9.2 The HIPAA 4-Factor Breach Risk Assessment

Key Takeaways

  • Under 45 CFR § 164.402, any unauthorized acquisition, access, use, or disclosure of unencrypted PHI is legally presumed to be a breach unless the entity demonstrates a low probability of compromise based on a risk assessment.
  • The 2013 Omnibus Final Rule eliminated the subjective 'harm threshold' standard, requiring covered entities and business associates to evaluate four mandatory objective factors to rebut the presumption of breach.
  • Three statutory exceptions under § 164.402(1)-(3) exempt unintentional good-faith access within scope of authority, inadvertent same-entity authorized disclosures, and good-faith beliefs that information could not have been retained.
  • The 4 mandatory risk assessment factors comprise: (1) nature and extent of PHI, (2) unauthorized recipient identity, (3) whether PHI was actually viewed or acquired, and (4) the extent of completed risk mitigation.
  • Under 45 CFR § 164.414, the covered entity bears the statutory burden of proof and must retain comprehensive documentation of all risk assessments demonstrating a low probability of compromise for a minimum of 6 years.
Last updated: August 2026

The HIPAA 4-Factor Breach Risk Assessment

Prior to the enactment of the 2013 HIPAA Omnibus Final Rule, healthcare organizations evaluated unauthorized uses and disclosures of Protected Health Information (PHI) under a subjective "harm standard." Under that prior interim framework, an incident was deemed a breach only if the covered entity determined that the impermissible disclosure posed a "significant risk of financial, reputational, or other harm to the individual." This subjective standard resulted in widespread under-reporting and inconsistent enforcement across the healthcare industry.

The 2013 Omnibus Final Rule fundamentally transformed federal breach analysis by establishing an explicit Presumption of Breach Standard. Under 45 CFR § 164.402, any acquisition, access, use, or disclosure of unsecured PHI in violation of the HIPAA Privacy Rule (Subpart E) is presumed to be a breach, unless the covered entity or business associate demonstrates that there is a low probability that the protected health information has been compromised based on a rigorous, documented risk assessment evaluating four mandatory factors.


1. Statutory Definition of Breach & The Omnibus Presumption Standard

To master the CHPC examination, candidates must understand the exact statutory definitions codified in 45 CFR Part 164, Subpart D.

+-----------------------------------------------------------------------------+
|                  STATUTORY DEFINITION OF BREACH (45 CFR § 164.402)          |
|                                                                             |
|   "Breach means the acquisition, access, use, or disclosure of protected    |
|    health information in a manner not permitted under subpart E of this      |
|    part which compromises the security or privacy of the protected health   |
|    information."                                                            |
|                                                                             |
|   +-------------------------------------+   |                               |
|   |                   THE 2013 OMNIBUS PRESUMPTION STANDARD             |   |
|   |                                                                     |   |
|   |   IMPERMISSIBLE USE OR DISCLOSURE OF UNSECURED PHI                  |   |
|   |                                 |                                   |   |
|   |                                 v                                   |   |
|   |                   LEGAL PRESUMPTION: IT IS A BREACH                 |   |
|   |                                 |                                   |   |
|   |                +----------------+----------------+                  |   |
|   |                |                                 |                  |   |
|   |                v                                 v                  |   |
|   |     [FALLS WITHIN 1 OF 3            [ENTITY DEMONSTRATES LOW        |   |
|   |      STATUTORY EXCEPTIONS]           PROBABILITY OF COMPROMISE      |   |
|   |      (§ 164.402(1)-(3))              VIA 4-FACTOR ASSESSMENT]       |   |
|   |                |                                 |                  |   |
|   |                +----------------+----------------+                  |   |
|   |                                 |                                   |   |
|   |                                 v                                   |   |
|   |                   BREACH PRESUMPTION REBUTTED                       |   |
|   |                   (No Breach Notifications Required)                |   |
|   |                   (Must Document & Retain 6 Years)                  |   |
|   +---------------------------------------------------------------------+   |
+-----------------------------------------------------------------------------+

Unsecured PHI vs. Secured PHI

Breach notification requirements apply only to unsecured PHI. Under 45 CFR § 164.402, unsecured PHI is defined as PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of technology or methodology specified by the Secretary of HHS in guidance (namely, NIST-standard encryption or complete physical destruction):

  • Data at Rest: Encrypted in compliance with NIST Special Publication 800-111 (e.g., AES-256 bit encryption on databases, laptops, and mobile devices).
  • Data in Motion: Encrypted in compliance with NIST Special Publication 800-52 (e.g., TLS 1.2/1.3 for web and email traffic).
  • Physical Media Destruction: Shredded, incinerated, or pulverized such that PHI cannot be read or reconstructed (NIST SP 800-88 Rev. 1).

