Breach Notification Rule Requirements and Risk Assessment

Defining a Breach

Under the HIPAA Breach Notification Rule, a breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. RHIA candidates should understand that not every impermissible disclosure is automatically a breach; a four factor risk assessment determines whether the low probability of compromise exception applies.

The Four Factor Risk Assessment

  • The nature and extent of the PHI involved, including the types of identifiers and likelihood of re-identification.
  • The unauthorized person who used the PHI or to whom the disclosure was made.
  • Whether the PHI was actually acquired or viewed.
  • The extent to which the risk to the PHI has been mitigated, such as through prompt retrieval of a misdirected fax.

If the assessment demonstrates a low probability that PHI has been compromised, the incident does not require breach notification, but the covered entity must document the analysis.

Notification Timelines

When a breach is confirmed, covered entities must notify affected individuals without unreasonable delay and no later than sixty days after discovery. If the breach affects five hundred or more residents of a state or jurisdiction, the covered entity must also notify prominent media outlets and the Department of Health and Human Services within the same sixty day period. Breaches affecting fewer than five hundred individuals may be reported to HHS annually, though individual notification still follows the sixty day standard.

Business Associate Obligations

Business associates that discover a breach of unsecured PHI must notify the covered entity, generally within sixty days, so the covered entity can meet its own notification obligations. The business associate agreement should specify the exact process and timeline for this internal notification.

Exceptions to the Breach Definition

Certain situations are excluded from the breach definition entirely, including unintentional access by a workforce member acting in good faith within the scope of authority, inadvertent disclosure between authorized persons at the same organization, and situations where the unauthorized person would not reasonably have been able to retain the information.

Exam Tip

Scenario questions often describe an incident and ask whether notification is required. Apply the four factor test methodically rather than assuming any unauthorized disclosure automatically triggers notification, since the low probability exception is a frequently tested nuance.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.