Breach
Under HIPAA, a breach generally refers to an unauthorized access, use, or disclosure of protected health information (PHI) that compromises its security or privacy. When such an event occurs, the HIPAA Breach Notification Rule may require covered entities and business associates to notify affected individuals, HHS, and in some cases the media. Not every impermissible use or disclosure automatically counts as a reportable breach, because specific regulatory criteria and exceptions apply.
The evidence packet provided does not contain the operative HIPAA regulatory definition of 'breach' and therefore cannot substantiate a precise, citation-supported technical definition. In general HIPAA terms, 'breach' is a defined term under the Breach Notification Rule, addressing the unauthorized acquisition, access, use, or disclosure of unsecured protected health information (PHI) in a manner not permitted by the Privacy Rule, subject to enumerated exceptions and a risk-assessment standard for determining whether notification obligations are triggered. The applicable definition, exceptions, and the multi-factor risk assessment used to rebut the presumption of a breach are set out in the HIPAA Breach Notification Rule regulatory text; practitioners must verify the exact wording, factors, and any thresholds against the current Code of Federal Regulations and HHS OCR guidance, as none of these details could be confirmed from the sources supplied. Note that 'breach' in this HIPAA context differs from the generic legal meaning (a violation of law or of a contractual obligation) and from unrelated common uses of the word; state breach-notification laws and the HITECH Act may impose additional or stricter requirements beyond HIPAA.
Why it matters
Under HIPAA, the determination that an event constitutes a reportable breach is often the trigger that sets legally significant obligations in motion. When an impermissible access, use, or disclosure of unsecured PHI qualifies as a breach, the Breach Notification Rule may require covered entities and business associates to notify affected individuals, HHS, and in certain circumstances the media. Getting this determination wrong in either direction carries consequences: failing to recognize and report a reportable breach can expose an organization to enforcement action by HHS OCR, while over-reporting can create unnecessary reputational and operational burdens.
Because not every impermissible use or disclosure automatically counts as a reportable breach, the concept sits at the center of a fact-specific analysis. The Breach Notification Rule generally applies a risk-assessment standard and enumerated exceptions to decide whether notification duties are triggered, so compliance teams must document their reasoning carefully. The operative definition, exceptions, and risk-assessment factors are set out in the HIPAA Breach Notification Rule regulatory text and HHS OCR guidance, which readers should consult directly rather than relying on the general description here.
The HIPAA meaning of breach also differs from the generic legal meaning of the word, which refers broadly to a violation of law or of a contractual obligation. Practitioners should not treat every security incident, contract violation, or policy lapse as a HIPAA breach, nor assume that a HIPAA breach is limited to those events. State breach-notification laws and the HITECH Act may impose additional or stricter requirements beyond HIPAA, so a single incident may need to be evaluated under multiple frameworks.
Who it's relevant to
Inside Breach
Common questions
Answers to the questions practitioners most commonly ask about Breach.