Skip to content
Lawwise

      Subjects

      This handbook

      Healthcare Regulation

      When Exposure of Health Information Must Be Reported

      An impermissible use or disclosure is presumed to be a reportable breach. The presumption can be rebutted, but only by a documented assessment against four defined factors, and the clock for notifying everyone who must be told runs from discovery rather than from the conclusion of that assessment.

      Healthcare Regulation6 min readFederal and stateHealth information

      A cracked pane of frosted glass in a metal window frame, with pale daylight showing through the fracture lines.
      The question is not whether something got out, but whether what got out was capable of being read. — Rsparks3, CC0, source.

      The rule in short

      An acquisition, access, use or disclosure of protected health information not permitted by the privacy rule is presumed a breach unless the entity documents a low probability of compromise using four factors: the nature of the information, who received it, whether it was actually acquired or viewed, and the extent of mitigation. Individual notice is due no later than sixty calendar days after discovery, with separate media and federal tiers keyed to the number affected.

      Start from the presumption. An acquisition, access, use or disclosure of protected health information in a manner not permitted by the privacy rule is a breach, and the entity carries the burden of demonstrating otherwise. Nothing needs to be proven before the obligation attaches. The work is in rebutting it, and the rebuttal has to be written down.

      Three things that are not breaches at all

      Before the assessment, check the exclusions. An unintentional acquisition or use by a workforce member acting in good faith within the scope of authority is excluded, provided no further impermissible use follows. An inadvertent disclosure between two people both authorized to access information at the same entity is excluded on the same condition. And a disclosure is excluded where the entity has a good faith belief that the unauthorized recipient would not reasonably have been able to retain the information.

      Separately, the whole framework reaches only unsecured information. Information encrypted to the specified standard, or destroyed so that it cannot be reconstructed, is not unsecured, and its exposure is not reportable under this rule at all. That is the single most valuable control an organization can implement, because it removes the question rather than answering it.

      The four factors and how they are weighed

      Where no exclusion applies, the presumption stands unless the entity demonstrates a low probability that the information was compromised. Four factors are assessed at minimum. First, the nature and extent of the information, including the types of identifier and the likelihood of re-identification. Second, the unauthorized person who used it or received it. Third, whether the information was actually acquired or viewed. Fourth, the extent to which the risk has been mitigated.

      Each factor is evaluated and the conclusion rests on the combination. A disclosure of names and appointment times to another covered entity that returned the file unopened reads differently from a disclosure of diagnoses and account numbers to an unknown recipient. The standard is low probability of compromise, not certainty of harm, and an assessment that reasons toward no harm without addressing all four factors is not a defense.

      The assessment does not pause the clock

      The sixty days run from discovery, not from the completion of the risk assessment. An organization that spends fifty days investigating has ten days left to draft, print and mail, and substitute notice arrangements take longer than that. Build the assessment on a schedule that leaves room, and treat any incident still unresolved at the halfway mark as one that will be notified.

      The three notification tiers

      Individual notice comes first and applies to every breach regardless of size. It goes out without unreasonable delay and in no case later than sixty calendar days after discovery, by first-class mail to the last known address, or by email where the individual has agreed to electronic notice. Where contact information is insufficient or out of date, substitute notice is required, and its form depends on how many individuals cannot be reached.

      Media notice attaches where a breach affects more than five hundred residents of a state or jurisdiction. Notice goes to prominent media outlets serving that area, on the same timetable as individual notice. Federal notice runs on two tracks: a breach affecting five hundred or more individuals is reported contemporaneously with individual notice, and smaller breaches are logged and submitted within sixty days after the end of the calendar year in which they were discovered.

      ObligationWho is notifiedTriggerOuter deadlineMethod
      Individual noticeEach affected individualAny breach of unsecured informationSixty days from discoveryFirst-class mail, or email by prior agreement
      Substitute noticeIndividuals who cannot be reachedInsufficient or out-of-date contact informationSame as individual noticeAlternative written form, or web posting and toll-free line where ten or more are affected
      Media noticeProminent outlets in the jurisdictionMore than five hundred residents of one state affectedSixty days from discoveryPress release or equivalent
      Federal notice, large breachThe federal enforcement agencyFive hundred or more individuals affectedContemporaneous with individual noticeElectronic submission
      Federal notice, small breachThe federal enforcement agencyFewer than five hundred individuals affectedSixty days after the calendar year endsAnnual log submission
      Upward reportThe covered entityBreach at a business associateSixty days from discovery by the associateAs specified in the written agreement

      Breaches that begin downstream

      A business associate that discovers a breach reports it to the covered entity without unreasonable delay and no later than sixty days after discovery, identifying the individuals affected so far as known. The covered entity's own sixty-day clock is what governs individual notice, so a vendor that uses the full period leaves the entity with none. Contracts routinely shorten the vendor deadline for that reason, and the mechanics sit in the treatment of business associate agreements and downstream liability.

