which matters for any organization holding substance use disorder records.
Why is vendor-originated breach so hard to scope?
Because the covered entity usually cannot answer the questions the notification requires.
When you discover your own breach, you have the logs. You can determine which records were touched, by whom, and whether anything was altered. Scoping is work, but it is tractable.
When a vendor reports a breach, you are told that data was exposed. What you then need to establish is which of your records were involved, which individuals those records belong to, and whether the exposure meets the notification threshold. That determination depends on a record of what you sent that vendor and when.
Most organizations do not have that record in usable form. They have SFTP logs showing sessions and filenames, scattered across whichever tool was used for that particular relationship. Reconstructing "what did we send Vendor X between March and July" from that is a manual project, and it is being started on day 51 of a 60-day window.
What can you actually control?
Not the vendor's discovery timeline, and not their internal escalation. Three things sit on your side of the line.
The contractual clock. The Breach Notification Rule sets a ceiling of 60 days for business associate notice. It does not stop you from requiring faster. Many business associate agreements simply restate the regulatory maximum, which means the vendor is contractually entitled to consume nearly your entire window. Negotiating a shorter notification window costs nothing at signing and is very difficult to add later.
The record of what you sent. If a vendor reports an incident covering a date range, the question is whether you can produce what you transmitted to them in that range without a manual reconstruction. This is the single largest determinant of how much of your remaining window gets spent on scoping.
The encryption safe harbor. Under 45 CFR 164.402, ePHI encrypted to NIST-approved standards with keys kept secure may fall outside breach notification obligations entirely, because the data is unusable to an unauthorized recipient. This does not help with data the vendor decrypted to process, but it is meaningful for data at rest in transit paths, and it is underused.
Does a file transfer platform help with breach scoping?
Partly, and it is worth naming the part.
We do not prevent a vendor from being breached. If your billing company gets ransomwared, nothing about how the files got there changes that. Vendor security assessment, contractual controls, and your own third-party risk program are the tools for that problem and they are not ours.
What we affect is the scoping question. Every exchange produces a structured, append-only audit event exported to storage you control, so "what did we send this vendor between these dates, and who accessed it" is a query rather than a reconstruction project. In a 60-day window where the vendor has already used 50, the difference between a query and a project is the difference between meeting the deadline and missing it.
That is one input into breach response, not a breach response program.
More on audit evidence and, for healthcare specifically, HIPAA-compliant file sharing. Related: the HIPAA Security Rule delay.
The short version
Breach notification planning generally models a single 60-day clock. In vendor-originated incidents, which are now the common case, that window is shared with an organization whose timeline you do not control and whose delay is not a violation.
Two questions are worth asking this quarter. What does your business associate agreement actually require for notification timing, and if a vendor reported an incident tomorrow covering the last four months, how long would it take to determine what you sent them?
Sources
- HHS Office for Civil Rights, settlement with MMG Fusion, LLC, March 5, 2026
- HHS, HIPAA Resolution Agreements and Civil Money Penalties
- HIPAA Journal, HIPAA Violation Fines
- LegalClarity, OCR HIPAA Settlement News: Latest Enforcement Actions