US Medical BillingRevenue cycle solutions

Breach of unsecured PHI

Under HIPAA, a breach is an acquisition, access, use, or disclosure of unsecured protected health information in a way the Privacy Rule does not permit, which compromises its security or privacy. An impermissible use or disclosure is presumed to be a breach unless a risk assessment shows a low probability that the information was compromised.

Updated

A breach is the acquisition, access, use, or disclosure of protected health information in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of that information (45 CFR 164.402). It is the event that can trigger the Breach Notification Rule's duty to notify the people affected, HHS, and sometimes the media.

The rule reaches only unsecured PHI — information that has not been rendered unusable, unreadable, or indecipherable to unauthorized people through encryption or destruction by a method the Secretary of HHS has specified. PHI that has been secured that way is outside the notification duty even if it is lost or stolen.

In practice

An impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates, through a documented risk assessment, a low probability that the PHI was compromised (45 CFR 164.402(2)). That assessment weighs at least four factors: the nature and extent of the PHI involved, who received or accessed it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated.

The definition carves out three narrow exceptions — a good-faith, within-authority access by a workforce member with no further impermissible use; an inadvertent disclosure between two people authorized at the same entity; and a disclosure the entity has a good-faith belief the recipient could not reasonably have retained.

Commonly confused with

Sources

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.