What Counts as a HIPAA Breach? Definition, Risk Assessment, and Notification Rules
TL;DR
- A HIPAA breach is any acquisition, access, use, or disclosure of protected health information (PHI) not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the PHI (45 CFR § 164.402).
- Every impermissible PHI disclosure is presumed to be a breach. To avoid notification, you must document a four-factor risk assessment showing a low probability that the PHI was compromised.
- Three specific fact patterns are excluded: unintentional good-faith access by a workforce member, inadvertent disclosure between two authorized persons at the same organization, and incidents where the unauthorized recipient could not have retained the PHI.
- Individual notification is required within 60 calendar days of discovery. Breaches affecting 500 or more individuals also require concurrent HHS filing and media notification to outlets serving the affected state or jurisdiction.
- The 2025 inflation-adjusted civil money penalties run from $145 per violation (Tier 1 minimum) to $2,190,294 per violation (Tier 4 maximum); the annual cap is $2,190,294 across all four tiers.
Who This Is For
This article is for compliance officers, privacy attorneys, healthcare IT teams, and SaaS developers who handle PHI. If you are running a post-incident triage or building a breach response playbook, the sections on the four-factor assessment and notification timelines are the ones to read carefully.
The Legal Basis

The HIPAA Breach Notification Rule sits at 45 CFR §§ 164.400 through 164.414. It was enacted under the HITECH Act in 2009 and substantially revised by the 2013 Omnibus Rule, which replaced an earlier "harm threshold" standard with the current presumption-of-breach model.
The definition of breach appears at 45 CFR § 164.402: acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of that PHI.
Two elements must both be satisfied. First, the act must be impermissible under the Privacy Rule, meaning it is not authorized by the patient, not required for treatment, payment, or healthcare operations, and not covered by one of the Privacy Rule's named exceptions. Second, the incident must compromise the security or privacy of the PHI.
Since 2013, every impermissible use or disclosure of unsecured PHI is presumed to have compromised security or privacy. The covered entity or business associate bears the burden of rebutting that presumption through a documented four-factor risk assessment. If no assessment exists, OCR treats the incident as reportable. That burden-of-proof allocation is codified at 45 CFR § 164.414.
What Counts as PHI
A breach can only occur if the information involved qualifies as PHI. Under 45 CFR § 160.103, PHI is any individually identifiable health information held or transmitted by a covered entity or business associate, in any form (electronic, paper, oral), that links to at least one of the 18 identifiers listed at 45 CFR § 164.514(b)(2):
Names, geographic subdivisions smaller than a state, all dates directly related to an individual except year alone, phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers, device identifiers, URLs, IP addresses, biometric identifiers, full-face photographs, and any other unique identifying number or code.
Data that has been de-identified under the Safe Harbor method of 45 CFR § 164.514(b) or through Expert Determination under 164.514(b)(1) is not PHI. An incident involving only de-identified data is not a HIPAA breach.
Aggregated population statistics, employment records held by a covered entity solely in its capacity as an employer, and student health records covered by FERPA are excluded from PHI even when they contain health information.
A limited data set, defined at 45 CFR § 164.514(e), sits between fully identified PHI and de-identified data. Direct identifiers have been removed, but certain dates and geographic information remain. Impermissible use of a limited data set can violate the Privacy Rule without automatically triggering the Breach Notification Rule, depending on the circumstances and the four-factor assessment.
The Four-Factor Breach Risk Assessment
When PHI has been accessed, used, or disclosed in a way that violates the Privacy Rule, the presumption is that a breach has occurred. 45 CFR § 164.402 provides four factors to assess whether there is a low probability that the PHI has been compromised. All four must be considered; the conclusion on each must be documented.
Factor 1: The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification.
A row in a spreadsheet containing a name, date of birth, diagnosis code, and Social Security number carries a high re-identification probability. A list of opaque patient identifiers with no clinical values and no names carries a lower probability. Sensitive PHI categories, including mental health records, substance use treatment records governed by 42 CFR Part 2, HIV status, genetic information, and reproductive health data, increase the weight of this factor.
Factor 2: Who received the PHI or who accessed it without authorization.
