Breach Notification Requirements: Advanced Scenarios

Refreshing the Breach Notification Framework

Under the HIPAA Breach Notification Rule, a breach is an impermissible use or disclosure of protected health information that compromises the security or privacy of that information, unless the covered entity demonstrates a low probability of compromise through a required risk assessment.

The Four-Factor Risk Assessment

When an impermissible disclosure occurs, the covered entity must assess at least four factors: the nature and extent of the PHI involved including the types of identifiers, the unauthorized person who used or received the information, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated.

Advanced Scenario: Misdirected Fax or Email

A common exam scenario involves PHI sent to the wrong recipient. If the recipient is another covered entity bound by HIPAA and confirms destruction without further use, the risk may be assessed as low. If the recipient is an unrelated third party with no obligation to protect the information, the risk of compromise is typically higher.

Advanced Scenario: Lost Unencrypted Device

A lost laptop containing unencrypted ePHI is presumed to be a reportable breach unless the entity can show through its risk assessment that there is a low probability of compromise, which is difficult when the device is unencrypted and unrecovered.

Notification Timing and Content

  • Individual notification is required without unreasonable delay and no later than 60 days after discovery
  • Breaches affecting 500 or more individuals require notification to the Secretary of Health and Human Services within 60 days and often trigger media notification
  • Breaches affecting fewer than 500 individuals can be reported to the Secretary annually
  • Notification letters must include a description of the breach, the types of information involved, steps individuals should take, and what the entity is doing in response

Business Associate Obligations

When a business associate discovers a breach, it must notify the covered entity without unreasonable delay and no later than 60 days, and the covered entity remains ultimately responsible for individual notification unless the business associate agreement states otherwise.

Exam Strategy

  1. Practice applying the four-factor test to fact patterns rather than memorizing definitions alone
  2. Know the exceptions to the breach definition, including unintentional access by workforce members acting in good faith
  3. Track the difference between the 60-day individual notification deadline and the tiered HHS reporting timelines

Key Takeaway

Breach notification questions on the RHIA exam typically require applying the risk assessment factors to a specific fact pattern rather than reciting the rule verbatim.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.