Is every impermissible PHI disclosure a breach?

It is presumed to be a breach unless a risk assessment shows a low probability the PHI was compromised.

Start playing free

  1. Presumed a breach unless a risk assessment shows low risk ✔
  2. It is never a breach if it was an accident
  3. It is always a breach, with no exceptions

Why: An impermissible use or disclosure is presumed to be a breach. It stays a breach unless a risk assessment of at least four factors shows a low probability the PHI was compromised.

Huh, didn't know that: If anyone questions it, the covered entity must prove that an incident was not a breach.

The dad joke
Why was the PHI so calm after the mix-up? It knew the risk assessment would sort it out.
Like this card?
Play the game

References

Answer: Presumed a breach unless a risk assessment shows low risk. An impermissible use or disclosure is presumed to be a breach. It stays a breach unless a risk assessment of at least four factors shows a low probability the PHI was compromised.

  1. HHS Breach Notification Rule www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
    An impermissible use or disclosure of protected health information is presumed to be a breach
    Checked 2026-10-10.
  2. 45 CFR 164.414(b) (eCFR) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.414
    burden of demonstrating that all notifications were made as required by this subpart or that the use or disclosure did not constitute a breach
    Checked 2026-10-10.

Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.

Test yourself in the game