Is every impermissible PHI disclosure a breach?
It is presumed to be a breach unless a risk assessment shows a low probability the PHI was compromised.
- Presumed a breach unless a risk assessment shows low risk ✔
- It is never a breach if it was an accident
- It is always a breach, with no exceptions
Why: An impermissible use or disclosure is presumed to be a breach. It stays a breach unless a risk assessment of at least four factors shows a low probability the PHI was compromised.
Huh, didn't know that: If anyone questions it, the covered entity must prove that an incident was not a breach.
Why was the PHI so calm after the mix-up? It knew the risk assessment would sort it out.
References
Answer: Presumed a breach unless a risk assessment shows low risk. An impermissible use or disclosure is presumed to be a breach. It stays a breach unless a risk assessment of at least four factors shows a low probability the PHI was compromised.
- HHS Breach Notification Rule www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
An impermissible use or disclosure of protected health information is presumed to be a breach
Checked 2026-10-10. - 45 CFR 164.414(b) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.414
burden of demonstrating that all notifications were made as required by this subpart or that the use or disclosure did not constitute a breach
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.