[!IMPORTANT] Safe Harbor Principle: If an encrypted laptop is stolen, and the encryption key was not compromised or stored on the same device, the lost data is Secured PHI. The incident is an operational security event, but not a statutory breach of unsecured PHI, eliminating the requirement to perform a breach risk assessment or issue notifications.


2. The Three Statutory Exceptions to the Breach Definition

Before conducting a full four-factor risk assessment, the Privacy Officer must determine whether the incident meets any of the three narrow statutory exceptions set forth in 45 CFR § 164.402.

+-----------------------------------------------------------------------------+
|                 THE THREE STATUTORY BREACH EXCEPTIONS (§ 164.402)           |
|                                                                             |
|   +---------------------------------------------------------------------+   |
|   | EXCEPTION 1: UNINTENTIONAL, GOOD-FAITH WORKFORCE ACQUISITION        |   |
|   | [45 CFR § 164.402(1)]                                               |   |
|   | • Any unintentional acquisition, access, or use of PHI by a         |   |
|   |   workforce member or person acting under authority of a CE or BA   |   |
|   | • Made in GOOD FAITH and WITHIN SCOPE OF AUTHORITY                  |   |
|   | • Results in NO FURTHER impermissible use or disclosure             |   |
|   | • Example: Biller opens chart of patient with identical last name,  |   |
|   |   realizes error immediately, and closes file without reading details|  |
|   +---------------------------------------------------------------------+   |
|                                     |                                       |
|   +---------------------------------------------------------------------+   |
|   | EXCEPTION 2: INADVERTENT SAME-ENTITY / OHCA DISCLOSURE              |   |
|   | [45 CFR § 164.402(2)]                                               |   |
|   | • Inadvertent disclosure by a person authorized to access PHI at    |   |
|   |   a CE or BA to another person AUTHORIZED to access PHI             |   |
|   | • At the SAME Covered Entity, Business Associate, or OHCA           |   |
|   | • Results in NO FURTHER impermissible use or disclosure             |   |
|   | • Example: Nurse inadvertently emails surgical list to a pharmacist |   |
|   |   at the same hospital who had no direct care role for that patient  |   |
|   +---------------------------------------------------------------------+   |
|                                     |                                       |
|   +---------------------------------------------------------------------+   |
|   | EXCEPTION 3: IMPOSSIBILITY OF RETENTION                             |   |
|   | [45 CFR § 164.402(3)]                                               |   |
|   | • Good-faith belief that the unauthorized person to whom PHI was    |   |
|   |   disclosed COULD NOT REASONABLY HAVE RETAINED the information      |   |
|   | • Example: Front desk hands sealed envelope to wrong patient;       |   |
|   |   patient hands envelope back unbroken within 3 seconds without     |   |
|   |   opening or viewing contents                                       |   |
|   +---------------------------------------------------------------------+   |
+-----------------------------------------------------------------------------+

Exception Analysis & Critical Distinctions

  • Exception 1 vs. Intentional Snooping: If a nurse intentionally opens the chart of a neighbor or celebrity, this is not good faith and is outside the scope of clinical authority; Exception 1 cannot apply.
  • Exception 2 Boundary: The recipient must be an authorized workforce member at the same CE, BA, or Organized Health Care Arrangement (OHCA). If a clinic employee inadvertently emails PHI to an employee at an unaffiliated external clinic, Exception 2 does not apply.
  • Exception 3 Threshold: If an unauthorized recipient opened, read, or photographed the document before handing it back, Exception 3 fails, because the recipient was exposed to and could retain the clinical information.

3. The 4 Mandatory Risk Assessment Factors

If an impermissible use or disclosure of unsecured PHI does not satisfy any of the three statutory exceptions, the covered entity or business associate must conduct a formal Breach Risk Assessment. To rebut the presumption of a breach, the entity must evaluate and document all four mandatory factors specified in 45 CFR § 164.402.

+-----------------------------------------------------------------------------+
|                  THE 4 MANDATORY BREACH RISK ASSESSMENT FACTORS             |
|                                                                             |
|   +------------------------------------+   +----------------------------+   |
|   | FACTOR 1: NATURE & EXTENT OF PHI   |   | FACTOR 2: UNAUTHORIZED     |   |
|   | • Types of identifiers involved    |   |           RECIPIENT        |   |
|   | • Clinical sensitivity of records  |   | • Legal duty of recipient  |   |
|   | • Financial / SSN exposure         |   | • Covered Entity / BA vs.  |   |
|   | • Likelihood of re-identification  |   |   malicious actor / public |   |
|   +------------------------------------+   +----------------------------+   |
|                     |                                    |                  |
|                     +-----------------+------------------+                  |
|                                       |                                     |
|   +-----------------------------------+--------------------------------+    |
|   | FACTOR 3: ACTUAL ACQUISITION / VIEWING                             |    |
|   | • Forensic proof: Was PHI opened, viewed, downloaded, or copied?   |    |
|   | • Unopened emails recalled vs. active file exfiltration            |    |
|   | • Hardware examination of returned devices                         |    |
|   +--------------------------------------------------------------------+    |
|                                       |                                     |
|   +-----------------------------------+--------------------------------+    |
|   | FACTOR 4: EXTENT OF RISK MITIGATION                                |    |
|   | • Immediate retrieval of physical records                          |    |
|   | • Executed, legally binding Certificate of Destruction             |    |
|   | • Reliable technical containment and isolation                     |    |
|   +--------------------------------------------------------------------+    |
+-----------------------------------------------------------------------------+

