13.1 Federal Breach Notification Rule Definition, Exceptions, and Safe Harbors

Key Takeaways

  • Under 45 CFR § 164.402, a breach is defined as the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted under Subpart E of Part 164 (the Privacy Rule) which compromises the security or privacy of the protected health information.
  • The 2013 HIPAA Omnibus Final Rule eliminated the previous subjective 'harm threshold' and established a strict legal presumption: any impermissible use or disclosure of unsecured PHI is presumed to be a statutory breach unless the covered entity or business associate demonstrates a low probability of compromise through an objective four-factor risk assessment.
  • Under HHS Guidance issued pursuant to Section 13402 of the HITECH Act, the Safe Harbor provision exempts secured PHI rendered unusable, unreadable, or indecipherable to unauthorized individuals through NIST-compliant encryption (NIST SP 800-111 for data at rest, NIST SP 800-52 for data in transit) or destruction (NIST SP 800-88 Rev. 1).
  • 45 CFR § 164.402 establishes three narrow statutory exceptions to the definition of breach: (1) unintentional, good faith acquisition/access by workforce members within scope of authority (§ 164.402(1)(i)); (2) inadvertent disclosure between authorized persons at the same covered entity, business associate, or OHCA (§ 164.402(1)(ii)); and (3) good faith belief that the unauthorized recipient could not reasonably have retained the information (§ 164.402(1)(iii)).
  • If an impermissible disclosure meets all statutory prerequisites of an exception, it is excluded as a matter of law from the definition of a breach, eliminating individual, media, and HHS OCR notification requirements while still requiring documented internal logging and potential workforce counseling.
Last updated: September 2026

Federal Breach Notification Rule Definition, Exceptions, and Safe Harbors

Prior to 2009, the Health Insurance Portability and Accountability Act (HIPAA) established comprehensive privacy and security standards but lacked a uniform federal mechanism requiring healthcare organizations to inform individuals when their medical records were compromised. If an unauthorized workforce member browsed sensitive clinical records, or if an unencrypted database was exfiltrated by cybercriminals, covered entities faced potential regulatory penalties for safeguard violations under 45 CFR Part 164 Subparts C and E, but were under no explicit federal statutory obligation to notify the affected patients, the media, or the federal government.

This regulatory gap was permanently closed by Congress through the enactment of the Health Information Technology for Economic and Clinical Health (HITECH) Act, passed as Title XIII of the American Recovery and Reinvestment Act (ARRA) of 2009. The HITECH Act established the Federal Breach Notification Rule, subsequently codified by the Department of Health and Human Services (HHS) at 45 CFR Part 164, Subpart D (§§ 164.400–164.414). For candidates preparing for the AHIMA CHPS (Certified in Healthcare Privacy and Security) examination, mastering the statutory architecture of Subpart D is mandatory. Privacy and security leaders must understand the legal definition of a breach, the evolution from subjective harm standards to strict statutory presumption, the cryptographic technical specifications of the federal Safe Harbor, and the precise legal boundaries of the three statutory exceptions.


The Statutory Definition of a Breach (45 CFR § 164.402)

Under 45 CFR § 164.402, a breach is defined as:

"The acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information."

To deconstruct this statutory definition for exam analysis, a privacy officer must break the standard down into its foundational legal components:

  1. Protected Health Information (PHI): The incident must involve individually identifiable health information transmitted or maintained in any form or medium (electronic, paper, or oral) held by a covered entity or business associate under 45 CFR § 160.103. If the data is fully de-identified in accordance with 45 CFR § 164.514, it is not PHI, and Subpart D cannot apply.
  2. Impermissible Action (Subpart E Violation): The occurrence must involve an acquisition, access, use, or disclosure that violates the HIPAA Privacy Rule (45 CFR Part 164, Subpart E). If an access, use, or disclosure is permitted by the Privacy Rule—such as an authorized disclosure for treatment under § 164.506, a required-by-law disclosure under § 164.512(a), or an incidental disclosure where reasonable safeguards were maintained under § 164.502(a)(1)(iii)—there is no Privacy Rule violation, and therefore no breach can exist.
  3. Compromise of Security or Privacy: The impermissible event must compromise the security or privacy of the data. As analyzed below, federal law presumes compromise unless rebutted through a formal risk assessment.

The Evolution of the Breach Standard: Harm vs. Presumption

A central focus of the CHPS examination is the dramatic regulatory evolution from the 2009 Interim Final Rule to the 2013 HIPAA Omnibus Final Rule.

1. The 2009 Interim Final Rule: The Subjective "Harm Standard"

When HHS first issued the interim regulations in August 2009, the rule included a controversial "harm standard." Under that initial standard, an impermissible use or disclosure was deemed to compromise the privacy or security of PHI only if it posed a "significant risk of financial, reputational, or other harm to the individual." This standard placed covered entities in the subjective position of speculating whether an unauthorized recipient would use the data to cause harm. In practice, covered entities frequently rationalized that disclosures did not cause "significant harm," resulting in widespread under-reporting of serious privacy compromises.

