Skip to main content
Category: Breach Notification

Impermissible Use or Disclosure

Also known as: Unauthorized Use or Disclosure, Impermissible Disclosure
Simply put

An impermissible use or disclosure is any handling or sharing of protected health information (PHI) that is not allowed under the HIPAA Privacy Rule. When such an event happens, it is generally treated as a potential breach that must be investigated. In most cases, it is presumed to be a reportable breach unless the covered entity or business associate can show there is a low probability that the information was actually compromised.

Formal definition

Under the HIPAA Privacy Rule, an impermissible use or disclosure is a use or disclosure of PHI that is not permitted or required by the Rule. It is the threshold concept for the Breach Notification Rule: a breach is generally defined as an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the PHI. Following such an event, an impermissible use or disclosure is presumed to be a breach requiring notification unless the covered entity or business associate demonstrates, typically through a risk assessment, that there is a low probability that the PHI has been compromised. Note that this term applies to PHI in the context of Privacy Rule permissions and should be distinguished from the Security Rule's focus specifically on electronic PHI; readers should verify the specific breach analysis factors and any exceptions against the current regulatory text, and be aware that state law or the HITECH Act may impose additional notification obligations. Specific penalty tiers and thresholds are set and enforced by HHS OCR and should be confirmed against current guidance.

Why it matters

The concept of impermissible use or disclosure sits at the heart of the HIPAA Breach Notification Rule because it functions as the threshold that triggers a compliance analysis. Under the Privacy Rule, any use or sharing of PHI that is not permitted or required is impermissible, and once such an event occurs, it is generally presumed to be a reportable breach. This presumption shifts the burden onto the covered entity or business associate: rather than assuming an incident is harmless, the organization must affirmatively demonstrate, typically through a documented risk assessment, that there is a low probability the PHI was compromised. Getting this analysis wrong can mean either failing to notify when required or over-notifying unnecessarily.

Because the presumption favors treating impermissible events as breaches, organizations that lack a disciplined intake and assessment process may miss notification deadlines or fail to preserve the documentation needed to defend a "low probability" determination. This matters not only for regulatory exposure with HHS OCR but also for maintaining patient trust and meeting any additional obligations that may arise under the HITECH Act or state breach notification laws, which can be more stringent than the federal baseline.

It is important to distinguish the Privacy Rule context of this term from the Security Rule, which focuses specifically on electronic PHI. An impermissible use or disclosure can involve PHI in any form, including oral and paper. Readers should verify the specific breach analysis factors, exceptions, and any applicable penalty tiers against current regulatory text and HHS OCR guidance, as these are set and adjusted by the enforcing authority over time.

Who it's relevant to

Privacy Officers
Privacy officers are typically responsible for identifying whether an event constitutes an impermissible use or disclosure under the Privacy Rule and for conducting or overseeing the risk assessment that determines breach status. Because the term applies to PHI in all forms, not just electronic data, privacy officers must evaluate incidents involving oral, paper, and electronic information.
Compliance Officers
Compliance officers must ensure that intake, assessment, and documentation processes are in place so that the organization can defend a low-probability determination or meet notification obligations when required. They should also account for potentially stricter requirements under the HITECH Act or state law, which may exceed the federal HIPAA baseline.
Business Associates and Subcontractors
Business associates and subcontractors that handle PHI on behalf of covered entities may themselves discover impermissible uses or disclosures and can have investigation and notification responsibilities. The specific obligations generally flow through business associate agreements, so these parties should confirm their duties under their contractual arrangements and current regulatory guidance.
Legal and Regulatory Counsel
Counsel advising on breach analysis must map the correct authority for enforcement (HHS OCR for HIPAA) and confirm penalty tiers and notification thresholds against current guidance, since these are adjusted over time. Counsel also evaluates whether state law or the HITECH Act imposes additional notification obligations beyond those under the HIPAA Breach Notification Rule.

Inside Impermissible Use or Disclosure

Definition Under the Privacy Rule
An impermissible use or disclosure is any use or disclosure of protected health information (PHI) that is not permitted or required by the HIPAA Privacy Rule. Because it arises under the Privacy Rule, it applies to PHI in all forms, including oral, paper, and electronic, not only electronic PHI.
Use vs. Disclosure
A 'use' generally refers to the sharing, employment, application, examination, or analysis of PHI within an entity that maintains it, while a 'disclosure' generally refers to the release, transfer, or divulging of PHI outside the entity. Both can be impermissible when they fall outside what the Privacy Rule permits or requires.
Relationship to Breach Notification
Under the Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless the covered entity or business associate demonstrates, typically through a risk assessment, a low probability that the PHI has been compromised. Not every impermissible use or disclosure automatically constitutes a reportable breach.
Who Can Commit One
Both covered entities and business associates (including subcontractors, through their business associate agreements) can be responsible for impermissible uses or disclosures. Obligations flow through defined relationships and agreements rather than attaching to any party that merely touches data.
Common Scenarios
Examples generally include sharing PHI without a required authorization, disclosures exceeding the minimum necessary standard where it applies, misdirected communications, unauthorized internal access, and releases to parties not permitted under the Privacy Rule.
Enforcement Authority
Impermissible uses or disclosures are enforced by HHS OCR under the HIPAA Enforcement Rule. Penalty tiers and figures are adjusted over time and should be confirmed against current guidance; state law and the HITECH Act may impose additional requirements.