Factor 1: Nature and Extent of the PHI Involved

Factor 1 evaluates the clinical, financial, and personal sensitivity of the exposed data, as well as the ease with which an individual could be re-identified.

Data CategorySpecific Elements ExposedInherent Risk Level & Assessment Impact
High-Risk Identifiers & FinancialsSocial Security Numbers, banking details, credit card numbers, driver's license numbers, date of birth + full name.Extremely High Risk: High probability of identity theft and financial fraud. Almost impossible to demonstrate low probability of compromise unless recipient is bound by strict HIPAA duties.
Highly Sensitive Clinical DataSubstance Use Disorder (SUD) records, HIV/STI diagnoses, mental health/psychotherapy notes, oncology staging, reproductive health details.Extremely High Risk: Poses immediate reputational, social, and employment harm. Heightened sensitivity weighs heavily toward finding a breach.
Limited Clinical / Demographic DataPatient names, appointment dates, clinic provider name (e.g., General Internal Medicine vs. Oncology Clinic).Moderate to Low Risk: Risk depends on whether the provider name reveals underlying condition (e.g., Dr. Smith, Primary Care vs. Dr. Jones, HIV Clinic).
De-Identified / Limited Data SetsData stripped of direct 16 identifiers under § 164.514(e) with low re-identification risk.Low Risk: If re-identification requires complex external data linkage and recipient lacks motivation/capacity, weighs toward low probability.

Factor 2: The Unauthorized Person Who Used or Received the PHI

Factor 2 evaluates the identity, legal status, and confidentiality obligations of the unauthorized recipient who accessed or received the PHI.

+-----------------------------------------------------------------------------+
|                FACTOR 2: RECIPIENT RISK SPECTRUM ANALYSIS                   |
|                                                                             |
|   LOW RISK RECIPIENT                    HIGH RISK RECIPIENT                 |
|   <-----------------------------------------------------------------------> |
|   [HIPAA Covered Entity / BA]           [Unknown Hacker / Dark Web]         |
|   - Bound by federal Privacy Rule       - Malicious criminal intent         |
|   - Professional code of ethics         - Active extortion / data sale      |
|   - Subject to direct OCR penalties     - Zero legal or ethical duty        |
|                                                                             |
|   [Trusted Business Partner]            [General Public / Social Media]     |
|   - Subject to confidentiality NDA      - Uncontrolled mass dissemination   |
|   - Known, verifiable identity          - Permanent digital footprint       |
|   - Willing to execute destruction attestation                              |
+-----------------------------------------------------------------------------+
  • Recipient is a HIPAA Covered Entity or BA: If a misdirected fax containing clinical records is sent to another hospital or medical clinic, the recipient is independently bound by the HIPAA Privacy Rule to protect health information. This significantly lowers the probability of compromise.
  • Recipient is an Unknown or Malicious Actor: If data is exfiltrated via phishing or uploaded to a public cloud repository, the recipient has no confidentiality obligations, heavily indicating that a breach has occurred.

Factor 3: Whether PHI Was Actually Acquired or Viewed

Factor 3 investigates whether the unauthorized individual actually opened, read, downloaded, or copied the PHI, or whether access was prevented or forensic logs prove non-viewing.

  • Forensic Verification of Non-Access: If an unencrypted laptop is lost but recovered with intact forensic artifacts showing the operating system was never booted and the drive was not mounted during the loss window, the PHI was not actually acquired or viewed.
  • Email Delivery vs. Opening: If a misdirected secure email is sent to an external recipient, and the messaging server audit logs prove the recipient never opened the message or attachment before the link was revoked, the PHI was not viewed.
  • Confirmed Viewing: If an unauthorized employee opened an EHR chart and scrolled through progress notes, forensic access logs definitively prove actual viewing, satisfying Factor 3.

Factor 4: The Extent to Which the Risk Has Been Mitigated

Factor 4 examines the immediacy, completeness, and reliability of containment and mitigation actions taken by the covered entity after the incident occurred.