Disclosure to another covered entity that is already bound by the Privacy Rule is materially different from disclosure to a consumer with no obligations. Disclosure to a workforce member at the same covered entity who has a different, but legitimate, access authorization is different from disclosure to an external party. The nature of the recipient's obligations and the likelihood of further misuse both matter.
Factor 3: Whether the PHI was actually acquired or viewed.
This is the evidentiary factor. System and access logs, forensic reports, email delivery receipts, and endpoint telemetry all speak to whether an unauthorized party actually opened, read, or downloaded the data. A stolen laptop that never left offline state, demonstrated by a forensic image showing no post-theft logins, creates a credible argument that acquisition did not occur. An email misaddressed to a recipient who responded confirming they deleted it unread similarly supports a low-acquisition finding, though signed destruction documentation strengthens the position.
Factor 4: The extent to which the risk to the PHI has been mitigated.
Mitigation actions reduce the probability that PHI remains at risk even if it was accessed. Signed confidentiality attestations from the unauthorized recipient, remote device wipes confirmed by MDM logs, demonstrable destruction, and documented retraction of a misdirected communication all count. Verbal assurances alone are not sufficient. The mitigation evidence needs to be in the file.
If the assessment across all four factors supports a finding of low probability of compromise, the incident does not require notification. The risk assessment and all supporting evidence must be retained for six years from the date of creation or the date when the documentation last was in effect, whichever is later, per 45 CFR § 164.530(j).
The Three Breach Exceptions

45 CFR § 164.402(1) lists three fact patterns that are excluded from the definition of breach even when a technical violation of the Privacy Rule has occurred.
Exception 1 - Unintentional acquisition by a workforce member in good faith.
A workforce member who accidentally opens the wrong patient record, realizes the mistake, and takes no further action satisfies this exception. The access must be: unintentional, by a person authorized to access PHI generally, acting within their normal scope of authority, and not followed by any further unauthorized use or disclosure. Documentation of the incident and the circumstances still matters.
Exception 2 - Inadvertent disclosure between two authorized persons at the same covered entity or organized healthcare arrangement.
A billing specialist who sends a clinical note to the wrong billing colleague within the same covered entity, where both are authorized to handle PHI, can satisfy this exception. The key criterion is that both the sender and the recipient are authorized under the same covered entity or organized healthcare arrangement, and that no subsequent impermissible use or disclosure follows.
Exception 3 - Good-faith belief that the unauthorized recipient could not have retained the PHI.
The standard is objective: the covered entity must have a reasonable, good-faith belief that an unauthorized person to whom the PHI was disclosed could not have retained it. The clearest example is a document handed to the wrong patient in a waiting room, where that patient immediately hands it back without reading it. This exception requires contemporaneous evidence. If you cannot reconstruct what happened, you cannot claim this exception.
Incidents That Are Not Breaches
Several categories of incidents are regularly misclassified as breaches.
Encrypted PHI. HHS guidance specifies that PHI is "secured," and therefore outside the Breach Notification Rule, if it has been rendered unusable, unreadable, or indecipherable per the Secretary-specified technologies listed at 45 CFR § 164.402. For data at rest, NIST SP 800-111 provides the applicable standard. For data in transmission, a FIPS 140-2 validated encryption module is required, per NIST SP 800-52 Rev. 2. If the decryption key was not compromised in the same incident, loss or theft of the encrypted device is generally not a reportable breach.
Partial encryption, default vendor encryption settings that have not been verified against the NIST standard, or situations where the key was stored on or near the device do not qualify for this safe harbor.
De-identified data incidents. If the data involved has been de-identified under 45 CFR § 164.514(b), it is not PHI, and no breach has occurred regardless of who accessed it.
Internal incidents with no actual acquisition. A misconfigured access control that logs no unauthorized reads, a test environment with synthetic data mistakenly populated with real identifiers that was caught before any external query, or a monitoring alert that is resolved before any unauthorized access occurs: none of these are breaches. They may warrant internal incident documentation and remediation, but they do not trigger the Breach Notification Rule.
Disclosures to the individual about their own PHI. Providing a patient's records to that patient, even in error about the delivery method, is not an impermissible disclosure.
Notification Timelines
Once an incident is determined to be a reportable breach, three notification streams start, each running against its own deadline. 45 CFR §§ 164.404 through 164.410 govern each stream.
