Impermissible Use or Disclosure
An impermissible use or disclosure is any handling or sharing of protected health information (PHI) that is not allowed under the HIPAA Privacy Rule. When such an event happens, it is generally treated as a potential breach that must be investigated. In most cases, it is presumed to be a reportable breach unless the covered entity or business associate can show there is a low probability that the information was actually compromised.
Under the HIPAA Privacy Rule, an impermissible use or disclosure is a use or disclosure of PHI that is not permitted or required by the Rule. It is the threshold concept for the Breach Notification Rule: a breach is generally defined as an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the PHI. Following such an event, an impermissible use or disclosure is presumed to be a breach requiring notification unless the covered entity or business associate demonstrates, typically through a risk assessment, that there is a low probability that the PHI has been compromised. Note that this term applies to PHI in the context of Privacy Rule permissions and should be distinguished from the Security Rule's focus specifically on electronic PHI; readers should verify the specific breach analysis factors and any exceptions against the current regulatory text, and be aware that state law or the HITECH Act may impose additional notification obligations. Specific penalty tiers and thresholds are set and enforced by HHS OCR and should be confirmed against current guidance.
Why it matters
The concept of impermissible use or disclosure sits at the heart of the HIPAA Breach Notification Rule because it functions as the threshold that triggers a compliance analysis. Under the Privacy Rule, any use or sharing of PHI that is not permitted or required is impermissible, and once such an event occurs, it is generally presumed to be a reportable breach. This presumption shifts the burden onto the covered entity or business associate: rather than assuming an incident is harmless, the organization must affirmatively demonstrate, typically through a documented risk assessment, that there is a low probability the PHI was compromised. Getting this analysis wrong can mean either failing to notify when required or over-notifying unnecessarily.
Because the presumption favors treating impermissible events as breaches, organizations that lack a disciplined intake and assessment process may miss notification deadlines or fail to preserve the documentation needed to defend a "low probability" determination. This matters not only for regulatory exposure with HHS OCR but also for maintaining patient trust and meeting any additional obligations that may arise under the HITECH Act or state breach notification laws, which can be more stringent than the federal baseline.
It is important to distinguish the Privacy Rule context of this term from the Security Rule, which focuses specifically on electronic PHI. An impermissible use or disclosure can involve PHI in any form, including oral and paper. Readers should verify the specific breach analysis factors, exceptions, and any applicable penalty tiers against current regulatory text and HHS OCR guidance, as these are set and adjusted by the enforcing authority over time.
Who it's relevant to
Inside Impermissible Use or Disclosure
Common questions
Answers to the questions practitioners most commonly ask about Impermissible Use or Disclosure.