According to HIPAA regulations, covered entities like healthcare providers, health plans, and their business associates must notify the affected individuals, the Department of Health and Human Services (HHS), and in some cases, the media. The specific requirements depend on the size and scope of the breach.