An unsecured record under Part 2 is a covered record that has not been rendered unusable, unreadable, or indecipherable to unauthorized people through a technology or methodology specified in Secretary-issued guidance under the HITECH Act. Encryption labels, device settings, vendor assurances, and transport claims should be tested against the current guidance and the record's actual state.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Current breach framework
The HHS Part 2 resource page states that Part 2 programs must report breaches of unsecured Part 2 records and links the current complaint, breach-reporting, and privacy-notice resources. The 2024 final rule applied HIPAA Breach Notification Rule requirements to Part 2 breaches, with applicable compliance required by February 16, 2026. Classification is one input to incident analysis. It does not replace the separate breach definition, exceptions, risk work, affected-person count, timing, or notification duties.
Classification follows the actual record state
42 CFR 2.11 incorporates the Secretary's specified technology or methodology. Record the data, system, device, format, encryption state, key custody, transmission, backup, print copy, voice content, date, and evidence.
A control name is not the result
Confirm implementation, configuration, coverage, key separation, exceptions, logs, and failure states. Consider exports, local downloads, screenshots, email, messages, recordings, removable media, caches, and vendor copies.
Incident and breach analysis remains separate
When unauthorized acquisition, access, use, or disclosure may have occurred, route security response, Part 2 breach analysis, HIPAA when applicable, state law, contracts, payer terms, insurance, and notifications to their qualified owners.
Test the exact artifact and event
Start with the specific record copy that may have been exposed. Record its format, location, system state, encryption or destruction method, key location, authorized users, backup status, transfer path, and relevant time window. A platform-level statement that “data is encrypted” is too broad when a downloaded spreadsheet, printed report, email attachment, voice recording, screenshot, or powered-on endpoint may have a different state.
The HHS guidance on rendering protected information unusable, unreadable, or indecipherable addresses encryption and destruction methods. It explains that qualifying encryption depends on the process and on the confidential key or process not being breached. It also distinguishes destruction of hard-copy and electronic media. Apply the current guidance incorporated by the Part 2 definition, and retain technical evidence for the artifact at issue.
Separate security controls from the legal conclusion
Encryption at rest, transport encryption, access control, tokenization, masking, remote wipe, and redaction address different risks. Their presence can reduce exposure without automatically satisfying the incorporated HHS methodology for a particular copy. Determine whether the data was decrypted in memory, available to an authenticated session, cached locally, exported, printed, or accessible with a compromised key.
Document the algorithm or destruction method, configuration, key custody, device state, logging, exceptions, validation owner, and date. Ask the security team to explain what an unauthorized person could actually read or reconstruct during the event rather than accepting a product badge as the answer.
Run incident analysis in parallel
Preserve logs and evidence, contain access, identify affected records and people, and engage Part 2 privacy, security, incident response, and counsel promptly. Determine which entity is the Part 2 program, whether a QSO or other recipient is involved, who owns notification, and which HIPAA, state, contract, payer, insurance, or professional duties also apply.
Avoid delaying containment while classification is refined. Also avoid declaring that notification is unnecessary solely because one system uses encryption. The event, exposed copy, key status, applicable exceptions, and current breach rules all require review.
Example
Eleven exposed artifacts are classified. Eight have verified technology, key, scope, and exception evidence; three rely on a system-level encryption label. Classification completeness is 8 of 11 artifacts.
Unsecured-record response checklist
- inventory every affected record format, copy, system, device, and recipient;
- preserve encryption, key, destruction, device-state, and access evidence;
- compare the implemented method with current Secretary-issued guidance;
- contain the event and perform the separate Part 2 breach analysis;
- assign notification, patient communication, regulator, payer, and contract owners; and
- document decisions, dates, affected-person counts, corrections, and retained evidence.
This definition does not decide whether an incident is a reportable breach or which notices are due. Technical facts and current law control. Qualified Part 2 privacy, security, incident-response, and legal reviewers should make and document the final determination.
The decision record should name the specific artifact, time of exposure, device or service state, encryption or destruction method, key status, evidence reviewed, technical reviewer, privacy reviewer, legal reviewer, conclusion, and follow-up date. Link it to the incident file without placing patient-identifying details in a broadly accessible ticket. If facts change, preserve the earlier conclusion and add a dated revision so notification timing and later audits can be reconstructed.
Retest the conclusion whenever investigators identify another copy, recipient, credential, or decryption path.
Related terms
Sources
- Electronic Code of Federal Regulations, 42 CFR 2.11, Definitions
- U.S. Department of Health and Human Services, Guidance on Rendering Information Unusable, Unreadable, or Indecipherable
- U.S. Department of Health and Human Services, Understanding Part 2
- Federal Register, Confidentiality of Substance Use Disorder Patient Records, 2024 Final Rule
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni