Four-Factor Risk Assessment
The four-factor risk assessment is a documented evaluation that a covered entity or business associate performs after an impermissible use or disclosure of protected health information to determine whether it must notify affected individuals of a breach. Under the HIPAA Breach Notification Rule, such an incident is generally presumed to be a reportable breach unless this assessment demonstrates a low probability that the information was compromised. Reviewing the four factors helps organizations decide whether breach notification is required.
The four-factor risk assessment is the analysis prescribed by the HIPAA Breach Notification Rule for evaluating an impermissible acquisition, access, use, or disclosure of unsecured protected health information (PHI). The rule generally establishes a presumption of breach unless the covered entity or business associate demonstrates, through a risk assessment of at least the enumerated factors, a low probability that the PHI has been compromised. The factors assessed typically include: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the unauthorized person who used the PHI or to whom the disclosure was made; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated. Practitioners commonly rate each factor (for example, as low, medium, or high risk) and evaluate them together to reach an overall risk determination, documenting the analysis and the resulting notification decision. This assessment addresses only the breach-notification determination under HIPAA and is distinct from the enterprise-wide security risk analysis required by the Security Rule; state breach-notification laws and the HITECH Act may impose additional or differing requirements. Readers should verify the specific regulatory factors and any exceptions against the current text of the Breach Notification Rule.
Why it matters
The four-factor risk assessment sits at the heart of how covered entities and business associates decide whether an impermissible use or disclosure of protected health information triggers breach notification obligations. Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is generally presumed to be a reportable breach. That presumption is significant: without a documented assessment demonstrating a low probability that the PHI was compromised, an organization is expected to proceed as though notification is required. The four-factor analysis is the mechanism the rule provides for rebutting that presumption.
Because the assessment governs a notification decision that can affect individuals, HHS OCR reporting, and in some cases media notice, the quality and documentation of the analysis matter as much as the conclusion. Regulators and auditors generally expect to see that an organization actually considered each enumerated factor and reached a defensible determination, rather than simply asserting that no breach occurred. Documentation forms, such as those distributed by hospital associations, exist precisely to help providers record their consideration of the required factors and their resulting decision.
It is important to keep this assessment in its proper scope. The four-factor risk assessment addresses only the breach-notification determination under HIPAA and is distinct from the enterprise-wide security risk analysis required by the Security Rule. In addition, state breach-notification laws and the HITECH Act may impose additional or differing requirements, and organizations should not assume that satisfying the HIPAA four-factor analysis resolves every applicable obligation.
Who it's relevant to
Inside Four-Factor Risk Assessment
Common questions
Answers to the questions practitioners most commonly ask about Four-Factor Risk Assessment.