Skip to main content
Category: Breach Notification

Four-Factor Risk Assessment

Also known as: Four-Factor Breach Risk Assessment, HIPAA Four Factor Risk Assessment, Breach Risk Assessment
Simply put

The four-factor risk assessment is a documented evaluation that a covered entity or business associate performs after an impermissible use or disclosure of protected health information to determine whether it must notify affected individuals of a breach. Under the HIPAA Breach Notification Rule, such an incident is generally presumed to be a reportable breach unless this assessment demonstrates a low probability that the information was compromised. Reviewing the four factors helps organizations decide whether breach notification is required.

Formal definition

The four-factor risk assessment is the analysis prescribed by the HIPAA Breach Notification Rule for evaluating an impermissible acquisition, access, use, or disclosure of unsecured protected health information (PHI). The rule generally establishes a presumption of breach unless the covered entity or business associate demonstrates, through a risk assessment of at least the enumerated factors, a low probability that the PHI has been compromised. The factors assessed typically include: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the unauthorized person who used the PHI or to whom the disclosure was made; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated. Practitioners commonly rate each factor (for example, as low, medium, or high risk) and evaluate them together to reach an overall risk determination, documenting the analysis and the resulting notification decision. This assessment addresses only the breach-notification determination under HIPAA and is distinct from the enterprise-wide security risk analysis required by the Security Rule; state breach-notification laws and the HITECH Act may impose additional or differing requirements. Readers should verify the specific regulatory factors and any exceptions against the current text of the Breach Notification Rule.

Why it matters

The four-factor risk assessment sits at the heart of how covered entities and business associates decide whether an impermissible use or disclosure of protected health information triggers breach notification obligations. Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is generally presumed to be a reportable breach. That presumption is significant: without a documented assessment demonstrating a low probability that the PHI was compromised, an organization is expected to proceed as though notification is required. The four-factor analysis is the mechanism the rule provides for rebutting that presumption.

Because the assessment governs a notification decision that can affect individuals, HHS OCR reporting, and in some cases media notice, the quality and documentation of the analysis matter as much as the conclusion. Regulators and auditors generally expect to see that an organization actually considered each enumerated factor and reached a defensible determination, rather than simply asserting that no breach occurred. Documentation forms, such as those distributed by hospital associations, exist precisely to help providers record their consideration of the required factors and their resulting decision.

It is important to keep this assessment in its proper scope. The four-factor risk assessment addresses only the breach-notification determination under HIPAA and is distinct from the enterprise-wide security risk analysis required by the Security Rule. In addition, state breach-notification laws and the HITECH Act may impose additional or differing requirements, and organizations should not assume that satisfying the HIPAA four-factor analysis resolves every applicable obligation.

Who it's relevant to

Privacy and Compliance Officers
Privacy and compliance officers typically own the breach-determination process and are responsible for ensuring that a four-factor assessment is performed and documented after each impermissible use or disclosure. They must be able to defend the conclusion, whether or not notification was required, to HHS OCR and internal leadership, which makes consistent, well-documented analysis essential.
Business Associates and Subcontractors
Business associates, and by extension their subcontractors, may be obligated to perform or contribute to the four-factor assessment when they experience an impermissible use or disclosure. Their specific responsibilities generally flow through the business associate agreement, so they should confirm whether they are expected to conduct the assessment themselves or report the incident to the covered entity for evaluation.
Legal and Risk Management Teams
Legal counsel and risk managers help evaluate the individual factors, particularly re-identification likelihood and mitigation, and assess how state breach-notification laws or the HITECH Act may add requirements beyond the HIPAA analysis. They also weigh the litigation and regulatory implications of the notification decision.
Auditors and Assessors
Auditors reviewing an organization's breach-response program generally look for evidence that four-factor assessments were conducted and documented for relevant incidents. They evaluate whether the organization applied the required factors and reached defensible conclusions, rather than treating the presumption of breach as automatically rebutted.

Inside Four-Factor Risk Assessment

Nature and Extent of the PHI Involved
An assessment of the types of identifiers and the likelihood that the PHI could be used to identify an individual, as well as the sensitivity of the information (for example, financial data, clinical diagnoses, or other especially sensitive categories). This is the first of the four factors used to evaluate the probability that PHI has been compromised.
The Unauthorized Person Who Used or Received the PHI
An evaluation of who accessed or received the information, including whether that person or entity is itself obligated to protect PHI (such as another covered entity or business associate) or whether they have independent obligations to safeguard the data. The identity and obligations of the recipient bear on the risk that the information will be further used or disclosed.
Whether the PHI Was Actually Acquired or Viewed
An analysis of whether the PHI was actually accessed, acquired, or viewed, as opposed to merely being exposed to the possibility of access. Forensic evidence or other investigation may support a conclusion that the information was not in fact viewed.
The Extent to Which Risk Has Been Mitigated
Consideration of steps taken to reduce risk after the impermissible use or disclosure, such as obtaining satisfactory assurances (for example, a confidentiality agreement or confirmed destruction) that the recipient will not further use or disclose the information.
Purpose and Regulatory Context
The four-factor assessment is the analysis generally used under the HIPAA Breach Notification Rule to determine whether an impermissible use or disclosure of unsecured PHI constitutes a reportable breach. It rests on a presumption that an impermissible use or disclosure is a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised. Readers should verify the specific standard and its wording against the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Four-Factor Risk Assessment.

