• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

breach

HIPAA Breach: To Be Or Not To Be?

April 28, 2016/in Blog, HIPAA

Under HIPAA, a breach is any impermissible use or disclosure of protected health information (PHI) that does not fit into one of the following exceptions (45 C.F.R. §164.402):

  • Unintentional access, use, or acquisition of PHI by an employee of covered entity or business associate (BA) made in good faith and would not result in further use or disclosure;
  • Inadvertent disclosure from one authorized person to another authorized person;
  • Disclosure where the covered entity or BA has a good faith belief that the unauthorized person who received the PHI would not likely retain the information;
  • Low probability of compromise as determined by a risk assessment of the following factors:
  • Nature and extent of PHI involved including likelihood of re-identification;
  • The unauthorized person who used the PHI or to whom the disclosure was made;
  • Whether PHI actually was acquired or viewed;
  • The extent to which risk to PHI has been mitigated.

What constitutes PHI?  

PHI under the Privacy Rule is all individually identifiable health information held or transmitted by a covered entity or BA in any form or media which includes the individual’s past, present or future physical or mental health condition, the provision of health care to the individual, and past, present or future payment of health care to the individual. Individually identifiable health information includes a range of specified identifiers such as name, address, date of birth, fingerprint or full-face photograph, vehicle license, IP address etc. (45 C.F.R. §160.103)

The Risks of Unsecure PHI

The Office of Civil Rights (OCR) provides guidance for keeping PHI secure. In the event there is a breach of unsecured PHI, the covered entity is required to follow the Breach Notification Protocol.  Therefore, it is critical for providers to take the appropriate safeguards for securing PHI. Below is a list of examples of unsecure PHI that increases risk of a HIPAA breach:

  • Lost or stolen laptops, desktop computers, tablets, and other devices containing unsecure PHI
  • Discussing patient information in public areas
  • Leaving patient files in public areas
  • Leaving a computer unattended in an accessible area with unsecured PHI
  • Employees that inappropriately access patient information
  • Sending patient information to the wrong patient
  • Discussing patient information with friends, family or co-workers
  • Improperly disposing of patient records
  • Texting or emailing unsecure PHI
  • Posting photos or information regarding patients on social media sites
  • Releasing unauthorized PHI due to incomplete or invalid HIPAA forms
  • Failure to adhere to expiration dates specific on HIPAA forms
  • Impermissibly disclosing PHI in response to a subpoena that does not meet the requirements of the Privacy Rule
  • Being the victim of a cyber attack that compromises PHI

Unfortunately, cyber attacks are on the rise. Utilizing ransom ware and phishing scams, hackers are able to victimize those with encryption, password protection, and/ or a VPN. A couple of recent breaches such as MedStar in DC and Hollywood Hospital in LA resulted in taking EHRs offline, resuming paper processes and subsequently disrupting and delaying patient care.

The Security Official has determined a breach has occurred, now what?

  • The covered entity is required to notify the affected individuals of any unauthorized access, use, disclosure or acquisition without reasonable delay in writing within 60 days after discovery of breach (some states within 30 days).
  • If >500 affected individuals, HHS should be notified at the same time as the affected individuals and the breach should also be reported to major media outlets in the region.
  • If <500 affected individuals, HHS must be given a list of all breaches affecting under 500 individuals within 60 days of calendar year end.
  • If the breach originated from a BA, the BA must notify the covered entity immediately upon discovery. The covered entity is ultimately responsible for the Breach Notification protocol, but this can be the BA’s responsibility if part of the BA Agreement.  A recent $750,000 settlement for a HIPAA violation by an orthopedic practice demonstrates the need to have BA Agreements in place prior to disclosing PHI to a BA.

 

Tags: 1sthcc, EHR, First Healthcare Compliance, HIPAA, medical records, OCR, PHI, PHI breach
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2016/04/PHI-Breach2-1-scaled.jpg 1707 2560 First Healthcare Compliance Staff https://1sthcc.com/wp-content/uploads/2026/07/1stHCC_Logo_HORZ_LRG.png First Healthcare Compliance Staff2016-04-28 11:00:002025-04-15 12:58:01HIPAA Breach: To Be Or Not To Be?
You might also like
Q&A: The New AKS and Stark Law Final Rules – Key-Take-Aways Q&A: The New AKS and Stark Law Final Rules – Key Take-Aways
The Insecurity of Everything Webinar Hardware Hacking Trends – The Insecurity of Everything: Audio Version of the Webinar
Top Challenges Healthcare Compliance Be Aware of the Top Challenges of Healthcare Compliance
PHI 10 Ways PHI Can Be Leaked
5 Tips for Telehealth Compliance Infographic: 5 Tips for Telehealth Compliance
5 Tips for Telehealth Compliance OIG’s Updated Self-Disclosure Protocol

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • The OIG Exclusions List: First Line of Employment Defense
  • Navigating the HIPAA Security Landscape: A Comprehensive Guide to Security Risk Assessments
  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only