Conducting HIPAA Breach Risk Assessments
The HIPAA rules governing potential breaches of patient confidentiality were materially revised in 2013. On January 17, 2013, the Office for Civil Rights issued regulations that altered the analytical framework covered entities must apply when determining whether an impermissible acquisition, access, use, or disclosure of protected health information constitutes a reportable breach.
Although these regulations have been effective for a substantial period of time, many providers have not fully conformed their breach assessment procedures to the current regulatory standard. Even where written policies have been revised, workforce members and other responsible personnel may not fully appreciate the practical significance of the 2013 amendments or the manner in which potential breaches must now be evaluated.
1. Understand the Information-Focused Risk Assessment Standard
The principal change effected in 2013 was a substantive shift in the focus of the breach analysis. Under the prior framework, the analysis often emphasized the potential harm to the individual whose information was involved. The current standard instead requires an assessment of the probability that the protected health information itself has been compromised. A potential breach is not treated as a reportable breach only where a documented risk assessment demonstrates a low probability of compromise.
Under the prior approach, covered entities had broader discretion to determine that no breach existed where the affected individual was unlikely to suffer financial, reputational, or other cognizable harm. For example, if a disc containing records from a knee examination were sent to an incorrect address, a covered entity might previously have concluded that no breach occurred if the recipient could not identify the patient and the disc contained neither financial information nor information materially increasing the risk of identity theft.
The same facts may support a different conclusion under the current information-focused standard. An unauthorized recipient at an incorrect address may be able to access and view the health information, thereby increasing the probability that the information has been compromised. Although each determination remains fact-specific, the example illustrates the manner in which the current regulatory standard may alter the outcome of the analysis.
2. Follow a Structured HIPAA Breach Assessment Process
Step 1: Determine Whether a HIPAA Violation Occurred
The analysis should begin by distinguishing between a HIPAA violation and a HIPAA breach. Not every HIPAA violation constitutes a breach; however, a breach necessarily involves an impermissible acquisition, access, use, or disclosure of protected health information. Where the use or disclosure was permitted under HIPAA, the breach notification requirements are not implicated, although other compliance obligations or remedial measures may remain applicable.
Step 2: Determine Whether a Specific Breach Exception Applies
HIPAA recognizes three limited exceptions under which an impermissible use or disclosure is not deemed a breach: unintentional acquisition, access, or use by an authorized workforce member or person acting under the authority of a covered entity or business associate in good faith and within the scope of authority; certain inadvertent disclosures between persons authorized to access protected health information; and disclosures where the covered entity or business associate has a good-faith belief that the unauthorized recipient could not reasonably have retained the information. Because the covered entity or business associate bears the burden of establishing the applicability of any exception, the factual basis and legal rationale supporting reliance on an exception should be documented with particularity.
Step 3: Confirm Whether the Information Was Properly Secured
If no HIPAA violation occurred, the analysis should terminate. If a violation occurred but a specific regulatory exception applies, the incident is not a breach for purposes of the breach notification rule. If neither determination resolves the matter, the assessment should proceed to the remaining elements of the analysis.
For electronic protected health information, the covered entity or business associate should determine whether the information was properly secured, including whether applicable encryption standards were satisfied. Properly secured information is substantially less susceptible to compromise. For example, if patient files stored on a disc were properly encrypted and the encryption key was not compromised, the loss or theft of the disc generally would not give rise to breach notification obligations.
Step 4: Assess the Probability of Compromise
If the incident remains unresolved after the preceding steps, the covered entity or business associate should conduct a formal risk assessment. The dispositive inquiry is whether there is a low probability that the protected health information has been compromised. This determination is inherently fact-intensive and generally represents the most legally significant component of the analysis.
The “compromise” standard is among the most consequential features of the 2013 regulatory amendments. Rather than focusing primarily on the potential harm to the individual, the current analysis evaluates the likelihood that the protected health information was compromised. Accordingly, a greater number of impermissible uses or disclosures may require treatment as reportable breaches unless the presumption of breach is overcome through a properly supported risk assessment.
At a minimum, the risk assessment should address the nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification; the unauthorized person who used the information or to whom the disclosure was made; whether the information was actually acquired or viewed; and the extent to which the risk to the protected health information has been mitigated.
Each factor should be evaluated in light of the totality of the circumstances. Detailed clinical information, financial information, or information that may be combined with other data to re-identify an individual may increase the probability of compromise. The analysis should not consider the information in isolation; rather, it should account for all relevant surrounding facts and the extent to which those facts affect the likelihood of misuse, further disclosure, or other compromise.
The identity, role, and conduct of the recipient are also material considerations. By way of example, the risk may be materially greater where the recipient has a history of identity theft than where the recipient is a health care professional who promptly reports the disclosure and provides credible confirmation that the information was not retained, used, or further disclosed. No categorical rule should be applied; the conclusion must be supported by the specific facts and circumstances presented.
3. Document the Conclusion and Resolve Doubt Conservatively
Where the assessment supports a determination that there is a low probability of compromise, that determination should be supported by reliable facts, verifiable evidence, appropriate expert input where warranted, and a reasoned application of the governing standard. HIPAA presumes that an impermissible acquisition, access, use, or disclosure is a breach unless the covered entity or business associate demonstrates a low probability that the protected health information was compromised. A thorough investigation report should therefore document the steps undertaken, the facts reviewed, the regulatory factors considered, and the basis for the final determination.
Where material uncertainty remains after completion of the assessment, the more legally conservative course is to treat the incident as a breach and comply with the applicable notification requirements. A determination that no breach occurred should be made only where the documented record affirmatively supports that conclusion.
Conclusion
Potential HIPAA breach matters frequently arise in unanticipated circumstances, and an assessment that appears reasonable at the time may be scrutinized differently if the information is later misused. Not every potential breach must be treated as an actual breach; however, each assessment should be comprehensive, well supported, and legally defensible. In this context, shortcuts create significant compliance risk. The adequacy of the investigation and the quality of the supporting documentation may ultimately determine whether the organization can sustain its determination.