Does the four-factor risk assessment tell you whether a breach occurred?
No. The four-factor risk assessment does not determine whether an impermissible use or disclosure of PHI took place; that is a threshold question answered separately. Instead, the assessment applies after an impermissible use or disclosure has been identified, to evaluate the probability that the PHI has been compromised. Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of PHI is generally presumed to be a reportable breach unless the covered entity or business associate demonstrates, through this risk assessment, a low probability that the PHI was compromised (or unless an exception applies). The assessment is a mechanism for rebutting that presumption, not for deciding whether an incident happened in the first place.
Is a low probability of harm the same as the low probability of compromise standard used in the four factors?
No, and this is a common point of confusion. Earlier guidance framed the analysis around a risk of harm to the individual, but the four-factor assessment under the current Breach Notification Rule focuses on the probability that the PHI has been compromised rather than on harm alone. The four factors direct you to consider the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. Harm to the individual is one consideration embedded in that broader analysis, not the sole or controlling test. Readers should confirm the exact standard against the current regulatory text.
What are the four factors we are required to evaluate?
The four factors generally are: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the unauthorized person who used the PHI or to whom the disclosure was made; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated. Each factor should be evaluated and documented, and the analysis should consider the factors in combination to reach an overall conclusion about the probability of compromise. Confirm the precise wording against the current Breach Notification Rule.
How should we document the assessment?
Documentation should generally capture the facts of the incident, the analysis of each of the four factors, any exceptions considered, and the reasoned conclusion about the probability that the PHI was compromised. Because the impermissible use or disclosure is presumed reportable unless a low probability of compromise is demonstrated, the burden is typically on the covered entity or business associate to show that its determination was reasonable. Contemporaneous, factor-by-factor written records are advisable so the basis for any decision not to notify can be defended if reviewed by HHS OCR. Retention practices should align with applicable recordkeeping requirements, which readers should verify against current guidance.
Who is responsible for performing the assessment when a business associate is involved?
Responsibilities typically depend on the business associate agreement and the circumstances of the incident. A business associate that experiences an impermissible use or disclosure generally must report it to the covered entity, and either party may conduct the four-factor risk assessment depending on how the agreement allocates that duty. Regardless of who performs the analysis, the covered entity generally retains ultimate accountability for breach notification obligations to affected individuals, HHS, and, where applicable, the media. Parties should clarify these roles in the business associate agreement and coordinate closely, since the covered entity relies on the business associate's factual information to complete the assessment.
What happens if the assessment concludes there is more than a low probability of compromise?
If the four-factor assessment does not demonstrate a low probability that the PHI was compromised, the incident is generally treated as a reportable breach, and the applicable notification obligations under the Breach Notification Rule are triggered. These typically include notification to affected individuals and to HHS OCR, with additional media notification in certain larger incidents, all subject to timing requirements set out in the rule. The specific thresholds, deadlines, and notification methods should be confirmed against the current regulation. Note that state breach notification laws and other frameworks may impose additional or stricter requirements beyond HIPAA.

Common misconceptions

If PHI was impermissibly disclosed, breach notification is automatically required.
Under the Breach Notification Rule, an impermissible use or disclosure is presumed to be a breach, but notification is generally not required if the entity demonstrates, through the four-factor assessment, a low probability that the PHI has been compromised. The assessment is what determines whether the presumption is overcome. Certain exceptions defined in the rule may also apply. Confirm the current standard against the applicable regulatory text.
The four-factor assessment lets an organization decide subjectively whether a breach is 'serious enough' to report.
The four factors are a structured framework focused on the probability that PHI has been compromised, not on the perceived severity or harm to the individual. The prior harm-based standard is different from the compromise-based four-factor approach. The evaluation should be documented, evidence-based, and defensible rather than a subjective judgment about seriousness.
Completing a four-factor assessment guarantees the organization is protected from HHS OCR enforcement.
A thorough, documented assessment supports a reasonable determination but does not by itself guarantee any outcome. HHS OCR may review the analysis, and state laws or the HITECH Act may impose additional or stricter notification requirements. No single measure guarantees compliance or eliminates enforcement risk.

Best practices

Begin from the regulatory presumption that an impermissible use or disclosure is a breach, and treat the four-factor assessment as the mechanism for demonstrating a low probability of compromise rather than as a way to justify not reporting.
Document each of the four factors in writing with the supporting evidence relied upon, so the analysis is defensible if reviewed by HHS OCR.
Involve the privacy officer, security officer, and legal counsel as appropriate, and use a consistent, repeatable process across incidents to avoid ad hoc or subjective determinations.
Where mitigation is claimed, retain concrete evidence such as confidentiality assurances or confirmed destruction, and note that addressing risk after the fact does not remove the obligation to conduct the full assessment.
Check applicable state breach notification laws and any HITECH Act requirements, since these may impose additional obligations or shorter timelines beyond the federal HIPAA standard.
Verify the specific wording of the standard, the defined exceptions, and any notification deadlines against the current regulatory text, as these should not be assumed from memory.