Physicians Lawyers

Healthcare Lawyers for Physicians and Other Health Professionals
 

+menu-

header image

HIPAA Breach Risk Assessments Require Information-Focused Analysis

Businesswoman analyzes HIPAA risk assessment data on a monitor, with a man pointing to a diagram on a large screen.

Overview. Covered entities and business associates should ensure that their HIPAA breach assessment procedures reflect the current regulatory standard. Since the 2013 amendments to the HIPAA Breach Notification Rule, an impermissible acquisition, access, use, or disclosure of protected health information is presumed to be a breach unless the entity can demonstrate, through a documented risk assessment, that there is a low probability the information has been compromised.

Why it matters now. Although the 2013 standard remains the foundation for HIPAA breach determinations, the practical risk environment has changed substantially. Ransomware and hacking incidents now dominate large-breach reporting, OCR has repeatedly emphasized risk analysis, risk management, timely breach notification, and workforce training in enforcement matters, and HHS has proposed the first major update to the HIPAA Security Rule since 2013. These developments make breach assessment less of a narrow notification exercise and more of an integrated privacy, security, incident-response, and governance function.

Major Developments Since 2013

Ransomware is now treated as a presumptive breach risk. OCR guidance issued after the 2013 amendments clarified that ransomware affecting electronic protected health information generally triggers breach-analysis obligations because unauthorized actors may have acquired or controlled the information. A covered entity or business associate seeking to avoid notification must be able to demonstrate, through the required low-probability-of-compromise analysis, that the PHI was not compromised.

Cybersecurity has become central to breach analysis. Since 2013, hacking, ransomware, phishing, credential compromise, and vendor incidents have become among the most significant drivers of reported HIPAA breaches. OCR has identified substantial growth in large-breach reports and individuals affected, particularly in connection with hacking and ransomware. As a result, breach assessment should be coordinated with forensic investigation, containment, business-continuity planning, and Security Rule compliance review.

OCR enforcement increasingly focuses on foundational Security Rule controls. Recent enforcement activity has emphasized accurate and thorough risk analysis, risk management, access controls, security awareness training, timely notification, and documentation. In practice, OCR may examine not only whether an organization reached the correct breach-notification decision, but also whether underlying security deficiencies contributed to the incident or delayed detection and response.

Security Rule modernization is pending. HHS issued a proposed rule in December 2024 to strengthen HIPAA Security Rule requirements in response to escalating cyberattacks against the health care sector. Although proposed rules are not yet final obligations, regulated entities should monitor the rulemaking and consider whether current safeguards, asset inventories, access controls, encryption practices, incident-response procedures, and contingency plans would withstand heightened regulatory scrutiny.

Requests for sensitive PHI require closer legal review. Post-2013 developments, including the 2024 reproductive health privacy rulemaking and subsequent litigation, underscore that certain categories of PHI and certain law-enforcement, judicial, administrative, or oversight requests may require heightened legal analysis before disclosure. Organizations should maintain current procedures for evaluating requests involving sensitive health information and should update notices, policies, and training as applicable legal requirements evolve.

The Current Standard: Risk of Compromise to the Information

The principal change implemented in 2013 was a shift in the focus of the breach analysis. Prior to the amendments, many assessments emphasized the potential harm to the individual whose information was involved. The current standard focuses instead on whether the protected health information itself was compromised. A potential breach is not treated as a reportable breach only if a properly conducted risk assessment demonstrates a low probability that the information was compromised.

This distinction can materially affect breach determinations. Under a prior harm-based approach, an organization might have concluded that no breach occurred if the affected individual was unlikely to experience financial, reputational, or other harm. Under the current standard, however, the relevant inquiry is whether the information was subject to a meaningful risk of compromise.

For example, if a disc containing clinical records is mailed to the wrong address, the analysis should not end with whether the recipient can identify or harm the patient. The organization must assess whether the information was accessible, whether it was actually acquired or viewed, who received it, and what mitigation occurred. Depending on the facts, the information-focused standard may require a different conclusion than a harm-based analysis would have produced.

Key Takeaways for Covered Entities and Business Associates

  • Update breach response policies to reflect the presumption of breach, the information-focused risk assessment standard, and OCR’s ransomware guidance.
  • Coordinate breach analysis with cybersecurity response, forensic investigation, vendor management, and business-continuity planning.
  • Train workforce members to distinguish between a HIPAA violation, a regulatory exception to breach, and a reportable breach, including in ransomware and phishing scenarios.
  • Document all factual findings, mitigation efforts, forensic conclusions, and legal analysis supporting any determination that notification is not required.
  • Evaluate encryption, access controls, audit logs, backups, and evidence of acquisition or viewing early in the response process.
  • Monitor HIPAA Security Rule rulemaking, OCR enforcement trends, and evolving requirements for sensitive categories of PHI.
  • Resolve close factual or legal questions conservatively, especially where evidence of mitigation, non-access, or containment is incomplete.

