Research · 12 min read
What Counts as a Breach of Your Health Records
Losing health information and having a breach are two different things under federal law. The rule presumes the first is the second, then lets the company holding the records rebut that presumption with a four-part assessment nobody outside ever sees.
Key takeaways
- Under the federal health privacy rules a breach is a conclusion reached by applying a test, not simply an incident that happened.
- The definition covers acquisition, access, use or disclosure that the privacy rule does not permit and that compromises the security or privacy of the information.
- Three narrow exclusions come back out, and each carries conditions about good faith, scope of authority and no further impermissible use.
- Everything else is presumed to be a breach unless the entity demonstrates a low probability of compromise on at least four listed factors, none of which asks about harm.
- The duties run only to unsecured information, so records protected by a specified technology or methodology sit outside the subpart entirely.
- The entity carries the burden of showing that notifications were made or that no breach occurred, and that showing is internal rather than published.
- A covered entity must run a complaint process covering these subparts, may not retaliate for a complaint, and may not require a waiver of the right to complain as a condition of treatment or coverage.
Answer first: a breach is a conclusion, not an event
Something goes wrong with a set of health records. Whether anyone has to tell you is a separate question from whether anything went wrong.
The federal health privacy rules answer it with one definition, three carve-outs and a presumption. The presumption can be rebutted, and the rebuttal has a specified shape.
The company holding the records applies that test to itself and documents the result. Only after the test is a notice duty triggered.
That is not a loophole somebody is hiding. It is how the definition is written, and the definition is published. What follows is what it actually says.
Which rules are doing the counting
The part these rules sit in states who it binds. Its applicability section says the standards, requirements and implementation specifications adopted under the part apply to three kinds of entity.
A health plan. A health care clearinghouse. And a health care provider who transmits any health information in electronic form in connection with a transaction covered by the subchapter.
A second sentence adds that where provided, those standards apply to a business associate as well.
The breach subpart's own applicability section is narrower than people expect, and it is worth reading for what it does not say. It fixes a start date, stating that the requirements apply to breaches of protected health information occurring on or after a date in 2009.
It names no entity at all. The entity question is carried inside each duty instead, in the first words of each section: a covered entity shall, a business associate shall.
A separate federal rule reaches companies outside those categories, and the boundary between the two is a subject of its own. A companion article describes it. Everything below is the first rulebook.
The definition, and the words that carry it
Breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of the part, which compromises the security or privacy of the information.
Four verbs, and access is one of them. Nothing in the sentence requires an intruder, a theft or a technical failure.
The reference to subpart E is the hinge. Subpart E is the privacy rule, the part that says what a covered entity may do with the information in the ordinary course.
So the breach question begins exactly where a permission ends. A disclosure the privacy rule allows is not a breach however uncomfortable it looks, and a disclosure it does not allow is inside the definition however routine it felt.
The statute underneath uses a longer list of verbs for what an entity does with records in the first place. It reaches an entity that accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured protected health information.
Three things the definition takes back out
The same definition then excludes three situations, and each one has conditions attached that are easy to skip.
The first is an unintentional acquisition, access or use by a workforce member or a person acting under the entity's authority. It only qualifies if the act was made in good faith and within the scope of authority, and does not result in further use or disclosure that the privacy rule would not permit.
The second is an inadvertent disclosure between two people who are both authorized to access protected health information at the same covered entity or business associate. The information received must not then be used or disclosed impermissibly either.
The third is the one that turns on a judgment about somebody else. It applies where the entity has a good faith belief that an unauthorized person who received the information would not reasonably have been able to retain it.
None of the three is a general excuse. Each is a narrow situation with its own conditions, and the conditions do the work.
The presumption, and the four questions that answer it
Everything outside those three exclusions is presumed to be a breach. That word is in the regulation.
The presumption falls only where the covered entity or business associate demonstrates that there is a low probability that the protected health information has been compromised. That demonstration has to rest on a risk assessment of at least four listed factors.
