A Practice Note addressing the breach notification requirements for covered entities (including group health plans and health providers) and business associates under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Under implementing regulations, breach notification may need to be provided to individuals, the media, and the Department of Health and Human Services (HHS).