      Whether the underlying event was impermissible at all is answered by the analysis of the permitted uses of health information. A disclosure inside one of those permissions is not a breach, however alarming it looks. The reporting reflex here parallels the environmental rules on spill and release reporting: a short fixed window, running from awareness rather than from confirmation.

      Enforcement exposure after the notice goes out

      Civil money penalties are graded by culpability, from a violation the entity did not know of and would not have known of with reasonable diligence, through reasonable cause, to willful neglect corrected within thirty days, to willful neglect not corrected. The ranges are set by regulation and are adjusted for inflation on a recurring basis, so the operative figures should be read from the current penalty provision rather than from memory.

      Large breaches attract an enforcement review almost automatically, and reviews frequently end in a settlement with an obligation to remediate under supervision. What that obligation looks like in practice is set out in the discussion of corrective action plans and integrity agreements. The variable that most reliably reduces exposure is whether the entity had performed and documented a risk analysis before the incident, not after it.

      Points to carry away

      • An impermissible disclosure is presumed a breach; the entity carries the burden of showing otherwise.
      • The rebuttal rests on four defined factors and must be documented as a written risk assessment.
      • Individual notice is due no later than sixty calendar days after discovery of the breach.
      • A breach affecting five hundred or more individuals triggers media notice and contemporaneous federal notice.
      • Smaller breaches are logged and reported after the end of the calendar year in which they were discovered.
      • Properly encrypted or destroyed information falls outside the definition of unsecured information entirely.

      Questions readers ask

      When is a breach treated as discovered?

      On the first day the breach is known to the entity, or by exercising reasonable diligence would have been known, counting the knowledge of any workforce member or agent other than the person who committed the breach. That construction matters. A help desk ticket describing the incident starts the clock even if it sits unread for weeks, and an entity cannot extend the deadline by routing incidents slowly. Diligence is measured against what a reasonable entity in the same position would have detected.

      What must the notice actually say?

      Five elements, in plain language: a brief description of what happened including the date range where known, the types of information involved, the steps individuals should take to protect themselves, what the entity is doing to investigate and mitigate, and contact procedures including a toll-free number, an email address, a website or a postal address. Notices that describe the incident but omit the protective steps or the contact route are incomplete, and incompleteness is itself a violation separate from the underlying exposure.

      Can notification be postponed at the request of investigators?

      Yes, in defined terms. Where a law enforcement official states that notification would impede a criminal investigation or damage national security, the entity delays for the period specified. If the statement is in writing and specifies a time period, the entity delays for that period. If the statement is oral, the entity documents it, including the identity of the official, and delays no longer than thirty days unless a written statement follows. The delay does not otherwise change any deadline.

      Sources

      1. eCFR — 45 CFR 164.402, DefinitionsThe definition of breach, the three exclusions and the four-factor assessment.
      2. eCFR — 45 CFR 164.404, Notification to IndividualsThe sixty-day outer limit, the required content and substitute notice.
      3. eCFR — 45 CFR 164.408, Notification to the SecretaryThe five hundred individual threshold and the annual log for smaller breaches.
      4. eCFR — 45 CFR 164.410, Notification by a Business AssociateWhat a business associate must report upward and how quickly.
      5. eCFR — 45 CFR Part 164 Subpart D, Notification in the Case of Breach of Unsecured Protected Health InformationThe full notification subpart including media notice and law enforcement delay.
      6. eCFR — 45 CFR 160.404, Amount of a Civil Money PenaltyThe culpability tiers and how the penalty range is set and adjusted.

      Lawwise is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Healthcare Regulation

      Healthcare Regulation

      Using Health Information Without Written Authorization

      A covered entity may use or disclose protected health information without authorization to the individual, for treatment, payment and health care operations, under an opportunity to agree or object, and for an enumerated set of public interest purposes. Everything outside that list requires a written authorization, and psychotherapy notes, marketing and any sale of information require one regardless. Permitted disclosures are separately limited to the minimum necessary to accomplish the purpose.

      5 min readFederal and state

      Healthcare Regulation

      The Self-Referral Prohibition and the Exceptions to It

      Where a physician or an immediate family member holds an ownership interest in or a compensation arrangement with an entity, the physician may not refer designated health services to that entity for federal payment and the entity may not present a claim for them, unless the arrangement satisfies an exception in full. Liability does not depend on intent. Amounts collected on prohibited referrals must be refunded, and knowing violations carry additional penalties.

      5 min readFederal and state

      Healthcare Regulation

      Provider Enrollment, Revalidation and Revocation

      Enrollment establishes the effective date from which claims may be paid, and certain practitioner types may bill retrospectively for up to thirty days before it. Enrollment must be revalidated every five years, or every three for equipment suppliers, and a revalidation request must be answered within sixty calendar days. Revocation carries a reenrollment bar of one to ten years, extended to twenty for a second revocation, and it takes effect thirty days after the notice is mailed.

      5 min readFederal and state