The nature and extent of the information involved, including the types of identifiers and the likelihood of re-identification.
The unauthorized person who used the information, or to whom the disclosure was made.
Whether the information was actually acquired or viewed.
And the extent to which the risk to the information has been mitigated.
Two details in that list repay attention. The regulation says at least these factors, so four is a floor rather than a checklist. And not one of the four asks whether anyone was harmed.
The standard is compromise of the security or privacy of the information, which is a question about the information rather than about consequences to a person.
The word that decides whether any of this starts
The notification duties do not run to protected health information generally. They run to unsecured protected health information, and that phrase has its own definition.
It means information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance.
The statute says the same thing and then adds a fallback for the case where the guidance is not issued on time. In that case the term means information not secured by a technology standard that renders it unusable, unreadable or indecipherable, developed or endorsed by a standards developing organization accredited by the American National Standards Institute.
The practical effect is large. Records protected in the specified way can leave an organization without triggering the notification subpart at all.
So silence after an incident is not automatically a failure. It can mean the information was outside the definition, or that the four-factor assessment reached a low probability, or that one of the three exclusions applied.
It is worth being precise about what that means for a reader. Silence is not evidence of anything, in either direction.
Who has to prove what
The subpart assigns the burden, and it assigns it to the organization rather than to the person whose records these are.
Where there has been a use or disclosure in violation of the privacy rule, the burden falls on the covered entity or business associate. It must demonstrate that all notifications were made as required, or that the use or disclosure did not constitute a breach as the definition sets it out.
The statute puts the same burden in the same place, and adds one item to it. The demonstration must include evidence showing the necessity of any delay.
That is a real allocation and it matters in an enforcement proceeding. It is also invisible from outside, because the demonstration is internal documentation rather than anything published.
The duties that ride along with the assessment
The same section that assigns the burden also imports a list of administrative requirements from the privacy rule and applies them to the breach subpart.
Reading that list to the end is worth the minute it takes, because of what is on it and what is not. Training, complaints, sanctions, anti-retaliation, waiver, policies and procedures, and documentation are named. Safeguards and mitigation are not on the list.
The complaints requirement is the one a reader can use. A covered entity must provide a process for individuals to make complaints concerning its policies and procedures required by the privacy and breach subparts, or its compliance with them.
The anti-retaliation requirement sits beside it. A covered entity may not intimidate, threaten, coerce, discriminate against, or take other retaliatory action against an individual for exercising a right or taking part in a process under those subparts, including filing a complaint.
And there is a clause about what cannot be made a condition of service. A covered entity may not require individuals to waive their rights under the complaint provision as a condition of the provision of treatment, payment, enrollment in a health plan, or eligibility for benefits.
The complaint route, and the limit printed inside it
The rules also carry a route that runs past the company. A person who believes a covered entity or business associate is not complying with the administrative simplification provisions may file a complaint with the Secretary.
The mechanics are stated. A complaint must be in writing, on paper or electronically. It must name the person who is the subject of it and describe the acts or omissions believed to be in violation.
There is a clock. A complaint must be filed within one hundred and eighty days of when the complainant knew or should have known that the act or omission occurred. The Secretary may waive that limit for good cause shown.
Then comes the limit most summaries drop. The Secretary will investigate a complaint where a preliminary review of the facts indicates a possible violation due to willful neglect, and may investigate any other complaint filed under the section.
Those are two different words, and the difference is the whole sentence. One category is investigated; the other is discretionary.
A separate section carries the anti-retaliation rule out to business associates as well. It also extends beyond filing to testifying, assisting or participating in an investigation, and to opposing a practice made unlawful by the subchapter in good faith.
What a reader can actually look at
Whether the company publishes a document that names a complaint process, and whether that process is described as covering privacy and breach obligations rather than customer service generally.
Whether any document you are asked to sign contains language waiving rights or agreeing not to complain, since one of these rules speaks directly to that.
