What is Breach, and what should an ABA practice owner know before applying it? A breach is rule-defined, not every privacy or security incident. Under HIPAA, an impermissible acquisition, access, use, or disclosure of protected health information is presumed a breach unless an exception applies or the covered entity or business associate shows low probability of compromise. Required HIPAA notices apply only to a breach of unsecured PHI.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
An incident and a breach are different states
Under the HIPAA Security Rule, a security incident means attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, or interference with system operations. It does not necessarily become a breach. “Privacy incident” is an operating label, not a conclusion under the Breach Notification Rule. Wrong recipients, inappropriate access, lost paper, and unexpected vendor uses still need classification under governing rules.
HIPAA uses a defined classification sequence
The HHS Breach Notification Rule page explains the HIPAA path for covered entities and business associates. Start with these questions.
- Is the organization acting as a HIPAA covered entity or business associate for this information and activity?
- Is PHI involved, and was its acquisition, access, use, or disclosure impermissible under the Privacy Rule?
- Does one of the three regulatory exceptions apply?
- If no exception applies, will the entity notify, or can it demonstrate a low probability that the PHI was compromised through the required risk assessment?
- If the event is a breach, is the PHI unsecured, making the rule's notification duties applicable?
The three narrow exceptions cover: certain unintentional, good-faith, within-authority acquisition, access, or use with no further impermissible use or disclosure; certain inadvertent disclosures between authorized people at the same covered entity, business associate, or organized health care arrangement, again without further impermissible use or disclosure; and a disclosure when the entity has a good-faith belief that the unauthorized recipient could not reasonably retain the PHI.
Without an exception, the impermissible event is presumed a breach. The assessment covers at least the PHI's nature and extent, the unauthorized person, actual acquisition or viewing, and mitigation. A covered entity or business associate may notify without assessing, but bears the burden of documenting required notices or why the event was not a breach. Current 45 CFR Part 164 Subpart D contains these rules.
Unsecured PHI has not been rendered unusable, unreadable, or indecipherable to unauthorized people through an HHS-specified method. HHS guidance identifies qualifying encryption and destruction. A confidential process or key that could decrypt the data must remain uncompromised.
Discovery starts response clocks
Under HIPAA, discovery is the first day the entity knows of the breach or, through reasonable diligence, would have known. Knowledge is imputed from a covered entity workforce member or agent other than the person committing the breach; a comparable employee, officer, or agent rule applies to a business associate. The clock does not await privacy-office escalation or final classification. Record the earliest event, detection, report, escalation, classification, and notice dates.
- Affected individuals: The covered entity gives notice without unreasonable delay and no later than 60 calendar days after discovery.
- Covered entity: A business associate gives notice on the same federal timetable after its discovery, identifies each affected or reasonably believed affected individual to the extent possible, and supplies other available individual-notice information then or promptly as it becomes available. The covered entity remains ultimately responsible for individual notice, although it may delegate delivery.
- Media: If a breach affects more than 500 residents of a state or jurisdiction, the covered entity notifies prominent media serving that area without unreasonable delay and no later than 60 calendar days after discovery.
- HHS Secretary: For 500 or more affected individuals, the covered entity reports contemporaneously with individual notice and, under current HHS reporting instructions, without unreasonable delay and no later than 60 calendar days after discovery. For fewer than 500, it logs the breach and reports within 60 days after the end of the calendar year of discovery; earlier reporting is allowed.
These are federal baselines; 60 days is an outer limit. HHS's business associate agreement guidance notes that parties may set stricter business-associate reporting terms. Counsel should determine which state privacy, consumer-health, medical-record, insurance, licensing, payer, and contract duties run in parallel and whether they set different triggers, content, recipients, or clocks. HIPAA delay is limited to specified law-enforcement conditions. Track each source and recipient separately.
HIPAA and the FTC rule cover different entities
The current FTC Health Breach Notification Rule, 16 CFR Part 318, covers qualifying vendors of personal health records, PHR-related entities, and third-party service providers. It excludes HIPAA covered entities and other entities to the extent they act as business associates. It covers unauthorized acquisition of unsecured PHR-identifiable health information, including unauthorized business disclosures, and presumes unauthorized access is acquisition absent reliable contrary evidence.
A business associate for one service may separately operate a consumer-controlled product under the FTC rule. Map each entity, role, product, and data flow with counsel.
Build an incident and notice register
For each event, preserve:
- facts, systems, time zones, discovery timeline, reporters, and source evidence.
- people, data, copies, recipients, access, acquisition, retention, and working count.
- entity, role, rule, exception, assessment, decision authority, and revision history.
- containment, mitigation, and each notice's source, recipient, owner, due date, sent date, and proof.
- corrective action, validation, communication, escalation, and closure.
Limit access to the investigation. Preserve original messages, logs, files, and versions. Coordinate containment with evidence needs, and never alter a clinical record to hide the event.
A fictional event shows the decision boundary
A fictional employee exports 48 appointment rows, representing 31 unique clients, and emails a share link that lets the wrong outside recipient view the file without authentication. A field inventory finds PHI about those 31 clients and no other individual. Mail logs confirm delivery, but storage logs do not yet resolve whether the recipient opened or downloaded the file.
The practice opens one incident, preserves the export and logs, disables the link, contacts the recipient through an approved route, and verifies its HIPAA role. Privacy and legal reviewers assess permissibility, the three exceptions, the breach presumption and four factors, whether the PHI was unsecured, and each possible notice duty.
The practice tracks 31 potentially affected individuals as its current working count, not 48 rows. That count could change if the field inventory or logs reveal another individual or copy. Arithmetic does not establish a breach, low probability, notice duty, or final affected count. Each decision keeps its source, reviewer, timestamp, facts, and revision history.
Measures should preserve late and open work
Useful controls include:
- incidents routed within target divided by incidents whose routing target fell by the cutoff.
- investigations classified by target divided by investigations whose classification target fell by the cutoff.
- affected-person records reconciled divided by potentially affected people identified by the cutoff.
- notices sent on time divided by notices due under the same source and recipient type.
- corrective actions verified by due date divided by actions due.
- open investigations and overdue duties by count, severity, owner, and age.
Define the cohort, cutoff, numerator, denominator, deadline source, exclusions, and revision method. Report each framework separately; a timely ticket does not prove correct classification, notice, or mitigation.
Related terms
Sources
- U.S. Department of Health and Human Services, Breach Notification Rule
- Electronic Code of Federal Regulations, 45 CFR Part 164 Subpart D
- Electronic Code of Federal Regulations, 45 CFR 164.304
- U.S. Department of Health and Human Services, Submitting Notice of a Breach to the Secretary
- U.S. Department of Health and Human Services, Guidance to Render Unsecured PHI Unusable, Unreadable, or Indecipherable
- U.S. Department of Health and Human Services, Sample Business Associate Agreement Provisions
- Electronic Code of Federal Regulations, 16 CFR Part 318
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni