{
  "$schema": "https://bestinsuranceresearch.com/llms-full.txt",
  "recordType": "source",
  "id": "cfr-45-164-404-lii",
  "canonicalUrl": "https://bestinsuranceresearch.com/sources/cfr-45-164-404-lii",
  "contentVersion": "2026.08.31",
  "generatedFor": "2026-09-06",
  "operator": {
    "legalName": "WJB Services, Inc.",
    "dba": "Bollinsure Insurance Services",
    "license": "6013787",
    "licenseAuthority": "California Department of Insurance"
  },
  "license": "Text on this page may be quoted with attribution and a link to the canonical URL.",
  "notice": "Public page facts only. This record contains no visitor question, no tool input, and no identifier. It is not a coverage determination, an eligibility decision, or individualized advice.",
  "title": "45 CFR 164.404 - Notification to individuals (HIPAA Breach Notification Rule)",
  "publisher": "Cornell Legal Information Institute, reproducing the Code of Federal Regulations",
  "url": "https://www.law.cornell.edu/cfr/text/45/164.404",
  "officialHost": false,
  "sourceType": "regulation",
  "authorityLevel": "secondary",
  "primary": false,
  "jurisdiction": "US",
  "publishedDate": "2013-01-25",
  "effectiveDate": "2013-03-26",
  "accessedDate": "2026-08-31",
  "lastChecked": "2026-08-31",
  "updateCadence": "on-amendment",
  "status": "active",
  "supportsClaims": [
    {
      "claimId": "cfr-45-164-404-lii#c1",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cfr-45-164-404-lii#c1",
      "checksum": "e52885703266",
      "text": "Paragraph (b), Implementation specification: Timeliness of notification, provides that a covered entity shall provide the notification required by paragraph (a) without unreasonable delay and in no case later than 60 calendar days after discovery of a breach."
    },
    {
      "claimId": "cfr-45-164-404-lii#c2",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cfr-45-164-404-lii#c2",
      "checksum": "3065a9c8efe8",
      "text": "The 60 calendar day period runs from discovery of the breach, and is an outer limit rather than a safe harbor, because notification must also be without unreasonable delay."
    }
  ],
  "reliedOnBy": [
    {
      "kind": "Example",
      "title": "Reading the HIPAA notification rule against the CISA and NIST control cadences to see why one is a ceiling and the others are intervals",
      "url": "https://bestinsuranceresearch.com/examples/breach-clock-is-a-ceiling-not-a-cadence"
    },
    {
      "kind": "Module",
      "title": "Cyber Control Readiness (4 checks)",
      "url": "https://bestinsuranceresearch.com/tools/cyber-control-readiness"
    }
  ],
  "reliedOnByCount": 2,
  "citation": {
    "text": "Cornell Legal Information Institute, reproducing the Code of Federal Regulations. \"45 CFR 164.404 - Notification to individuals (HIPAA Breach Notification Rule).\" 2013-01-25. https://www.law.cornell.edu/cfr/text/45/164.404 (retrieved 2026-08-31).",
    "viaThisSite": "BestInsurance Research source record cfr-45-164-404-lii, content version 2026.08.31. https://bestinsuranceresearch.com/sources/cfr-45-164-404-lii",
    "note": "Cite the underlying source when you can. Cite this record when you are describing our synthesis or our claim list."
  }
}
