HIPAA mandates that affected individuals must be notified within 60 days of discovering the breach. Notification to the HHS must also occur within this timeframe, although breaches affecting fewer than 500 individuals can be reported annually. If a breach affects more than 500 individuals, the media must be notified as well.