What Is a HIPAA Breach?

A HIPAA breach generally is an impermissible use or disclosure of PHI that compromises its security or privacy, subject to regulatory exceptions. An…

Quick answer

A HIPAA breach generally is an impermissible use or disclosure of PHI that compromises its security or privacy, subject to regulatory exceptions. An…

The short answer

A HIPAA breach generally is an impermissible use or disclosure of PHI that compromises its security or privacy, subject to regulatory exceptions. An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless an exception applies or a documented risk assessment shows a low probability of compromise.

Start with scope and context

A security incident, an impermissible disclosure, and a reportable breach are related but distinct concepts. Record what is known, preserve evidence, and use the applicable regulatory definitions and response process before deciding whether notification is required.

Know how to recognize a security incident, assess impermissible disclosures, and prepare for breach response and notification.

The requirements in practice

Report a suspected incident promptly to the designated response team; preserve relevant logs, messages, devices, and other evidence while containing ongoing exposure safely.

Determine whether unsecured protected health information was involved, when the incident was discovered, which people and records may be affected, and whether an exception applies.

A workable process

Document the required breach risk assessment or applicable exception, coordinate covered-entity and business-associate responsibilities, and seek counsel on reporting duties.

If notification is required, follow the rule’s recipient, content, and timing requirements; fix the cause and record corrective actions without delaying required notices.

Make safeguards part of the workflow

Keep the response plan usable: give staff a clear reporting channel, designate a lead and backup, preserve logs, identify covered-entity and business-associate contacts, and periodically rehearse a realistic scenario.

Document the required breach risk assessment or applicable exception, coordinate covered-entity and business-associate responsibilities, and seek counsel on reporting duties.

Assign people and vendor responsibilities

Determine whether unsecured protected health information was involved, when the incident was discovered, which people and records may be affected, and whether an exception applies.

Report a suspected incident promptly to the designated response team; preserve relevant logs, messages, devices, and other evidence while containing ongoing exposure safely.

Keep useful evidence

Record when the incident was discovered, the systems and people involved, the PHI potentially affected, containment steps, investigation findings, risk-assessment reasoning, notifications, and corrective actions. Preserve a clear timeline and route legal decisions to the appropriate privacy lead and counsel.

Assign an owner and a review date. Retain current versions and record material changes so the next reviewer can see what was decided, why it was reasonable for the situation, and what still needs attention.

Check exceptions before making a blanket rule

Not every security incident is a reportable breach, but an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless an exception applies or a documented assessment demonstrates a low probability that PHI was compromised. State laws can impose separate requirements.

Apply the rule to the exact purpose and circumstances. State privacy laws, professional requirements, contracts, and other federal rules may add protections or obligations beyond the HIPAA baseline.

Review when the situation changes

For a suspected event, report internally without waiting for a full investigation. The federal rule generally uses discovery-based deadlines and requires notification without unreasonable delay; who sends which notice depends on covered-entity and business-associate roles.

Keep the response plan usable: give staff a clear reporting channel, designate a lead and backup, preserve logs, identify covered-entity and business-associate contacts, and periodically rehearse a realistic scenario.

Common mistakes to avoid

Not every security incident is a reportable breach, but an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless an exception applies or a documented assessment demonstrates a low probability that PHI was compromised. State laws can impose separate requirements.

Do not treat a checklist, vendor claim, signed agreement, training slide, or security product as a stand-alone compliance program. Confirm the actual rule, keep evidence of implementation, and revisit the assessment when the facts change.

A concise review checklist

  • Report a suspected incident promptly to the designated response team; preserve relevant logs, messages, devices, and other evidence while containing ongoing exposure safely.
  • Determine whether unsecured protected health information was involved, when the incident was discovered, which people and records may be affected, and whether an exception applies.
  • Document the required breach risk assessment or applicable exception, coordinate covered-entity and business-associate responsibilities, and seek counsel on reporting duties.
  • If notification is required, follow the rule’s recipient, content, and timing requirements; fix the cause and record corrective actions without delaying required notices.

Frequently asked questions

What is the first thing to check about What Is a HIPAA Breach?

Confirm the organization’s role, the purpose of the activity, and the information involved. Then compare the actual facts with the applicable HIPAA rule rather than relying on a general product claim or a broad rule of thumb.

Does following a checklist guarantee HIPAA compliance?

No. A checklist can organize work, but it cannot determine applicability or replace an accurate risk analysis, working policies, appropriate safeguards, required agreements, workforce training, and ongoing review.

Primary sources

Read the official guidance.

This guide is educational. Check current federal requirements and applicable state law for decisions about your organization.

This material is general information, not legal advice. HIPAA applicability and obligations depend on specific facts; state and other federal laws may add requirements. Consult qualified counsel for organization-specific decisions.