2. The 2013 Omnibus Final Rule: The Strict Legal "Presumption of Breach"

Recognizing the fundamental flaws of the harm standard, HHS issued the HIPAA Omnibus Final Rule in January 2013 (effective March 26, 2013, with compliance required by September 23, 2013), permanently eliminating the harm standard. In its place, HHS established a strict legal presumption of breach:

[!CRITICAL] The Presumption Standard (45 CFR § 164.402(2)): An acquisition, access, use, or disclosure of protected health information in a manner not permitted under Subpart E is presumed to be a breach unless the covered entity or business associate demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the four statutory factors.

This legal shift fundamentally altered healthcare compliance. On the CHPS exam, candidates must remember: The starting legal presumption is that a breach has occurred. The burden of proof rests entirely on the covered entity to demonstrate, through objective evidence, that there was a low probability of compromise. If the entity cannot meet this evidentiary burden, formal breach notifications are mandatory under federal law.

Regulatory EraGoverning RuleStandard for CompromiseEvidentiary BurdenPractical Compliance Effect
2009–2013HITECH Interim Final RuleSubjective "Harm Standard": Poses a significant risk of financial, reputational, or other harmAmbiguous; entity evaluated speculative individual injuryHigh rate of unnotified disclosures; entities argued no harm occurred
2013–PresentHIPAA Omnibus Final RuleObjective "Presumption of Breach": Presumed a breach unless low probability of compromise shownStrict statutory burden of proof on covered entity (§ 164.414)Mandatory formal 4-factor risk assessment; heightened transparency and enforcement

The Statutory Safe Harbor: Secured vs. Unsecured PHI

The Breach Notification Rule applies exclusively to unsecured protected health information. Under 45 CFR § 164.402, unsecured PHI is defined as:

"Protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in guidance."

Pursuant to Section 13402(h)(2) of the HITECH Act, the Secretary of HHS issued explicit technical guidance defining the technologies and methodologies that render PHI unusable, unreadable, or indecipherable. This guidance creates the Federal Breach Safe Harbor. If electronic or physical PHI is secured in strict compliance with these cryptographic or destruction standards, and an incident occurs (such as a lost laptop or stolen hard drive), the data is legally "secured." Therefore, no breach has occurred as a matter of law, and zero notification obligations are triggered under federal law.

Valid Safe Harbor Methods Recognized by HHS Guidance

  1. Encryption of Electronic PHI at Rest:
    • Standard: National Institute of Standards and Technology (NIST) Special Publication (SP) 800-111 (Guide to Storage Encryption Technologies for End User Devices).
    • Requirements: Full-disk encryption or robust file-level encryption utilizing Advanced Encryption Standard (AES) with 128-bit, 192-bit, or 256-bit keys. The cryptographic key must NOT be stored on the same physical device or accessible to the unauthorized person.
  2. Encryption of Electronic PHI in Transit:
    • Standard: NIST SP 800-52 (Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations), NIST SP 800-77 (Guide to IPsec VPNs), or Federal Information Processing Standards (FIPS) 140-2 / FIPS 140-3.
    • Requirements: Data traversing public networks or wireless media must be protected using TLS (version 1.2 or 1.3) or IPsec tunnels with compliant cipher suites.
  3. Destruction of Physical and Electronic Media:
    • Standard: NIST SP 800-88 Revision 1 (Guidelines for Media Sanitization).
    • Paper Media: Must be shredded, pulverized, or incinerated such that PHI cannot be read or reconstructed. Cross-cut shredding is the healthcare industry benchmark.
    • Electronic Media: Must be sanitized through physical destruction (disintegration, incineration, melting, or pulverizing) or cryptographic sanitization/degaussing in compliance with NIST SP 800-88.

[!WARNING] Candidate Trap: Password Protection vs. Encryption A perennial distractor on the CHPS exam is "password protection" or "PIN protection." Password protection (such as a basic Windows logon password, a BIOS password, or a password-protected PDF/Excel file) does NOT meet the statutory definition of encryption under NIST SP 800-111 and does NOT qualify for Safe Harbor protection. If an unencrypted laptop protected only by a Windows password is stolen, the data is unsecured PHI, and the incident is presumed to be a reportable breach.

[!CAUTION] Candidate Trap: The "Key on the Keychain" Problem Encryption satisfies the Safe Harbor only if the decryption key has not been compromised. If an encrypted flash drive is stolen while attached to a lanyard containing a written note with the encryption password, or if a laptop is stolen with the recovery key taped to the bottom casing, the Safe Harbor is entirely invalidated. The data is treated as unsecured PHI.