Individual Notification (45 CFR § 164.404)
The covered entity must notify each affected individual without unreasonable delay and no later than 60 calendar days after discovery of the breach. Discovery is defined as the first day on which any workforce member or agent of the covered entity (other than the person who caused the breach) knew or, by exercising reasonable diligence, would have known about the breach.
Written notification is required by first-class mail to the individual's last known address, or by email if the individual has provided a prior written consent for electronic communication. For urgent situations where immediate misuse is possible, telephone outreach is required in addition to written notice.
Required content includes: a description of what happened and the dates of the breach and discovery, the types of unsecured PHI involved, steps individuals should take to protect themselves, a description of what the covered entity is doing to investigate, mitigate, and prevent future incidents, and contact information including a toll-free number active for 90 days.
When contact information is out of date for 10 or more individuals, substitute notice is required: either a conspicuous posting on the covered entity's website for 90 days, or notice in major print or broadcast media serving the relevant geographic area.
HHS Notification (45 CFR § 164.408)
For breaches affecting fewer than 500 individuals, the covered entity must maintain a log of the incidents and submit notification to HHS no later than 60 calendar days after the end of the calendar year in which the breaches were discovered.
For breaches affecting 500 or more individuals, notification to the Secretary must occur contemporaneously with the individual notifications, meaning within the same 60-calendar-day window from discovery. Submission is made through the HHS OCR Breach Portal.
Breaches affecting 500 or more individuals are listed publicly on OCR's breach portal, commonly referred to as the Wall of Shame.
Media Notification (45 CFR § 164.406)
When a breach affects more than 500 residents of a single state or jurisdiction, the covered entity must also provide notification to prominent media outlets serving that state or jurisdiction. The deadline is the same as individual notification: within 60 calendar days of discovery. Content requirements follow the same standard as individual notifications under 45 CFR § 164.404(c).
Business Associate Obligations (45 CFR § 164.410)
If the breach occurs at or is discovered by a business associate, the BA must notify the covered entity without unreasonable delay and no later than 60 calendar days after the BA's discovery of the breach. Discovery is defined the same way as for covered entities: the first day any employee, officer, or agent of the BA (other than the person who caused the breach) knew or should have known.
The BA must provide the covered entity with enough information to complete the CE's own notifications, including the identities of affected individuals to the extent known, the dates involved, the types of PHI involved, and a description of mitigation steps taken.
In practice, business associate agreements specify an internal BA notification deadline shorter than 60 days, typically 10 to 30 days from discovery, to give the covered entity adequate time to prepare its notifications before the 60-day deadline runs.
Law Enforcement Delay (45 CFR § 164.412)
If a law enforcement official requests that notification be delayed because it would impede a criminal investigation or damage national security, the covered entity or BA may postpone. A written statement from the official governs the duration. An oral request permits a delay of up to 30 days from the date of the oral statement, unless a written statement arrives within that window.
Civil Money Penalties

OCR enforces the Breach Notification Rule through civil money penalties. The 2025 inflation-adjusted amounts under 45 CFR § 160.404 and 45 CFR Part 102 are:
| Tier | Culpability | Per-violation range | Annual cap |
|---|---|---|---|
| 1 | Did not know and could not have known | $145 to $73,011 | $2,190,294 |
| 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
| 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| 4 | Willful neglect, not corrected | $73,011 to $2,190,294 | $2,190,294 |
Criminal penalties under 42 USC § 1320d-6 apply when PHI is obtained under false pretenses or disclosed for personal gain or malicious harm: up to $250,000 in fines and up to 10 years of imprisonment.
Late notification, meaning discovery-to-notification exceeding 60 days, is itself a separate violation that stacks on top of the underlying breach. OCR has cited late notification as the primary aggravating factor in several large settlements.
State attorney generals received independent HIPAA enforcement authority under the HITECH Act and can bring parallel civil actions. State breach notification laws also apply and in several states impose shorter notification deadlines or require additional content. The shorter deadline controls when a conflict exists.
