Skip to main content
Category: Breach Notification

Low Probability of Compromise

Also known as: LoPoC, Low Probability that PHI Has Been Compromised, Low Probability Standard
Simply put

Low probability of compromise is the standard used under the HIPAA Breach Notification Rule to determine whether an unauthorized use or disclosure of protected health information (PHI) actually counts as a reportable breach. In general, when PHI is improperly used or disclosed, it is presumed to be a breach unless a covered entity or business associate can demonstrate through a risk assessment that there is a low probability the information was compromised. If that low probability is established, the incident is generally not treated as a breach requiring notification.

Formal definition

Under the HIPAA Breach Notification Rule, an impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment. That assessment generally evaluates factors such as the nature and extent of the PHI involved (including identifiers and likelihood of re-identification), the unauthorized person who used the PHI or to whom the disclosure was made, whether the PHI was actually acquired or viewed, and the extent to which the risk to the PHI has been mitigated. A demonstrated low probability of compromise removes the incident from the definition of a reportable breach, meaning notification obligations generally do not apply. This standard is distinct from the separate regulatory exceptions to the breach definition (for example, certain unintentional acquisitions by workforce members, inadvertent disclosures between authorized persons, and situations where the recipient could not reasonably have retained the PHI). The specific risk-assessment factors, terminology, and any burden-of-proof requirements should be confirmed against the current text of the Breach Notification Rule, and readers should note that state law or other frameworks may impose additional or stricter notification requirements.

Why it matters

The low probability of compromise standard sits at the center of nearly every breach determination a covered entity or business associate must make. Because the HIPAA Breach Notification Rule presumes that an impermissible acquisition, access, use, or disclosure of PHI is a breach, the burden generally falls on the organization to demonstrate, through a documented risk assessment, that there is a low probability the PHI has been compromised. If the organization cannot make that showing, notification obligations to affected individuals, and in many cases to HHS OCR and potentially the media, generally follow. Getting this analysis right determines whether an incident quietly resolves internally or triggers a public, resource-intensive notification process.

The stakes are heightened by the fact that this is a defensible judgment, not an automatic outcome. Regulators and, where applicable, litigants may later scrutinize whether the risk assessment was thorough, reasoned, and properly documented. A conclusory or poorly supported determination that an incident carried a low probability of compromise can expose an organization to enforcement risk if OCR disagrees. Because the standard shifts the analytical burden onto the entity, the quality of the documentation supporting a low probability finding is often as important as the finding itself.

Readers should also recognize the limits of this standard within the broader compliance picture. A low probability of compromise finding addresses only whether an incident is a reportable breach under HIPAA; it does not resolve obligations that may arise under state breach notification laws, the HITECH Act, or other frameworks, several of which may apply stricter thresholds or shorter timelines. The specific risk-assessment factors and any burden-of-proof requirements should be confirmed against the current text of the Breach Notification Rule.

Who it's relevant to

Privacy and Compliance Officers
These professionals typically own the breach determination process and are responsible for conducting and documenting the risk assessment that supports a low probability of compromise finding. They must ensure the four-factor analysis is applied consistently, that determinations are defensible, and that supporting documentation is retained in case OCR later reviews the decision.
Business Associates and Subcontractors
Business associates, and their subcontractors where applicable, may be obligated under their business associate agreements and the Breach Notification Rule to assess incidents involving PHI in their control. They should understand that the presumption of breach applies to them as well, and coordinate with covered entities on who performs the risk assessment and how findings are communicated.
Legal and Regulatory Counsel
Counsel advising on incident response should focus on whether the burden of demonstrating low probability of compromise has been met and properly documented, and should evaluate whether separate breach-definition exceptions apply instead. They also need to flag where state breach notification laws, HITECH, or other frameworks may impose stricter or additional notification requirements beyond the HIPAA analysis.
IT and Security Teams
Technical staff often supply the factual findings that feed the risk assessment, such as whether PHI was actually acquired or viewed, what identifiers were involved, and what mitigation was achieved. Their forensic evidence directly influences whether a low probability of compromise can be reasonably demonstrated.

Inside LoPoC

Four-Factor Risk Assessment
Under the Breach Notification Rule, an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment that generally considers at least four factors: (1) the nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification; (2) the unauthorized person who used the PHI or to whom the disclosure was made; (3) whether the PHI was actually acquired or viewed; and (4) the extent to which the risk to the PHI has been mitigated.
Rebuttable Presumption of Breach
An impermissible acquisition, access, use, or disclosure of PHI is presumed to be a breach requiring notification. The 'low probability of compromise' standard is the mechanism by which a covered entity or business associate can overcome that presumption, but the burden of demonstrating a low probability rests on the entity.
Documentation Burden
Because the entity bears the burden of proof, the risk assessment and its conclusion should generally be documented in a manner that could withstand review by HHS OCR. Reaching a low-probability determination typically requires retaining evidence of the analysis rather than relying on an informal judgment.
Relationship to Breach Notification Obligations
If the risk assessment does not support a low probability of compromise, notification obligations under the Breach Notification Rule generally apply, which may include notifying affected individuals, HHS, and in some cases the media. This standard is part of the Breach Notification Rule and is distinct from the Privacy, Security, and Enforcement Rules.
Regulatory Exceptions to Breach
Separate from the risk assessment, certain situations are excluded from the definition of breach by regulation (for example, specific good-faith or inadvertent scenarios described in the rule). These exceptions operate independently of the low-probability-of-compromise analysis and should be evaluated on their own terms against the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about LoPoC.