The Three Statutory Exceptions to the Definition of Breach

Even if an incident involves unsecured PHI and represents an impermissible use or disclosure under Subpart E, it does not constitute a breach if it satisfies all statutory elements of one of the three explicit exceptions codified at 45 CFR § 164.402:

Statutory Breach Exceptions (45 CFR § 164.402):

  ┌────────────────────────────────────────────────────────────────────────┐
  │ Exception 1: § 164.402(1)(i)                                           │
  │ Unintentional, Good Faith Acquisition/Access by Workforce Member       │
  │ • Must be unintentional and in good faith                              │
  │ • Must be within scope of authority                                    │
  │ • Must result in no further impermissible use or disclosure            │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
  ┌───────────────────────────────────▼────────────────────────────────────┐
  │ Exception 2: § 164.402(1)(ii)                                          │
  │ Inadvertent Intra-Entity Disclosure Between Authorized Persons         │
  │ • Discloser is authorized to access PHI                                │
  │ • Recipient is authorized to access PHI at same CE / BA / OHCA         │
  │ • Must result in no further impermissible use or disclosure            │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
  ┌───────────────────────────────────▼────────────────────────────────────┐
  │ Exception 3: § 164.402(1)(iii)                                         │
  │ Impossibility of Data Retention by Unauthorized Recipient              │
  │ • Good faith belief unauthorized recipient could not have retained data│
  │ • Immediate retrieval, unopened sealed envelopes, or physical return   │
  └────────────────────────────────────────────────────────────────────────┘

1. Exception 1: Unintentional, Good Faith Acquisition or Access (§ 164.402(1)(i))

  • Statutory Language: "Any unintentional, good faith acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or a business associate, if such acquisition, access, or use was made within the scope of authority and results in no further use or disclosure not permitted under subpart E of this part."
  • Legal Breakdown:
    • Must involve a workforce member (employee, volunteer, trainee under § 160.103) or person acting under the entity's direct authority.
    • The initial access must be unintentional and in good faith (e.g., an honest clerical error or accidental keystroke).
    • The person must have general authority to access clinical records in their job role (an IT analyst or nurse, not an unauthorized environmental services worker).
    • The access must result in no further impermissible use or disclosure (e.g., the employee realized the error immediately, did not read details, did not write down data, and did not share it).
  • Clinical Scenario: A surgical nurse attempts to open the electronic health record of patient "John A. Smith" scheduled for appendectomy but mistakenly clicks on "John B. Smith" (who has an identical birth date). Upon realizing the demographic disparity on the screen, the nurse immediately closes the chart without reviewing clinical progress notes and logs the error. Because the nurse had general EHR access authority, acted in good faith, made an unintentional error, and executed no further disclosure, Exception 1 applies. The event is not a breach.

2. Exception 2: Inadvertent Intra-Entity Disclosure (§ 164.402(1)(ii))

  • Statutory Language: "Any inadvertent disclosure by a person who is authorized to access protected health information at a covered entity or business associate to another person authorized to access protected health information at the same covered entity or business associate, or organized health care arrangement in which the covered entity participates, and results in no further use or disclosure not permitted under subpart E of this part."
  • Legal Breakdown:
    • Both the person disclosing and the person receiving must be authorized to access PHI.
    • Both individuals must belong to the same covered entity, business associate, or Organized Health Care Arrangement (OHCA).
    • The disclosure must be inadvertent (accidental misrouting, such as sending an internal email to Dr. Robert Jones in Cardiology instead of Dr. Robert Jones in Oncology).
    • The recipient must execute no further impermissible use or disclosure (e.g., deleting the email upon recognizing the misdirection).
  • Clinical Scenario: A hospital HIM coding specialist mistakenly routes an operative report regarding a pediatric psychiatric inpatient to an orthopedic surgeon employed by the same hospital system. The orthopedic surgeon has active clinical privileges and general HIPAA access authority within the institution. The surgeon immediately replies, "Wrong patient routed to my inbox; I have permanently deleted this message," and takes no further action. Because both individuals were authorized workforce members within the same covered entity, the disclosure was inadvertent, and no further disclosure occurred, Exception 2 applies. The event is not a breach.

3. Exception 3: Impossibility of Data Retention (§ 164.402(1)(iii))

  • Statutory Language: "Any disclosure of protected health information where a covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information."
  • Legal Breakdown:
    • The recipient can be an unauthorized third party (unlike Exceptions 1 and 2, which require workforce or intra-entity status).
    • The covered entity or business associate must hold a good faith belief that the recipient could not reasonably have retained or memorized the information.
    • Evaluated based on physical circumstances: exposure duration, document containment, physical sealed containers, or immediate physical interception.
  • Clinical Scenario: A clinic discharge receptionist hands an envelope containing medical instructions for Patient X to Patient Y. The envelope is completely sealed. Before Patient Y opens the envelope or leaves the registration desk, the receptionist realizes the mistake, immediately says, "Pardon me, I handed you the wrong envelope," takes the sealed envelope back, verifies that the tamper-evident adhesive seal is unbroken, and hands Patient Y the correct envelope. Because the unauthorized recipient never opened the envelope and could not have retained or viewed the clinical information inside, Exception 3 applies. The event is not a breach.