Specific Scenarios
Ransomware
OCR has stated in guidance that a ransomware infection affecting systems containing PHI is presumed to be a breach of unsecured PHI, because ransomware encryption by an attacker constitutes unauthorized access. (HHS OCR, Ransomware and HIPAA Fact Sheet, July 2016, see source 15.) The covered entity may rebut the presumption through the four-factor assessment, but in practice this is difficult: modern ransomware attacks routinely include a data exfiltration phase before encryption, which undercuts any argument that acquisition did not occur. The safer operational position is to treat a ransomware event as a breach unless forensic analysis affirmatively rules out PHI access.
Lost or Stolen Devices
Whether a lost or stolen device triggers notification depends on whether encryption meets the HHS safe harbor standard at the time of loss. A device with full-disk encryption, a pre-boot authentication password maintained separately from any cloud key storage, and MDM-confirmed policy enforcement generally qualifies as unsecured PHI rendered indecipherable. The loss is then not a reportable breach. Devices without full-disk encryption, or where the password was stored with the device or on an attached note, do not qualify.
Theft from parked cars remains one of the most frequently cited sources of breach reports in OCR's enforcement history. MDM-enforced full-disk encryption and remote-wipe capability are the direct operational controls.
Workforce Member Snooping
Unauthorized access to a patient's record by a workforce member, even without further disclosure, is a breach. The impermissible access itself satisfies the definition. Covered entities must have access monitoring sufficient to detect these incidents. The workforce member faces personal criminal liability under 42 USC § 1320d-6; the covered entity faces civil liability for failing to implement adequate access controls and auditing.
Subcontractor Breaches
When a business associate uses a subcontractor that suffers a breach, the subcontractor notifies the BA; the BA notifies the covered entity; the covered entity notifies individuals. Each link in the chain runs against its own 60-day discovery-to-notification deadline. Business associate agreements must flow these obligations downstream to all subcontractors, and subcontractor BAAs must specify reporting timelines consistent with allowing the CE to meet its own deadlines.
Breach Response Sequence
A defensible breach response follows the same sequence whether the triggering incident is a stolen device, a misdirected email, a cloud misconfiguration, or a ransomware event.
Contain (within 24 hours). Stop the ongoing disclosure. Revoke compromised credentials, isolate affected systems, retract misdirected communications, initiate remote wipe on lost devices. Preserve logs and do not wipe or rebuild affected systems before a forensic snapshot is captured.
Preserve evidence (days 1 to 3). Pull all access logs, email delivery and read receipts, endpoint telemetry, and physical evidence. If the incident involves an external attacker or has potential criminal elements, engage forensic counsel before any remediation.
Conduct the four-factor assessment (days 3 to 14). Document each factor with the supporting evidence. Have two reviewers (compliance officer and legal counsel) sign off on the conclusion. If the finding is low probability of compromise, this document is the file you retain for six years.
Notify (days 14 to 60, or sooner if facts are clear). Issue individual notifications, HHS filing, and media notifications where required. Waiting until day 58 or 59 has been cited repeatedly in OCR settlements as evidence that the covered entity treated notification as a last resort rather than an obligation.
Remediate and update the risk analysis. Close the root cause. Update the relevant HIPAA risk analysis to reflect the incident as a discovered risk. Revise policies, retrain the workforce, or add technical controls as indicated. Document the remediation.
Frequently Asked Questions
Is there a minimum number of individuals affected before a breach must be reported?
No. A breach affecting a single individual is reportable. The size of the breach affects how you report (HHS batch filing for fewer than 500, concurrent filing and media notification for 500 or more), but there is no de minimis threshold below which notification is excused.
Does the 60-day clock start at discovery or at the conclusion of the investigation?
At discovery. 45 CFR § 164.404(b) defines discovery as the first day the covered entity or any employee (other than the person who caused the breach) knew or reasonably should have known about the incident. The clock does not pause while the investigation is ongoing.
Is an encrypted laptop always outside the Breach Notification Rule?
Only if the encryption meets the Secretary-specified standard: NIST SP 800-111 for data at rest or a FIPS 140-2 validated module for data in transmission, and the decryption key was not compromised in the same incident. Default vendor encryption that has not been verified against these standards, or situations where the key was stored with the device, does not qualify for the safe harbor.
What happens if a business associate finds the breach and notifies us past 60 days?
The BA's late notification to you is itself a violation of 45 CFR § 164.410. Your 60-day clock for notifying individuals still starts from the date your organization discovered or should have discovered the breach, not the date the BA formally told you. If the BA's delay caused you to miss your individual notification deadline, both parties face potential enforcement action.