Recommended Assessment Framework

1. Determine Whether a HIPAA Violation Occurred

The first step is to determine whether the underlying event involved an impermissible acquisition, access, use, or disclosure of protected health information. Not every HIPAA violation constitutes a breach; however, every breach necessarily includes a HIPAA infraction. If the use or disclosure was permitted under the HIPAA Privacy Rule, no breach exists for notification purposes, although other compliance obligations may still warrant review.

2. Assess Whether a Specific Breach Exception Applies

HIPAA recognizes three specific exceptions under which an impermissible use or disclosure is not treated as a breach: unintentional acquisition, access, or use by a workforce member or person acting under appropriate authority; certain inadvertent disclosures to another authorized person; and disclosures where the covered entity or business associate has a good-faith belief that the recipient could not reasonably retain the information. Because the entity bears the burden of establishing the exception, the analysis should be supported by contemporaneous documentation.

3. Confirm Whether the Information Was Properly Encrypted

Where the incident involves electronic protected health information, the organization should promptly determine whether the information was secured through encryption that satisfies applicable standards. If properly encrypted information is lost or disclosed, the incident generally will not trigger breach notification obligations under the HIPAA Breach Notification Rule. In cyber incidents, however, encryption should be evaluated alongside evidence of credential compromise, exfiltration, unauthorized access, malware activity, backup integrity, and whether the information was encrypted before or only after the attacker obtained access.

This inquiry should be addressed early in the response process because encryption may be dispositive in some matters, but it is not a substitute for a complete incident investigation. Organizations should maintain records sufficient to establish whether the relevant device, file, database, transmission, or backup environment was encrypted at the time of the incident and whether unauthorized actors had any ability to access usable PHI.

4. Evaluate the Probability of Compromise

If the matter is not resolved by the preceding steps, the organization must conduct and document a risk assessment to determine whether there is a low probability that the protected health information was compromised. Since 2013, this analysis has become increasingly intertwined with cybersecurity evidence, including forensic findings, system logs, endpoint data, network activity, containment timelines, and evidence concerning acquisition, viewing, exfiltration, or destruction of PHI.

At a minimum, the assessment should address the nature and extent of the protected health information involved, including identifiers and the likelihood of re-identification; the unauthorized person who used the information or to whom it was disclosed; whether the information was actually acquired or viewed; and the extent to which the risk to the information has been mitigated. In cyber incidents, the assessment should also consider whether data was encrypted, copied, staged, compressed, transferred, posted, sold, destroyed, or rendered unavailable.

The assessment should evaluate these factors collectively rather than in isolation. Clinical information, financial data, direct identifiers, or information that can be combined with other data may increase the likelihood of compromise. Conversely, credible evidence that the information was not accessed, was returned or destroyed, or was subject to effective mitigation may support a lower-risk conclusion.

The identity and reliability of the recipient may also be relevant. For example, disclosure to another regulated health care provider who promptly reports the incident may present a different risk profile than disclosure to an unknown recipient or a recipient whose conduct suggests possible misuse. The conclusion should be tied to verifiable facts rather than assumptions.

Because an impermissible acquisition, access, use, or disclosure is presumed to be a breach unless the entity demonstrates a low probability of compromise, the organization should treat documentation as a core compliance requirement. Any no-breach determination should be supported by reliable facts, mitigation records, forensic evidence where applicable, appropriate legal or subject-matter input, and a clear written rationale. Where material doubt remains, particularly in ransomware or hacking matters, the more prudent course is to proceed with breach notification.

Recommended Next Steps

Organizations subject to HIPAA should review their breach response policies, incident intake procedures, documentation templates, vendor incident protocols, cybersecurity controls, and workforce training materials to ensure alignment with current breach notification expectations and post-2013 enforcement priorities. Policies should reflect the presumption of breach, the required risk assessment factors, OCR ransomware guidance, the limited regulatory exceptions, encryption and forensic-evidence considerations, and the importance of prompt, well-supported documentation. Because breach determinations are highly fact-specific and increasingly technical, covered entities and business associates should involve privacy, security, compliance, legal, forensic, and vendor-management personnel early in the response process.

author avatar
admin
John Fisher is a seasoned health care lawyer with more than 30 years of experience advising physicians and health care providers. His practice spans a wide range of issues, including physician investments in ambulatory surgery centers, concierge and cash-based medical practices, and health care fraud prevention. John is dedicated to helping his clients navigate complex legal challenges while protecting their interests and ensuring compliance in a rapidly evolving industry.
This entry was posted in Health Law Practice, HIPAA Issues. Bookmark the permalink.

 

Comments are closed.