  • Immediate Physical Retrieval: A hospital staff member drops off an envelope containing lab results at the wrong patient address, realizes the error within 10 minutes, returns to the home, retrieves the unopened envelope, and verifies the seal is intact.
  • Signed Destruction Attestations: The recipient of a misdirected email responds immediately, confirms they deleted the message and emptied their digital trash, and executes a legally binding attestation of destruction. HHS OCR recognizes destruction certificates from credible recipients as valid mitigation under Factor 4.
  • Mitigation Inefficacy: If an unauthorized recipient refuses to sign a destruction attestation, threatens to publish records, or cannot be contacted, risk mitigation has failed, and a breach must be declared.

4. Burden of Proof & 6-Year Documentation Mandate (§ 164.414)

Under 45 CFR § 164.414(a), the covered entity or business associate bears the legal burden of proof to demonstrate that all notifications were provided in compliance with Subpart D, or that an impermissible use or disclosure did not constitute a breach.

+-----------------------------------------------------------------------------+
|             BURDEN OF PROOF & DOCUMENTATION ARCHITECTURE (§ 164.414)        |
|                                                                             |
|   [45 CFR § 164.414 STATUTORY BURDEN OF PROOF]                              |
|   The Covered Entity / Business Associate MUST maintain documentation       |
|   sufficient to prove that:                                                 |
|   1. All required breach notifications were provided (§§ 164.404-408); OR   |
|   2. The incident fell within a statutory exception (§ 164.402(1)-(3)); OR   |
|   3. A low probability of compromise was demonstrated via the 4 factors.   |
|                                     |                                       |
|                                     v                                       |
|   [45 CFR § 164.530(j)(2) / § 164.414 RETENTION MANDATE]                    |
|   Must retain all risk assessment matrices, investigative memos, forensic   |
|   reports, and destruction attestations for at least SIX (6) YEARS from    |
|   the date of creation.                                                     |
+-----------------------------------------------------------------------------+

Risk Assessment Documentation Package Elements

To satisfy an OCR compliance audit, every non-breach determination must be supported by a comprehensive Risk Assessment Dossier containing:

  1. Incident Chronology: Date of occurrence, date of discovery, date containment initiated.
  2. Data Manifest: Exact list of data elements and patient identifiers involved.
  3. Recipient Profile: Detailed evaluation of the recipient's identity and confidentiality duties.
  4. Forensic Evidence: EHR audit trails, server logs, network captures, or forensic imaging reports.
  5. Mitigation Records: Signed Certificates of Destruction, retrieval receipts, or written communications.
  6. Synthesized Four-Factor Conclusion: Detailed legal and compliance justification establishing why each factor supports a low probability of compromise, signed by the Privacy Officer.

5. Real-World Compliance Scenario & Officer Trap

+-----------------------------------------------------------------------------+
|                   REAL-WORLD SCENARIO: THE MISDIRECTED FAX                  |
|                                                                             |
|   SCENARIO: A cardiology clinic faxes a 15-page diagnostic report containing|
|   patient demographics, Social Security Numbers, and operative notes to a   |
|   local commercial accounting firm due to a one-digit speed-dial typo.      |
|                                                                             |
|   TRIAGE & ASSESSMENT:                                                      |
|   • Factor 1: High risk (SSNs, full clinical operative notes).              |
|   • Factor 2: High risk (Commercial business with no HIPAA obligations).    |
|   • Factor 3: High risk (Office receptionist opened and viewed pages).      |
|   • Factor 4: The clinic Privacy Officer immediately called the accounting |
|     office manager, had the pages shredded on a cross-cut shredder within   |
|     1 hour, and obtained a signed, notarized Certificate of Destruction.    |
|                                                                             |
|   COMPLIANCE OFFICER TRAP: Concluding that obtaining a destruction          |
|   attestation automatically reduces overall risk to 'low.'                  |
|   Because Factors 1, 2, and 3 all demonstrated severe risk (SSNs exposed,   |
|   recipient had no legal confidentiality duties, and pages were actually    |
|   read), mitigation under Factor 4 alone CANNOT overcome the high           |
|   probability of compromise. The Privacy Officer must declare a statutory   |
|   breach and provide individual notifications under 45 CFR § 164.404.        |
+-----------------------------------------------------------------------------+
Loading diagram...
HIPAA 4-Factor Breach Risk Assessment Decision Tree
Test Your Knowledge

Under the HIPAA Breach Notification Rule (45 CFR § 164.402), which of the following scenarios qualifies for a STATUTORY EXCEPTION to the definition of a breach?

A
B
C
D
Test Your Knowledge

How did the 2013 HIPAA Omnibus Final Rule modify the legal standard for determining whether an impermissible use or disclosure of protected health information constitutes a breach?

A
B
C
D
Test Your Knowledge

Under 45 CFR § 164.414, what is the statutory retention requirement for documentation associated with a HIPAA breach risk assessment where the Privacy Officer concluded there was a low probability of compromise?

A
B
C
D