Skip to main content
Category: Breach Notification

Breach

Also known as: Breach of Unsecured PHI, HIPAA Breach
Simply put

Under HIPAA, a breach generally refers to an unauthorized access, use, or disclosure of protected health information (PHI) that compromises its security or privacy. When such an event occurs, the HIPAA Breach Notification Rule may require covered entities and business associates to notify affected individuals, HHS, and in some cases the media. Not every impermissible use or disclosure automatically counts as a reportable breach, because specific regulatory criteria and exceptions apply.

Formal definition

The evidence packet provided does not contain the operative HIPAA regulatory definition of 'breach' and therefore cannot substantiate a precise, citation-supported technical definition. In general HIPAA terms, 'breach' is a defined term under the Breach Notification Rule, addressing the unauthorized acquisition, access, use, or disclosure of unsecured protected health information (PHI) in a manner not permitted by the Privacy Rule, subject to enumerated exceptions and a risk-assessment standard for determining whether notification obligations are triggered. The applicable definition, exceptions, and the multi-factor risk assessment used to rebut the presumption of a breach are set out in the HIPAA Breach Notification Rule regulatory text; practitioners must verify the exact wording, factors, and any thresholds against the current Code of Federal Regulations and HHS OCR guidance, as none of these details could be confirmed from the sources supplied. Note that 'breach' in this HIPAA context differs from the generic legal meaning (a violation of law or of a contractual obligation) and from unrelated common uses of the word; state breach-notification laws and the HITECH Act may impose additional or stricter requirements beyond HIPAA.

Why it matters

Under HIPAA, the determination that an event constitutes a reportable breach is often the trigger that sets legally significant obligations in motion. When an impermissible access, use, or disclosure of unsecured PHI qualifies as a breach, the Breach Notification Rule may require covered entities and business associates to notify affected individuals, HHS, and in certain circumstances the media. Getting this determination wrong in either direction carries consequences: failing to recognize and report a reportable breach can expose an organization to enforcement action by HHS OCR, while over-reporting can create unnecessary reputational and operational burdens.

Because not every impermissible use or disclosure automatically counts as a reportable breach, the concept sits at the center of a fact-specific analysis. The Breach Notification Rule generally applies a risk-assessment standard and enumerated exceptions to decide whether notification duties are triggered, so compliance teams must document their reasoning carefully. The operative definition, exceptions, and risk-assessment factors are set out in the HIPAA Breach Notification Rule regulatory text and HHS OCR guidance, which readers should consult directly rather than relying on the general description here.

The HIPAA meaning of breach also differs from the generic legal meaning of the word, which refers broadly to a violation of law or of a contractual obligation. Practitioners should not treat every security incident, contract violation, or policy lapse as a HIPAA breach, nor assume that a HIPAA breach is limited to those events. State breach-notification laws and the HITECH Act may impose additional or stricter requirements beyond HIPAA, so a single incident may need to be evaluated under multiple frameworks.

Who it's relevant to

Privacy and Security Officers
These professionals typically lead the evaluation of whether an incident meets the HIPAA definition of a breach, coordinate the risk assessment, and document the basis for any notification decision. They must work from the operative regulatory text rather than the generic meaning of the word.
Covered Entities
Covered entities generally bear primary responsibility for notifying affected individuals, HHS, and in some cases the media when a reportable breach of unsecured PHI occurs. They should confirm current notification requirements and timelines against the Breach Notification Rule and HHS OCR guidance.
Business Associates and Subcontractors
Business associates that experience an impermissible use or disclosure of PHI generally must notify the covered entity, with specific obligations flowing through the business associate agreement. Subcontractors may have parallel duties toward the business associate that engaged them.
Compliance and Legal Counsel
Counsel and compliance teams advise on whether an event triggers HIPAA notification duties, how enumerated exceptions apply, and whether state breach-notification laws or the HITECH Act impose additional or stricter requirements. They should distinguish the HIPAA meaning of breach from its generic legal sense.
Auditors and Assessors
Auditors reviewing breach-response programs generally examine whether an organization has documented its risk assessments and notification decisions consistent with the current Breach Notification Rule. Note that frameworks such as the HITRUST CSF may address breach handling but do not by themselves establish HIPAA compliance.

Inside Breach

Regulatory Definition of Breach
Under the HIPAA Breach Notification Rule, a breach is generally defined at 45 C.F.R. § 164.402 as the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. Readers should confirm the exact operative language against the current text of the regulation.
Presumption of Breach
An impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, typically based on a risk assessment addressing factors such as the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.
Regulatory Exceptions
The definition generally excludes certain events, such as unintentional acquisition, access, or use by a workforce member acting in good faith and within scope of authority, certain inadvertent disclosures between authorized persons at the same entity, and disclosures where the entity has a good-faith belief the unauthorized recipient could not reasonably have retained the information. The precise exception language should be verified against 45 C.F.R. § 164.402.
Scope of Information Covered
A breach under this rule involves PHI. Note that breach notification obligations under the Breach Notification Rule apply to unsecured PHI (PHI not rendered unusable, unreadable, or indecipherable through methods such as encryption or destruction consistent with HHS guidance). PHI secured in accordance with that guidance generally does not trigger the same notification duties.
Notification Obligations Triggered
When a breach of unsecured PHI is determined, affected parties are generally required to be notified. Covered entities typically must notify affected individuals, HHS OCR, and in certain cases the media, while business associates generally must notify the covered entity. Specific timing, thresholds, and content requirements should be confirmed against current HHS guidance and regulatory text.
Distinction From Common Usage
In common usage, 'breach' may refer broadly to any security incident or unauthorized access. Under HIPAA, 'breach' has a narrower, specific regulatory meaning that turns on impermissible use or disclosure of PHI and the compromise standard; not every security incident meets this definition. State law and the HITECH Act may impose additional or differing notification requirements beyond HIPAA.