Do state breach notification laws apply alongside HIPAA?
Yes. State laws run in parallel. Where a state deadline is shorter than 60 days or requires additional notification content, the state law controls for that element. The HIPAA Breach Notification Rule sets a federal floor, not a ceiling.
What is the difference between a breach and a security incident?
A security incident is any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information, as defined at 45 CFR § 164.304. A breach is a specific subset: an impermissible use or disclosure of unsecured PHI. Many security incidents do not involve PHI and are not breaches. An incident involving PHI proceeds through the four-factor assessment to determine whether it is a reportable breach.
Sources
- 45 CFR § 164.402, Definitions (Breach). https://www.law.cornell.edu/cfr/text/45/164.402. Accessed 2026-05-12.
- 45 CFR § 164.404, Notification to individuals. https://www.law.cornell.edu/cfr/text/45/164.404. Accessed 2026-05-12.
- 45 CFR § 164.406, Notification to the media. https://www.law.cornell.edu/cfr/text/45/164.406. Accessed 2026-05-12.
- 45 CFR § 164.408, Notification to the Secretary. https://www.law.cornell.edu/cfr/text/45/164.408. Accessed 2026-05-12.
- 45 CFR § 164.410, Business associate notification. https://www.law.cornell.edu/cfr/text/45/164.410. Accessed 2026-05-12.
- 45 CFR § 164.412, Law enforcement delay. https://www.law.cornell.edu/cfr/text/45/164.412. Accessed 2026-05-12.
- 45 CFR § 164.414, Burden of proof. https://www.law.cornell.edu/cfr/text/45/164.414. Accessed 2026-05-12.
- 45 CFR § 164.514, De-identification and limited data set. https://www.law.cornell.edu/cfr/text/45/164.514. Accessed 2026-05-12.
- 45 CFR § 164.530(j), Documentation retention (6-year rule). https://www.law.cornell.edu/cfr/text/45/164.530. Accessed 2026-05-12.
- 45 CFR § 160.404, HIPAA civil money penalty tiers. https://www.law.cornell.edu/cfr/text/45/160.404. Accessed 2026-05-12.
- 45 CFR Part 102, 2025 inflation-adjusted penalty amounts. https://www.law.cornell.edu/cfr/text/45/102.3. Accessed 2026-05-12.
- 42 USC § 1320d-6, Criminal penalties for HIPAA violations. https://www.law.cornell.edu/uscode/text/42/1320d-6. Accessed 2026-05-12.
- HHS OCR Breach Portal. https://ocrportal.hhs.gov/ocr/breach/breach_form.jsf. Accessed 2026-05-12.
- HHS Office for Civil Rights, Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules, 78 FR 5566 (Jan. 25, 2013), Omnibus Rule establishing the four-factor risk assessment and presumption-of-breach standard. https://www.federalregister.gov/documents/2013/01/25/2013-01073/modifications-to-the-hipaa-privacy-security-enforcement-and-breach-notification-rules. Accessed 2026-06-23.
- HHS Office for Civil Rights, Ransomware and HIPAA Fact Sheet (July 2016), OCR guidance stating that ransomware infections affecting PHI systems are presumed breaches of unsecured PHI. https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdf. Accessed 2026-06-24.
- NIST Special Publication 800-111, Guide to Storage Encryption Technologies for End User Devices, Secretary-specified standard for encryption of PHI at rest under 45 CFR § 164.402 safe harbor. https://csrc.nist.gov/publications/detail/sp/800-111/final. Accessed 2026-06-24.
- NIST Special Publication 800-52 Rev. 2, Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations, FIPS 140-2 validation reference for PHI encryption in transmission under 45 CFR § 164.402 safe harbor. https://csrc.nist.gov/publications/detail/sp/800-52/rev-2/final. Accessed 2026-06-24.
Last reviewed: 2026-05-12. This article was prepared by the Security Compliance Guide Editorial Team. We use AI to draft initial summaries of publicly available cybersecurity compliance documentation, then verify every claim against primary sources before publication. We are not licensed auditors, attorneys, or compliance consultants. For binding decisions, consult a qualified professional. See our editorial standards for full sourcing rules.
