Soon, when a healthcare organization faces a breach, it’ll need to comply with two different reporting timelines. HIPAA requires covered entities to notify affected individuals, HHS, and in some cases, the media within 60 days of discovering a breach of unsecured protected health information. Sixty days is a ceiling that influences how healthcare compliance teams plan for breach response for more than a decade.

The other timeline is much quicker. Organizations across 16 critical infrastructure sectors, including healthcare, will be required to report cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) under the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) within 72 hours and ransomware payments within 24 hours. The proposed rule has been under review since April 2024, and CISA said it expects to issue a final rule this fall.

 

Triggers for the two clocks

Generally, the 60-day clock begins to run when discovery occurs, which is when the breach is known or reasonably should have been known. According to the regulation, a covered entity has knowledge of a breach if it is “known, or by exercising reasonable diligence would have been known.”

CIRCIA's clock starts earlier and ticks faster. In its coverage of the rulemaking, Paubox said that the reporting obligation begins at the time an organization has reason to believe that an incident occurred, not when an investigation is complete. The proposed rule states that the covered entity must report “within 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred.” An organization has a suspicion that something big has happened, but that trigger does not wait for forensic confirmation, legal sign-off, or a board briefing.

Under HIPAA’s timeline, a health system can spend weeks trying to understand the scope of the incident. CIRCIA does not allow this pace. The same incident can trigger a 72-hour reporting requirement to CISA and a different, more deliberate breach notification process for affected individuals under HIPAA, on different schedules, to different regulators, and under different definitions of when the clock starts. CISA describes the requirement as reporting “no later than 72 hours from the time the entity reasonably believes the incident occurred.”

 

Why the gap is bigger than it looks

The core problem is its detection capability. Most healthcare organizations do not currently know within 72 hours that something has happened. A Frontiers in Digital Health review of hospital cybersecurity gaps, published in PMC, found that "the healthcare industry takes the longest to identify and manage breaches" of any sector studied, averaging 236 days to identify an incident and 93 days to contain it once found.

Research from Paubox shows a similar trend. Its 2026 Healthcare Email Security Report found that healthcare organizations take an average of 308 days to identify and contain a breach, and 41% of the breached organizations analyzed fell into a high-risk category, up from 31% the previous year.

Confidence is not the same as competence. In Paubox’s Healthcare Email Security Maturity Index 2026, every healthcare IT leader surveyed rated their ability to detect breaches in real time as “excellent” or “good.” In that same sample, 58% said their organization had been compromised through email in the past 24 months, with nearly a quarter saying they had been compromised more than once.

 

Practical steps for covered entities and business associates

Waiting for the final rule is not a strategy. The core 72-hour and 24-hour timelines are not expected to change materially, so preparation can start now.

  • Separate the two clocks in your incident response plan.
  • Define "reasonable belief" internally, in writing, ahead of time.
  • Invest in detection before you invest in reporting workflows.
  • Update business associate agreements.
  • Treat vendor and business associate incidents as your own.

 

Where secure communication fits, and where it does not

Faster reporting timelines put pressure on every layer of healthcare’s technical infrastructure, and email is part of that picture. Email is a leading entry point in healthcare breaches, according to Paubox’s 2026 Healthcare Email Security Report. Its analysis of breached organizations found that 74% had no DMARC policy or had it set to monitor-only mode, which logs fraudulent messages rather than blocking them.

Email authentication and encryption controls reduce the likelihood of email being the entry point for an incident, and they can shorten the time a compromised account or intercepted message remains undetected. But encryption alone will not satisfy HIPAA or CIRCIA. Both frameworks require documented processes, risk assessments, criteria for determining breaches, notification workflows, evidence retention, and clear ownership of reporting decisions.

A healthcare organization needs many controls, one of which is email encryption that supports HIPAA compliance, is properly configured, backed by a business associate agreement, and paired with authentication protocols like DMARC, SPF, and MTA-STS. It opens a channel of communication. It is not a breach response workflow or reporting obligation in itself.

For organizations building out both HIPAA breach response and CIRCIA reporting readiness, that distinction is worth making explicit before an incident happens, not during one. As former OCR Director Melanie Fontes Rainer put it in Paubox's 2026 Healthcare Email Security Report, patients need to be able to "trust that sensitive health information in their files is protected." Meeting that expectation takes more than a single tool; it takes detection capability, a documented process, and a clear answer to who decides when the clock starts.

See also: How healthcare organizations can manage email content at scale

 

FAQs

Does every HIPAA covered entities have to comply with CIRCIA?

No, HIPAA and CIRCIA use different definitions of a covered entity. An organization’s status as a HIPAA covered entity or business associate does not automatically make it a CIRCIA covered entity. CIRCIA has unique parameters that determine if an organization is a covered entity, which are outlined here.

 

Can an incident be reportable under CIRCIA but not HIPAA?

Yes, A cyber incident could substantially disrupt healthcare operations or information systems without exposing unsecured patient data.

 

Is every ransomware attack automatically a reportable HIPAA breach?

Not automatically, but HHS states that when ransomware accesses unsecured patient data, a breach is presumed.