Arizona’s 45-Day Breach Notification Rule: What Medical Practices Need to Know

If your medical practice experiences a data breach, the federal HIPAA Breach Notification Rule gives you 60 days to notify affected patients. That sounds like a reasonable timeline until you find out Arizona doesn’t give you 60 days. Arizona gives you 45.

ARS 18-552, Arizona’s data breach notification law, requires notification within 45 days of discovering a breach. That’s 15 fewer days than the federal standard, and when you’re dealing with a security incident, forensic investigation, legal review, and patient communication, those 15 days matter enormously.

What Triggers the 45-Day Clock

The clock starts when you discover, or reasonably should have discovered, that a breach occurred. Not when the breach happened. When you found out. This means if a breach happened in January but you didn’t have monitoring in place to detect it until March, the clock starts in March, but you may also face questions about why it took so long to detect.

A “breach” under Arizona law means unauthorized acquisition of unencrypted personal information. If the data was encrypted, notification isn’t required. This is one of the strongest arguments for encrypting everything: it’s not just good security practice, it’s a legal shield.

Who You Have to Notify

Affected individuals: Anyone whose personal information was compromised. The notification must include what happened, what information was involved, what you’re doing about it, and how they can protect themselves.

Arizona Attorney General: If more than 1,000 individuals are affected, you must notify the AG. Even for smaller breaches, notification to the AG is recommended.

Credit reporting agencies: If more than 1,000 individuals are affected, you must also notify the major credit reporting agencies.

And remember: HIPAA has its own notification requirements on top of this. You’re dealing with both state and federal obligations simultaneously.

Why 45 Days Is Tighter Than It Sounds

Here’s what typically happens after a breach:

Days 1-5: Contain the breach and begin forensic investigation. Figure out what happened and stop it from continuing.

Days 5-15: Determine scope. Which systems were affected? Which patient records? How many people?

Days 15-25: Legal review. Draft notification letters. Coordinate with your attorney, your IT provider, and potentially law enforcement.

Days 25-35: Prepare and send notifications. Set up a response hotline. File regulatory reports.

Days 35-45: Buffer. Except there is no buffer. You’re already at the deadline.

With a 60-day window, you have breathing room. With 45 days, every step has to happen on schedule or you risk missing the deadline, which brings its own penalties.

What Arizona Medical Practices Should Do Now

1. Encrypt everything. If breached data is encrypted, Arizona’s notification requirement doesn’t apply. BitLocker on every device. Encrypted email for patient communications. Encrypted backups. This is the single most impactful step.

2. Have monitoring in place. You can’t start the clock on notification if you never detect the breach. Endpoint detection, audit logging, and 24/7 monitoring mean you find out fast instead of months later.

3. Document your incident response plan. Who does what? Who calls the attorney? Who contacts patients? Who files with the AG? Write it down before you need it.

4. Get a current security risk assessment. OCR cites missing risk analyses in 65% of enforcement cases. A current SRA identifies your vulnerabilities before attackers do.

5. Work with an IT provider who understands Arizona law. National providers may not know about the 45-day rule. Your IT partner needs to understand both HIPAA and ARS 18-552.

The Cost of Getting It Wrong

Beyond the regulatory penalties, a mishandled breach destroys patient trust. Medical practices live on referrals and reputation. Patients who learn their data was exposed, and that you were slow to tell them, don’t come back. And they tell their friends.

OCR continues to ramp up enforcement. In April 2026, they settled $1.16 million across four entities, every one cited for failing to conduct proper risk analyses. The enforcement environment is real and getting more aggressive.

The Bottom Line

Arizona’s 45-day breach notification rule means your practice needs to be prepared before an incident happens. Encryption, monitoring, and a documented response plan aren’t optional. They’re the difference between a manageable incident and a practice-threatening crisis.

Asteroid IT works with Arizona medical practices to build the security controls that prevent breaches and the response plans that handle them when prevention isn’t enough.

Call 480-937-7021 or schedule a free HIPAA consultation.

Scroll to Top