The breach definition used by Part 2 is the meaning in 45 CFR 164.402. It begins with an acquisition, access, use, or disclosure of protected health information that is impermissible under the HIPAA Privacy Rule and compromises security or privacy. The definition includes three exceptions and a presumption of breach unless the regulated entity demonstrates low probability of compromise through the required assessment.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current rule checkpoint
Live 42 CFR 2.11 gives breach the meaning in 45 CFR 164.402. That definition begins with an acquisition, access, use, or disclosure of protected health information not permitted under the HIPAA Privacy Rule that compromises security or privacy. It contains three exclusions and a presumption of breach unless the covered entity or business associate demonstrates low probability of compromise through the required risk assessment.
Classify the event before the notice path
Current 42 CFR 2.11 incorporates the HIPAA term. Record the information, Part 2 and HIPAA status, acquisition or activity, permission analysis, people, systems, date, discovery, containment, mitigation, evidence, and owner. A security alert or privacy concern is not automatically a breach.
Apply the complete definition
Current 45 CFR 164.402 contains three exclusions and, outside them, the breach presumption unless a covered entity or business associate demonstrates low probability of compromise using at least four named factors. The entity may choose notification without conducting the assessment.
Track separate duties and clocks
After classification, map Part 2, HIPAA, state, consumer-health, payer, contract, insurer, licensing, law-enforcement, and individual-notice duties. Keep each discovery standard, recipient, content, deadline, owner, and evidence separate while response continues.
Start with the event facts
Preserve discovery time, occurrence period, reporter, systems, accounts, people, patients, data, access, use, disclosure, recipients, locations, protections, containment, logs, copies, and evidence. Separate what is known from what remains under investigation. Do not delay containment while waiting to decide whether the regulatory definition is met.
An alert, policy violation, lost device, misdirected message, malware event, or unusual access is an incident to assess. None is automatically a breach, and absence of an alert does not rule one out.
Identify PHI and the impermissible act
Determine whether the information is protected health information and which acquisition, access, use, or disclosure was not permitted under subpart E. Map the person, role, purpose, recipient, data, authority, and rule. Separately identify Part 2 records and obligations because the incorporated definition does not erase Part 2 scope.
Trace structured data, narrative, images, attachments, credentials, logs, exports, backups, and inferred patient status. Use the actual information, not the system's sensitivity label alone.
Test exclusions carefully
Document whether one of the three definition exclusions applies: certain unintentional good-faith workforce or authority activity without impermissible further use or disclosure; certain inadvertent disclosure between authorized people within the same covered entity, business associate, or organized arrangement without impermissible further handling; or a good-faith belief that the unauthorized recipient could not reasonably retain the information.
Apply every condition and preserve evidence. An internal recipient, apology, deletion request, or lack of apparent harm does not automatically satisfy an exclusion.
Perform the four-factor risk assessment
Unless an exclusion applies, analyze at least the nature and extent of PHI including identifiers and re-identification likelihood, the unauthorized person, whether PHI was actually acquired or viewed, and the extent of mitigation. Document facts, evidence, uncertainties, methodology, decision, qualified reviewers, and timing.
Do not replace the analysis with a severity score, number of patients, encryption checkbox, or statement that misuse is unlikely. Mitigation is one factor, not a retroactive permission.
Decide duties and remediate
After classification, determine Part 2, HIPAA, state, contractual, professional, law-enforcement, regulator, patient, and other notification or reporting duties with privacy and counsel. Preserve deadlines and decisions separately. Security and operations should complete containment, credential changes, access removal, correction, recovery, and root-cause remediation.
Audit incident intake, late discovery, evidence, exclusions, risk assessments, notices, vendor reports, closure, and corrective action. Review near misses and events classified outside breach for control improvements.
Example
Twelve privacy events reach assessment. Nine document information, impermissible activity, exception review, decision to notify or four-factor analysis, mitigation, clocks, owner, and evidence; three are closed from an alert label alone. Completeness is 9 of 12 events.
Breach-definition checklist
- preserve discovery, systems, people, data, access, recipients, protections, and containment;
- identify PHI, Part 2 records, and the specific impermissible act;
- apply every condition of any claimed exclusion;
- document all four required compromise-risk factors and supporting evidence;
- decide notification and reporting duties under each applicable rule; and
- remediate root cause, test controls, and audit both breaches and other incidents.
“Breach” is a defined legal conclusion reached after disciplined fact development. Incident response should begin before that conclusion and continue after it.
Related terms
Sources
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni