Defining a Breach
Under HIPAA, a breach is the acquisition, access, use, or disclosure of unsecured protected health information in a manner not permitted by the Privacy Rule, which compromises the security or privacy of the information. Not every impermissible disclosure constitutes a reportable breach; certain limited exceptions exist, such as unintentional access by an employee acting in good faith within the scope of authority, provided the information is not further used or disclosed impermissibly.
Risk Assessment
When a potential breach occurs, the covered entity must perform a documented risk assessment to determine the probability that the protected health information was compromised, unless a recognized exception applies. The risk assessment must consider at least four factors specified in the Breach Notification Rule.
Required Risk Assessment Factors
- The nature and extent of the protected health information involved, including types of identifiers and likelihood of re-identification
- The unauthorized person who used the information or to whom the disclosure was made
- Whether the information was actually acquired or viewed
- The extent to which the risk to the information has been mitigated
Notification Timelines
If the risk assessment concludes that a reportable breach occurred, the covered entity must notify affected individuals without unreasonable delay and no later than 60 days following discovery of the breach. Notification to individuals must be made by first-class mail or, if the individual has agreed, by email, and must include a description of the breach, the types of information involved, steps individuals should take to protect themselves, and what the covered entity is doing in response.
HHS Reporting Requirements
Breaches affecting 500 or more individuals must be reported to the Secretary of Health and Human Services contemporaneously with individual notification, and HHS publishes these breaches on a public website often referred to as the wall of shame. Breaches affecting fewer than 500 individuals may be reported to HHS on an annual basis, no later than 60 days after the end of the calendar year in which the breach was discovered.
State Notification Laws
Many states impose their own breach notification requirements that may have different triggering thresholds, timelines, or content requirements than HIPAA. When both federal and state law apply, covered entities generally must comply with whichever requirement is more stringent or provides greater protection to affected individuals.
Media Notification
Breaches affecting more than 500 residents of a single state or jurisdiction also require notification to prominent media outlets serving that area, ensuring broader public awareness of significant breaches.