Common questions

Answers to the questions practitioners most commonly ask about Breach.

Does every impermissible use or disclosure of PHI automatically count as a reportable breach?
No. Under the HIPAA Breach Notification Rule (generally at 45 C.F.R. § 164.402), an acquisition, access, use, or disclosure of protected health information in a manner not permitted by the Privacy Rule is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment. The rule also sets out specific exceptions. So an impermissible use or disclosure creates a presumption that must be evaluated, not an automatic reporting obligation. Confirm the current regulatory text, as definitions and exceptions may be updated over time.
Is a breach the same thing in HIPAA as the general legal or security meaning of the word?
Not exactly. In common and technical usage, breach often refers broadly to any security incident or unauthorized access to data. Under HIPAA, breach has a specific regulatory meaning tied to unsecured protected health information and the Privacy Rule, and it carries defined exceptions and a risk-assessment standard before notification duties are triggered. Because the HIPAA definition differs from everyday usage, readers should rely on the operative definition at 45 C.F.R. § 164.402 (verified against the current regulation) rather than a generic definition when determining compliance obligations.
What factors should a risk assessment consider when evaluating whether a breach occurred?
The Breach Notification Rule generally directs covered entities and business associates to assess at least the nature and extent of the PHI involved (including types of identifiers and likelihood of re-identification), the unauthorized person who used the PHI or to whom the disclosure was made, whether the PHI was actually acquired or viewed, and the extent to which the risk to the PHI has been mitigated. These factors are used to determine whether there is a low probability that the PHI has been compromised. Document the assessment and verify the current factors against the applicable regulatory text.
Are there situations that are excepted from the definition of breach?
Yes. The rule generally provides exceptions, such as certain unintentional acquisition, access, or use of PHI by a workforce member acting in good faith within the scope of authority, certain inadvertent disclosures between authorized persons at the same covered entity or business associate, and situations where there is a good-faith belief the unauthorized recipient could not reasonably have retained the information. Whether an exception applies is fact-specific and should be documented. Confirm the exact exceptions against the current regulation.
How does the concept of 'unsecured PHI' affect whether notification is required?
Notification obligations under the Breach Notification Rule generally apply to breaches of unsecured protected health information, meaning PHI that is not rendered unusable, unreadable, or indecipherable through methods specified in HHS guidance (such as certain encryption or destruction approaches). PHI secured consistent with that guidance may fall outside the notification requirements even if impermissibly accessed. Because the specifics depend on current HHS guidance, verify the applicable safe-harbor methods against the latest official guidance.
How do breach obligations differ between covered entities and business associates?
In general, a business associate that discovers a breach must notify the covered entity, and the covered entity is typically responsible for notifying affected individuals, HHS OCR, and, where applicable, the media, according to the timeframes and thresholds in the rule. The precise allocation of notification duties is often addressed in the business associate agreement, though the agreement cannot override the regulatory floor. Verify timing, thresholds, and contractual allocations against the current regulation and your specific agreements, and note that state law or the HITECH Act may impose additional requirements.

Common misconceptions

Any unauthorized access to a system containing PHI is automatically a reportable breach.
An impermissible use or disclosure of PHI is generally presumed to be a breach, but that presumption can be overcome by demonstrating a low probability of compromise through the required risk assessment. In addition, certain regulatory exceptions may apply, and PHI that was appropriately secured (for example, encrypted consistent with HHS guidance) generally does not trigger breach notification. Whether an event is a reportable breach depends on this analysis, not merely on the occurrence of unauthorized access.
Breach notification is solely the responsibility of the covered entity.
Business associates also have obligations. In most cases a business associate that discovers a breach must notify the covered entity, and the specifics of that notification are typically addressed in the business associate agreement. The covered entity generally remains responsible for notifying affected individuals, HHS OCR, and the media where applicable, but obligations flow to business associates and subcontractors through defined relationships and agreements.
HITRUST CSF certification means an organization is protected from HIPAA breach notification obligations.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance or exempt an entity from the Breach Notification Rule. If a breach of unsecured PHI occurs, HIPAA notification duties enforced by HHS OCR apply regardless of certification status.

Best practices

Establish a documented breach risk assessment process that evaluates each impermissible use or disclosure against the factors in 45 C.F.R. § 164.402, and retain the analysis to support any determination that notification was or was not required.
Implement and document methods to render PHI unusable, unreadable, or indecipherable (such as encryption or secure destruction) consistent with current HHS guidance, so that qualifying secured PHI generally falls outside breach notification triggers.
Define breach discovery, reporting timelines, and responsibilities in business associate agreements so that business associates and subcontractors know when and how to notify the covered entity.
Verify current notification timing, thresholds, and content requirements against the latest HHS OCR guidance and regulatory text before responding to any incident, since specific figures and deadlines are adjusted over time.
Check applicable state breach notification laws and HITECH Act requirements, which may impose additional or stricter obligations beyond HIPAA.
Train workforce members to recognize potential impermissible uses or disclosures and to report them promptly, and document the good-faith conditions relevant to the regulatory exceptions where they may apply.