{"@context":"https://schema.org","@type":"Article","headline":"Part 2 breach definition","description":"Learn how Part 2 adopts the HIPAA breach definition, including the presumption, three exceptions, and four-factor low-probability assessment.","url":"https://finnihealth.com/resources/glossary/part-2-breach-definition","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 breach definition","item":"https://finnihealth.com/resources/glossary/part-2-breach-definition"}]}}
Glossary term

Part 2 breach definition

Learn how Part 2 adopts the HIPAA breach definition, including the presumption, three exceptions, and four-factor low-probability assessment.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
· View sources
Also called

SUD record breach meaning Part 2 HIPAA breach cross reference

The breach definition used by Part 2 is the meaning in 45 CFR 164.402. It begins with an acquisition, access, use, or disclosure of protected health information that is impermissible under the HIPAA Privacy Rule and compromises security or privacy. The definition includes three exceptions and a presumption of breach unless the regulated entity demonstrates low probability of compromise through the required assessment.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Current rule checkpoint

Live 42 CFR 2.11 gives breach the meaning in 45 CFR 164.402. That definition begins with an acquisition, access, use, or disclosure of protected health information not permitted under the HIPAA Privacy Rule that compromises security or privacy. It contains three exclusions and a presumption of breach unless the covered entity or business associate demonstrates low probability of compromise through the required risk assessment.

Classify the event before the notice path

Current 42 CFR 2.11 incorporates the HIPAA term. Record the information, Part 2 and HIPAA status, acquisition or activity, permission analysis, people, systems, date, discovery, containment, mitigation, evidence, and owner. A security alert or privacy concern is not automatically a breach.

Apply the complete definition

Current 45 CFR 164.402 contains three exclusions and, outside them, the breach presumption unless a covered entity or business associate demonstrates low probability of compromise using at least four named factors. The entity may choose notification without conducting the assessment.

Track separate duties and clocks

After classification, map Part 2, HIPAA, state, consumer-health, payer, contract, insurer, licensing, law-enforcement, and individual-notice duties. Keep each discovery standard, recipient, content, deadline, owner, and evidence separate while response continues.

Start with the event facts

Preserve discovery time, occurrence period, reporter, systems, accounts, people, patients, data, access, use, disclosure, recipients, locations, protections, containment, logs, copies, and evidence. Separate what is known from what remains under investigation. Do not delay containment while waiting to decide whether the regulatory definition is met.

An alert, policy violation, lost device, misdirected message, malware event, or unusual access is an incident to assess. None is automatically a breach, and absence of an alert does not rule one out.

Identify PHI and the impermissible act

Determine whether the information is protected health information and which acquisition, access, use, or disclosure was not permitted under subpart E. Map the person, role, purpose, recipient, data, authority, and rule. Separately identify Part 2 records and obligations because the incorporated definition does not erase Part 2 scope.

Trace structured data, narrative, images, attachments, credentials, logs, exports, backups, and inferred patient status. Use the actual information, not the system's sensitivity label alone.

Test exclusions carefully

Document whether one of the three definition exclusions applies: certain unintentional good-faith workforce or authority activity without impermissible further use or disclosure; certain inadvertent disclosure between authorized people within the same covered entity, business associate, or organized arrangement without impermissible further handling; or a good-faith belief that the unauthorized recipient could not reasonably retain the information.

Apply every condition and preserve evidence. An internal recipient, apology, deletion request, or lack of apparent harm does not automatically satisfy an exclusion.

Perform the four-factor risk assessment

Unless an exclusion applies, analyze at least the nature and extent of PHI including identifiers and re-identification likelihood, the unauthorized person, whether PHI was actually acquired or viewed, and the extent of mitigation. Document facts, evidence, uncertainties, methodology, decision, qualified reviewers, and timing.

Do not replace the analysis with a severity score, number of patients, encryption checkbox, or statement that misuse is unlikely. Mitigation is one factor, not a retroactive permission.

Decide duties and remediate

After classification, determine Part 2, HIPAA, state, contractual, professional, law-enforcement, regulator, patient, and other notification or reporting duties with privacy and counsel. Preserve deadlines and decisions separately. Security and operations should complete containment, credential changes, access removal, correction, recovery, and root-cause remediation.

Audit incident intake, late discovery, evidence, exclusions, risk assessments, notices, vendor reports, closure, and corrective action. Review near misses and events classified outside breach for control improvements.

Example

Twelve privacy events reach assessment. Nine document information, impermissible activity, exception review, decision to notify or four-factor analysis, mitigation, clocks, owner, and evidence; three are closed from an alert label alone. Completeness is 9 of 12 events.

Breach-definition checklist

  • preserve discovery, systems, people, data, access, recipients, protections, and containment;
  • identify PHI, Part 2 records, and the specific impermissible act;
  • apply every condition of any claimed exclusion;
  • document all four required compromise-risk factors and supporting evidence;
  • decide notification and reporting duties under each applicable rule; and
  • remediate root cause, test controls, and audit both breaches and other incidents.

“Breach” is a defined legal conclusion reached after disciplined fact development. Incident response should begin before that conclusion and continue after it.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni