A breach under HIPAA occurs when protected health information (PHI) is accessed, used, or disclosed in a way that compromises the privacy or security of that information.
Common Breach Examples:
-
Sending patient records to the wrong email or fax number
-
A stolen or lost laptop or USB drive containing PHI
-
Discussing a patient’s condition in a public area
-
Unauthorized staff member accessing a celebrity’s record
-
Posting a patient photo on social media without consent
Not all incidents are breaches, but any unauthorized use or disclosure must be evaluated to determine if a breach has occurred.
Key Test:
Was the PHI accessed, acquired, used, or disclosed in a way that presents a risk to the individual?
If the answer is yes, it’s likely a breach.