Common questions

Answers to the questions practitioners most commonly ask about Impermissible Use or Disclosure.

Does every impermissible use or disclosure automatically count as a reportable breach?
No. An impermissible use or disclosure of PHI is presumed to be a breach under the Breach Notification Rule, but that presumption can be overcome. A covered entity or business associate may determine, through a documented risk assessment, that there is a low probability the PHI has been compromised, in which case breach notification generally is not required. There are also specific regulatory exceptions. The presumption and its rebuttal should be evaluated against the current regulatory text, and any determination should be documented.
Is an impermissible use or disclosure only a concern for electronic PHI?
No. This is a Privacy Rule concept, and the Privacy Rule covers PHI in all forms, including oral, paper, and electronic. An impermissible disclosure can occur through a conversation overheard in a hallway, a misdirected paper fax, or a mailing sent to the wrong recipient, not only through electronic systems. The Security Rule's focus on ePHI is a separate matter; impermissible uses and disclosures are not limited to electronic information.
How do we determine whether a particular use or disclosure was permissible in the first place?
Generally, a use or disclosure is permissible when it is expressly permitted or required by the Privacy Rule, such as for treatment, payment, or health care operations within applicable limits, or when it falls under another recognized permission or a valid authorization. Uses or disclosures that fall outside these permissions are typically impermissible. Organizations should compare the specific activity against the permissions in the current Privacy Rule text, and note that state law or other requirements may impose additional limits.
What should staff do immediately after discovering a suspected impermissible use or disclosure?
In most cases, staff should promptly report the incident through the organization's established privacy incident reporting channel so it can be evaluated. Typical next steps include preserving relevant facts, working to mitigate any harmful effect to the extent practicable, and initiating a risk assessment to determine whether the presumption of breach can be rebutted. Specific procedures should follow the organization's own policies and the current regulatory requirements.
How does the minimum necessary standard relate to impermissible disclosures?
The minimum necessary standard generally requires that uses and disclosures of PHI be limited to the amount reasonably needed for the intended purpose, subject to certain exceptions such as disclosures for treatment. Disclosing more PHI than is reasonably necessary, where the standard applies, can itself render a disclosure impermissible even if the underlying purpose was otherwise permitted. Organizations should review how the minimum necessary requirements apply to their specific activities under the current rule.
What documentation should we maintain regarding impermissible uses or disclosures?
Organizations typically maintain records of the incident, the risk assessment performed, the reasoning supporting any determination about whether notification was required, and any mitigation and notification steps taken. Maintaining this documentation supports accountability and can be important if the matter is reviewed by HHS OCR. Retention periods and specific documentation expectations should be confirmed against the current regulatory requirements and internal policy.

Common misconceptions

Every impermissible use or disclosure is automatically a reportable breach.
An impermissible use or disclosure of unsecured PHI is presumed to be a breach, but the presumption can generally be overcome through a documented risk assessment demonstrating a low probability that the PHI was compromised, or where a regulatory exception applies. The two concepts are related but not identical.
The concept only applies to electronic PHI, like the Security Rule.
Impermissible use or disclosure is a Privacy Rule concept and applies to PHI in all forms, including oral and paper, not only electronic PHI. The Security Rule governs only ePHI and addresses safeguards rather than the permissibility of a use or disclosure.
Achieving HITRUST CSF certification or strong safeguards prevents impermissible uses or disclosures.
HITRUST is a private organization and its CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. Robust safeguards may reduce risk but do not guarantee that no impermissible use or disclosure will occur.

Best practices

Maintain clear policies distinguishing permitted and required uses and disclosures under the Privacy Rule, and train workforce members on when authorization or the minimum necessary standard applies.
When an impermissible use or disclosure is identified, promptly conduct and document a risk assessment to determine whether it rises to the level of a reportable breach under the Breach Notification Rule.
Ensure business associate agreements clearly assign responsibilities for identifying, reporting, and mitigating impermissible uses or disclosures, extending obligations to subcontractors as appropriate.
Log and investigate potential incidents such as misdirected communications and unauthorized internal access, and retain documentation to support any determination about breach status.
Verify current penalty tiers, breach notification timelines, and applicable CFR provisions against the latest HHS OCR guidance, since figures and requirements are adjusted over time.
Assess whether state law or the HITECH Act imposes additional notification or handling requirements beyond the federal HIPAA baseline for a given incident.