Breach or Incident? Using the HIPAA Four-Factor Risk Assessment

A nurse faxes a resident's records to the wrong number. A laptop is stolen from a car. An employee opens a file she should not have. Each of these is a security or privacy incident, but is each one a breach that must be reported? The answer has real consequences, and HIPAA gives a specific method for working it out.

Understanding that method helps you respond with confidence rather than panic or guesswork.

Incident versus breach

An incident is any event that may compromise the confidentiality, integrity or availability of information. A breach, as defined in the HIPAA Breach Notification Rule, is an impermissible use or disclosure of protected health information (PHI) that compromises its security or privacy.

The rule presumes that an impermissible use or disclosure of PHI is a breach unless you can demonstrate, through a documented risk assessment, that there is a low probability that the PHI has been compromised. There are also a few narrow exceptions, such as certain unintentional, good-faith access by a workforce member acting within their authority, or inadvertent disclosures between authorized people at the same organization, provided the information is not further misused.

The four factors

When no exception applies, you assess at least these four factors:

1. The nature and extent of the PHI involved

What types of information were exposed? Names alone are different from names with Social Security numbers, diagnoses, medications or financial details.

2. The unauthorized person who used the PHI or to whom it was disclosed

Who received it? A disclosure to another HIPAA-covered entity or someone obligated to protect it is lower risk than a disclosure to an unknown person, a journalist or a criminal.

3. Whether the PHI was actually acquired or viewed

Was the data actually looked at, or was there only an opportunity? A stolen laptop that is later recovered with forensic proof that files were never opened is different from one that disappeared. A misdirected email that was deleted unread, confirmed by the recipient, is different from one that was opened.

4. The extent to which the risk has been mitigated

Did you get assurance, preferably in writing, that the recipient destroyed or returned the information and will not misuse it? Did you remotely wipe the device? Mitigation can lower the probability of compromise.

Walk through an example

Consider a hypothetical: a staff member emails a spreadsheet with resident names and diagnoses to the wrong external address. The assessment might note that the information is sensitive (factor 1), that the recipient is an unknown individual at an unrelated company (factor 2), that it is unclear whether the message was opened (factor 3), and that you are awaiting a reply to your request for deletion (factor 4). Without solid evidence that the data was not accessed, you likely could not show a low probability of compromise, and notification would be required. Different facts could lead to a different result, and the reasoning must be written down.

If it is a breach: notification

HIPAA breach notification requirements include:

Individuals: notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. A breach is treated as discovered when it is known, or reasonably should have been known, to the organization.

HHS: for breaches affecting 500 or more individuals, notify HHS at the same time as individuals. For fewer than 500, log the breaches and report them to HHS within 60 days after the end of the calendar year.

Media: for breaches affecting more than 500 residents of a state or jurisdiction, notify prominent media outlets in that area.

Business associates: must notify the covered entity, which then handles notification to others unless the contract assigns the task differently.

State laws may impose additional or different requirements, so ask your attorney to check them for Oklahoma, Texas, Arkansas or wherever your residents live.

Encryption and safe harbor

PHI that has been properly encrypted according to HHS guidance, so that it is unusable and unreadable to unauthorized persons, is not considered unsecured. Losing an encrypted laptop with a secure key can therefore be a very different event from losing an unencrypted one. This is a strong reason to encrypt every portable device.

Document everything

Keep a record of each incident, the facts you gathered, the assessment of each factor, your conclusion and any notices sent. Retain the documentation for six years. Even incidents you decide are not reportable should have a written analysis.

Support from UnityCare IT

UnityCare IT helps healthcare organizations investigate technical facts, such as whether a device was encrypted or which files were accessed, so your privacy officer and counsel can make a sound decision. We can also help you set up an incident log and response workflow.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172