Whether the privacy document names the entity that actually holds the medical record, which can be a different company from the brand on the website.
Whether the company says anything about how records are protected at rest, since that is the question the unsecured definition turns on.
And whether there is a stated contact for privacy questions at all. A route that exists on paper is a different thing from one you can find.
What this does not decide
It does not say which federal rulebook governs any particular company. That is a legal conclusion about a specific business, it depends on facts a homepage does not show, and nothing here reaches it.
It does not say that any company has experienced a breach, has made a low-probability determination, or has failed to notify anyone. No such claim is made and none is implied.
It does not describe the second federal rule's own definitions, which a companion article covers, and it does not describe any state statute.
And it is not legal advice. It reports what one federal subpart, two enforcement sections and one statute say, which is a different thing from advice about your situation.
Sources
- 45 CFR 164.104, "Applicability"Paragraph (a), stating that except as otherwise provided the standards, requirements, and implementation specifications adopted under the part apply to a health plan, a health care clearinghouse, and a health care provider who transmits any health information in electronic form in connection with a transaction covered by the subchapter. Paragraph (b), stating that where provided, those standards, requirements and implementation specifications apply to a business associate.
- 45 CFR 164.400, "Applicability"The single sentence of the breach subpart's own applicability section, which fixes a start date for the requirements and names no category of entity, so that the entity question is carried by the subject noun of each substantive section rather than by this one.
- 45 CFR 164.402, "Definitions"The definition of breach as the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E which compromises the security or privacy of the information. The three exclusions at paragraph (1): an unintentional acquisition, access or use by a workforce member or person acting under the entity's authority made in good faith and within the scope of authority and not resulting in further impermissible use or disclosure; an inadvertent disclosure between persons authorized to access protected health information at the same covered entity, business associate or organized health care arrangement, not further used or disclosed impermissibly; and a disclosure where the entity has a good faith belief that the unauthorized recipient would not reasonably have been able to retain the information. The presumption at paragraph (2) that any other impermissible acquisition, access, use or disclosure is a breach unless the covered entity or business associate demonstrates a low probability that the information has been compromised, based on a risk assessment of at least four factors: the nature and extent of the information involved including the types of identifiers and the likelihood of re-identification; the unauthorized person who used it or to whom the disclosure was made; whether it was actually acquired or viewed; and the extent to which the risk has been mitigated. The definition of unsecured protected health information as information not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance.
- 45 CFR 164.414, "Administrative requirements and burden of proof"Paragraph (a), importing the administrative requirements of § 164.530(b), (d), (e), (g), (h), (i) and (j) with respect to the requirements of the breach subpart, and by its own enumeration leaving the safeguards and mitigation paragraphs of that section off the list. Paragraph (b), placing on the covered entity or business associate the burden of demonstrating that all notifications were made as required by the subpart or that the use or disclosure did not constitute a breach as defined.
- 45 CFR 164.530, "Administrative requirements"Paragraph (d)(1), requiring a covered entity to provide a process for individuals to make complaints concerning its policies and procedures required by that subpart and the breach subpart, or its compliance with them. Paragraph (g)(1), barring a covered entity from intimidating, threatening, coercing, discriminating against, or taking other retaliatory action against any individual for the exercise of a right established, or for participation in a process provided for, by those subparts, including the filing of a complaint. Paragraph (h), barring a covered entity from requiring individuals to waive their rights under the complaints-to-the-Secretary section as a condition of the provision of treatment, payment, enrollment in a health plan, or eligibility for benefits.
- 45 CFR 160.306, "Complaints to the Secretary"Paragraph (a), the right of a person who believes a covered entity or business associate is not complying with the administrative simplification provisions to file a complaint with the Secretary. Paragraph (b), requiring the complaint to be filed in writing on paper or electronically, to name the person that is the subject of the complaint, to describe the acts or omissions believed to be in violation, and to be filed within one hundred and eighty days of when the complainant knew or should have known of the act or omission unless the time limit is waived for good cause shown. Paragraph (c), stating that the Secretary will investigate a complaint when a preliminary review of the facts indicates a possible violation due to willful neglect, and may investigate any other complaint filed under the section.
