Low Probability of Compromise
Low probability of compromise is the standard used under the HIPAA Breach Notification Rule to determine whether an unauthorized use or disclosure of protected health information (PHI) actually counts as a reportable breach. In general, when PHI is improperly used or disclosed, it is presumed to be a breach unless a covered entity or business associate can demonstrate through a risk assessment that there is a low probability the information was compromised. If that low probability is established, the incident is generally not treated as a breach requiring notification.
Under the HIPAA Breach Notification Rule, an impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment. That assessment generally evaluates factors such as the nature and extent of the PHI involved (including identifiers and likelihood of re-identification), the unauthorized person who used the PHI or to whom the disclosure was made, whether the PHI was actually acquired or viewed, and the extent to which the risk to the PHI has been mitigated. A demonstrated low probability of compromise removes the incident from the definition of a reportable breach, meaning notification obligations generally do not apply. This standard is distinct from the separate regulatory exceptions to the breach definition (for example, certain unintentional acquisitions by workforce members, inadvertent disclosures between authorized persons, and situations where the recipient could not reasonably have retained the PHI). The specific risk-assessment factors, terminology, and any burden-of-proof requirements should be confirmed against the current text of the Breach Notification Rule, and readers should note that state law or other frameworks may impose additional or stricter notification requirements.
Why it matters
The low probability of compromise standard sits at the center of nearly every breach determination a covered entity or business associate must make. Because the HIPAA Breach Notification Rule presumes that an impermissible acquisition, access, use, or disclosure of PHI is a breach, the burden generally falls on the organization to demonstrate, through a documented risk assessment, that there is a low probability the PHI has been compromised. If the organization cannot make that showing, notification obligations to affected individuals, and in many cases to HHS OCR and potentially the media, generally follow. Getting this analysis right determines whether an incident quietly resolves internally or triggers a public, resource-intensive notification process.
The stakes are heightened by the fact that this is a defensible judgment, not an automatic outcome. Regulators and, where applicable, litigants may later scrutinize whether the risk assessment was thorough, reasoned, and properly documented. A conclusory or poorly supported determination that an incident carried a low probability of compromise can expose an organization to enforcement risk if OCR disagrees. Because the standard shifts the analytical burden onto the entity, the quality of the documentation supporting a low probability finding is often as important as the finding itself.
Readers should also recognize the limits of this standard within the broader compliance picture. A low probability of compromise finding addresses only whether an incident is a reportable breach under HIPAA; it does not resolve obligations that may arise under state breach notification laws, the HITECH Act, or other frameworks, several of which may apply stricter thresholds or shorter timelines. The specific risk-assessment factors and any burden-of-proof requirements should be confirmed against the current text of the Breach Notification Rule.
Who it's relevant to
Inside LoPoC
Common questions
Answers to the questions practitioners most commonly ask about LoPoC.