Comparison of Statutory Breach Exceptions

Statutory ExceptionCitationPermitted RecipientRequired Intent / StateKey Disqualifiers (Breach Presumed)
1. Unintentional Good Faith Access45 CFR § 164.402(1)(i)Workforce member with general PHI access authorityUnintentional error; good faith beliefIntentional snooping (curiosity); employee lacks general system access rights; data subsequently copied or shared
2. Inadvertent Intra-Entity Disclosure45 CFR § 164.402(1)(ii)Authorized person at same CE, BA, or participating OHCAInadvertent misdirectionRecipient is at an unrelated covered entity (e.g., independent community hospital); recipient further disseminates data
3. Impossibility of Data Retention45 CFR § 164.402(1)(iii)Any person (internal or external third party)Good faith belief recipient could not retain infoRecipient had opportunity to read, photocopy, photograph, or memorize the data before recovery

CHPS Exam Tips and Common Candidate Traps

[!TIP] Exam Tip: Same Covered Entity vs. Different Covered Entity Pay meticulous attention to the recipient's institutional affiliation in exam scenarios testing Exception 2 (§ 164.402(1)(ii)). If a clerk accidentally faxes or emails PHI to a physician at the same hospital, Exception 2 can apply. However, if the clerk accidentally faxes PHI to a physician at an unaffiliated hospital across town, Exception 2 CANNOT apply because the recipient is not at the same covered entity, business associate, or OHCA. That incident must proceed immediately to a formal four-factor risk assessment!

[!WARNING] Candidate Trap: Snooping Is Never an Exception Exception 1 requires that the acquisition or access be unintentional and in good faith. When an employee deliberately accesses the electronic chart of an estranged spouse, a celebrity, a coworker, or a neighbor out of curiosity, that access is intentional. It can never qualify under Exception 1, even if the employee claims they only looked for five seconds and told nobody. Intentional snooping is a direct Privacy Rule violation and is legally presumed to be a breach unless rebutted under the four-factor risk assessment.

[!CAUTION] Candidate Trap: Written Attestation Does Not Create Exception 3 If an unauthorized external third party receives unencrypted PHI and reads it, the entity cannot claim Exception 3 simply because the recipient promises they forgot it or signs an attestation that they shredded it. Exception 3 requires that the person "would not reasonably have been able to retain such information" at the time of the event (e.g., an unopened envelope or an immediate physical recovery). Post-disclosure promises and destruction attestations are evaluated under Factor 4 of the Risk Assessment, not as a statutory exception.

Loading diagram...
Federal Breach Notification Rule Statutory Determination Architecture
Test Your Knowledge

A hospital registration clerk is searching the enterprise Master Patient Index (MPI) to locate the medical record of a patient arriving for scheduled cardiac catheterization named 'Robert T. Vance' (DOB: 04/12/1965). The clerk accidentally clicks on the record of 'Robert E. Vance' (DOB: 04/12/1965), who was admitted to the behavioral health unit. Upon noticing the different middle initial on the demographic banner, the clerk immediately closes the record without scrolling into the clinical notes, notifies the department supervisor, and logs the incident. How should the Privacy Officer classify this incident under 45 CFR § 164.402?

A
B
C
D
Test Your Knowledge

An encrypted USB flash drive containing exported diagnostic radiology reports for 1,200 oncology patients is misplaced by an attending radiologist during an inter-hospital commute. The drive was encrypted using Advanced Encryption Standard (AES) with a 256-bit key in strict compliance with NIST SP 800-111. The radiologist confirms that the complex cryptographic passkey was stored exclusively in an enterprise password vault on the hospital's secure server and was neither written down nor attached to the USB drive. What is the legal status of this incident under the HITECH Act Breach Notification Rule?

A
B
C
D
Test Your Knowledge

An emergency department triage nurse hands a sealed, opaque discharge envelope containing patient instructions, prescriptions, and lab results for Patient A to Patient B in the waiting room. Before Patient B can open the envelope or stand up, the nurse realizes the clerical error, immediately approaches Patient B, explains the mistake, and takes back the envelope. The nurse inspects the envelope and confirms that the tamper-evident seal was completely intact and undisturbed. Why does this incident qualify as an exception to the definition of a breach under 45 CFR § 164.402?

A
B
C
D