- 45 CFR 160.316, "Refraining from intimidation or retaliation"The prohibition on a covered entity or business associate threatening, intimidating, coercing, harassing, discriminating against or taking any other retaliatory action against any individual or other person for filing a complaint under the complaints section, for testifying, assisting or participating in an investigation, compliance review, proceeding or hearing, or for opposing an act or practice made unlawful by the subchapter where the person has a good faith belief that the practice is unlawful and the manner of opposition is reasonable.
- 42 U.S.C. 17932, "Notification in the case of breach"Subsection (a), reaching a covered entity that accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured protected health information, and requiring notice to each individual whose information has been or is reasonably believed to have been accessed, acquired or disclosed as a result of a breach. Subsection (d)(2), placing on the covered entity or business associate the burden of demonstrating that all notifications were made as required, including evidence demonstrating the necessity of any delay. Subsection (h)(1), defining unsecured protected health information by reference to a technology or methodology specified in the Secretary's guidance, and supplying a fallback where that guidance is not issued in time, keyed to a technology standard developed or endorsed by a standards developing organization accredited by the American National Standards Institute.
Frequently asked questions
Does a breach have to be a hack?
No. The definition names four things: acquisition, access, use, or disclosure of protected health information in a manner the privacy rule does not permit, which compromises the security or privacy of that information. Access on its own is inside that list, and nothing in the sentence requires an intruder or a technical failure. The reference to the privacy rule is doing the real work, because it means the breach question starts exactly where a permission ends. A disclosure the privacy rule allows is not a breach, and a routine disclosure it does not allow is inside the definition.
If a company decides an incident was not a breach, how would anyone know?
From outside, usually not at all. Everything outside the three narrow exclusions is presumed to be a breach. The presumption falls only where the entity demonstrates a low probability that the information was compromised, based on a risk assessment of at least four listed factors. The burden of that demonstration sits on the covered entity or business associate, and the same rule requires the burden to be carried for any delay too. But the demonstration is internal documentation rather than a published finding, so it is not something a reader can inspect.
What does unsecured mean here?
It is the word that decides whether the notification duties start at all. Unsecured protected health information means information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology the Secretary specifies in guidance. The statute adds a fallback if that guidance is not issued in time, pointing instead to a technology standard developed or endorsed by a standards developing organization accredited by the American National Standards Institute. Information protected in the specified way sits outside the subpart.
Does the four-factor assessment ask whether I was harmed?
It does not. The four named factors start with the nature and extent of the information involved, including the types of identifiers and the likelihood of re-identification. The others are the unauthorized person involved, whether the information was actually acquired or viewed, and the extent to which the risk has been mitigated. The standard they feed is a low probability that the information has been compromised. That is a question about the information rather than about consequences to a person. The regulation also says at least those factors, so the list is a floor rather than a complete method.
Can a company make me give up the right to complain?
One of these rules speaks to that directly. A covered entity may not require individuals to waive their rights under the complaint provision as a condition of the provision of treatment, payment, enrollment in a health plan, or eligibility for benefits. A separate requirement bars intimidating, threatening, coercing, discriminating against or otherwise retaliating against someone for exercising a right or participating in a process under the privacy and breach subparts, including filing a complaint. Another section extends the same anti-retaliation rule to business associates.
Will the Secretary investigate a complaint?
The section answers that with two different verbs, and the difference is the point. The Secretary will investigate a complaint where a preliminary review of the facts indicates a possible violation due to willful neglect, and may investigate any other complaint filed under the section. There is also a filing window. A complaint must be made within one hundred and eighty days of when the complainant knew or should have known of the act or omission. The Secretary may waive that for good cause shown. It must be in writing, name the subject, and describe the acts or omissions.