Does a low probability of compromise mean no breach occurred?
Not exactly. Under the Breach Notification Rule, an impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate demonstrates that there is a low probability that the PHI has been compromised. So the acquisition, access, use, or disclosure still occurred; the low probability determination is what may relieve the notification obligation. It does not mean nothing happened or that the incident need not be documented. You should verify the specific standard and its application against the current regulatory text.
Is a low probability of compromise the same as low risk of harm to the individual?
These are generally distinct concepts. The current standard focuses on the probability that the PHI has been compromised, assessed through a risk assessment of specified factors, rather than the older harm-based approach that some readers may recall. Because the framing and terminology in this area have shifted over time, readers should confirm the operative standard and the exact factors against the current version of the Breach Notification Rule rather than relying on prior formulations.
What factors are typically considered when assessing the probability of compromise?
A risk assessment for this purpose generally considers factors such as the nature and extent of the PHI involved (including types of identifiers and the likelihood of re-identification), the unauthorized person who used the PHI or to whom the disclosure was made, whether the PHI was actually acquired or viewed, and the extent to which the risk to the PHI has been mitigated. These factors should be evaluated together rather than in isolation. Confirm the precise factors and any additional considerations against the current regulation, and note that state law or the HITECH Act may impose further requirements.
How should an organization document a low probability of compromise determination?
In most cases, organizations maintain a written risk assessment that walks through each of the required factors, states the evidence considered, and records the conclusion and its rationale. Because the presumption is that a breach occurred, the burden generally rests on the covered entity or business associate to demonstrate the low probability, so contemporaneous, defensible documentation is important. Retention periods and the sufficiency of documentation should be verified against current guidance and applicable recordkeeping requirements.
Who is responsible for performing the assessment when a business associate is involved?
Responsibility typically depends on the terms of the business associate agreement and the roles of the parties. A business associate generally must notify the covered entity of an incident, and the parties often need to coordinate on who conducts or reviews the risk assessment. The covered entity generally retains ultimate obligations for notification decisions, but the BAA may allocate specific tasks. Review the applicable BAA and confirm obligations against the current regulatory text.
If the assessment does not support a low probability of compromise, what generally follows?
When the risk assessment does not demonstrate a low probability that the PHI has been compromised, the incident is generally treated as a reportable breach, triggering the applicable notification obligations to affected individuals, HHS OCR, and, in certain cases, the media, subject to the thresholds and timelines in the Breach Notification Rule. The specific thresholds, deadlines, and reporting mechanics are adjusted and clarified over time, so they should be confirmed against current OCR guidance, and note that state breach laws may add separate requirements.

Common misconceptions

A low probability of compromise means the same thing as a low risk of actual harm.
The current standard focuses on the probability that PHI has been compromised, assessed through the multi-factor analysis, rather than on a 'significant risk of harm' test that existed under earlier guidance. Practitioners should apply the compromise-focused standard as reflected in the current regulation and verify the applicable text.
If we conclude there was a low probability of compromise, we do not need to keep records of that decision.
The covered entity or business associate carries the burden of demonstrating that notification was not required. A defensible low-probability determination generally depends on retaining documentation of the risk assessment, its factors, and its conclusion.
Encryption or another safeguard automatically eliminates any breach obligation.
While mitigation and factors such as whether data was rendered unreadable can weigh heavily in the assessment, no single measure automatically guarantees a low-probability conclusion. Each incident is generally evaluated against all applicable factors, and readers should confirm how safe-harbor or encryption provisions apply under current guidance.

Best practices

Treat every impermissible use or disclosure of PHI as a presumed breach and document why the presumption is or is not overcome, rather than assuming no notification is needed.
Apply and record all of the risk assessment factors, nature and extent of the PHI, the recipient, whether the data was actually acquired or viewed, and mitigation, for each incident.
Maintain retained documentation of each assessment sufficient to demonstrate the basis for a low-probability determination if reviewed by HHS OCR.
Adopt a consistent, written procedure so that different staff evaluate incidents against the same factors and reach comparable, defensible conclusions.
Separately evaluate whether a regulatory exception to the definition of breach applies before relying solely on the risk assessment.
Confirm state law and HITECH-related obligations, which may impose additional or stricter notification requirements beyond the federal low-probability standard, and verify the specific factors and thresholds against the current regulatory text.