Four-Factor HIPAA Breach Risk Assessment Example for a Clinic

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Four-Factor HIPAA Breach Risk Assessment Example for a Clinic

Kevin Henry

HIPAA

July 12, 2026

7 minutes read
Share this article
Four-Factor HIPAA Breach Risk Assessment Example for a Clinic

This Four-Factor HIPAA Breach Risk Assessment Example for a Clinic shows you how to analyze an incident step by step, determine the probability of compromise, and decide whether the Breach Notification Rule applies. You will evaluate Protected Health Information (PHI), identify who accessed it, confirm whether it was actually acquired or viewed, and measure how well your Mitigation Strategies reduced risk.

The walkthrough centers on a realistic clinic scenario and folds in practical Incident Response Protocols and HIPAA Compliance Auditing practices so you can document decisions that hold up to scrutiny.

Evaluating Nature and Extent of PHI

What to examine

Start by cataloging exactly what PHI was involved. Sensitivity drives harm potential and the Risk of Re-identification. Names paired with diagnoses, test results, Social Security numbers, or full financial data typically raise risk. Limited elements—such as first name plus appointment date—carry less risk, especially if identifiers are truncated or masked.

  • Data elements: identifiers, clinical details, financial numbers, images.
  • Volume and timeframe: number of records and period covered.
  • Format and protection: plaintext vs. encrypted, redacted vs. full detail.
  • Context: whether the details could enable identity theft or stigma.

Clinic example

A front-desk user emails a scheduling spreadsheet to the wrong recipient. It includes patient names, medical record numbers, appointment dates, and provider names—no diagnoses, SSNs, or insurance IDs. The file is unencrypted. Because direct identifiers are present, re-identification is certain; absence of diagnoses reduces sensitivity but does not negate exposure risk.

Identifying Unauthorized Persons

Who received the PHI matters

Assess the role, obligations, and technical capability of the recipient. Disclosure to a workforce member who is authorized for a similar purpose presents lower risk than disclosure to an external party. A business associate under contract with Incident Response Protocols offers more control than an unknown individual or a public website.

  • Internal but unauthorized workforce member: moderate risk with strong containment options.
  • Business associate with safeguards: lower risk if promptly contained and attested.
  • Third party with no obligations (e.g., personal email, public forum): higher risk of Unauthorized Access and misuse.

Clinic example

The email was sent to a former vendor’s personal Gmail address not covered by a current business associate agreement. That status elevates risk because you cannot rely on contractual safeguards.

Determining Actual Acquisition or Viewing of PHI

Evidence over assumptions

Differentiate “could have accessed” from “did access.” Analyze email delivery logs, read receipts, endpoint forensics, EHR audit logs, and cloud storage access records. Returned mail, bounce messages, unopened envelopes, or a verified secure deletion before opening can reduce the probability that PHI was actually acquired or viewed.

  • If the file was encrypted and the key was not exposed, probability of compromise is low.
  • If the recipient confirms non-access in writing and you verify deletion, risk drops.
  • If logs show download or preview, treat as actual acquisition.

Clinic example

Delivery logs show the message was delivered and opened once. The recipient replied two hours later, acknowledging receipt. This constitutes likely viewing and acquisition.

Assessing Risk Mitigation Measures

Reduce the probability of compromise

Immediate, targeted Mitigation Strategies can materially lower risk. Aim to contain exposure, prevent further disclosure, and remediate root causes. Document timing and effectiveness because the four-factor analysis must reflect conditions after mitigation.

  • Recall the email or revoke shared links; request and verify permanent deletion.
  • Obtain a signed attestation of non-retention and non-disclosure.
  • Remote-wipe devices, rotate passwords, and disable misused accounts.
  • Sanction and retrain workforce; harden DLP, auto-encryption, and address validation.

Clinic example

The clinic contacted the recipient the same day, obtained a written statement that the file was deleted without further sharing, and verified deletion via a brief remote screen share. DLP rules and automatic encryption were enabled that evening, and staff retraining was completed within 48 hours. These steps substantively reduce residual risk.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Applying Breach Assessment to Clinic Settings

Putting the four factors together

Scenario A (likely breach requiring notification): Unencrypted spreadsheet with names and MRNs was emailed to a personal account, opened, and forwarded to another party before you intervened. Factor 1: identifiable PHI; Factor 2: recipient is an uncontrolled third party; Factor 3: access confirmed; Factor 4: mitigation partial and after re-disclosure. Overall probability of compromise remains more than low—treat as a breach.

Scenario B (low probability of compromise): The same spreadsheet was sent, but the recipient confirmed non-access, provided a same-day deletion attestation, and your logs show no download or preview. Factor 1: identifiable PHI; Factor 2: uncontrolled recipient; Factor 3: no viewing; Factor 4: rapid, verified mitigation. Document a reasoned conclusion that the probability of compromise is low.

Operational tips for clinics

  • Use a simple matrix (low, moderate, high) for each factor and record the rationale.
  • Escalate when any single factor trends “high,” especially confirmed viewing or re-disclosure.
  • Align decisions with your Incident Response Protocols to ensure consistent outcomes.

Documenting Assessment Findings

What to record

Good documentation underpins HIPAA Compliance Auditing and defends your decision. Maintain records for at least six years. Capture who discovered the incident, when, the PHI elements, systems involved, the four-factor analysis, mitigation steps with timestamps, final determination, approvals, and any notification content.

Example entry

“On 2026-08-12, front-desk user emailed unencrypted schedule to ex-vendor Gmail. PHI: names, MRNs, appointment dates (no diagnoses or SSNs). Recipient acknowledged receipt; deletion attestation obtained 2026-08-12 16:20. No further sharing evident. DLP and auto-encryption enabled 2026-08-12 19:00; staff retrained 2026-08-14. Conclusion: low probability of compromise; Breach Notification Rule not triggered. Approved by Privacy Officer 2026-08-15.”

Complying with HIPAA Breach Notification Requirements

When notification is required

Under the Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is presumed a HIPAA Breach unless you demonstrate a low probability of compromise based on the four factors. If the probability is not low, notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery.

Who to notify and how

  • Individuals: First-class mail (or email if they agreed). Include what happened, types of PHI involved, steps they can take, your Mitigation Strategies, and contact information.
  • HHS: If 500 or more individuals are affected in a state or jurisdiction, notify HHS without unreasonable delay and within 60 days of discovery. If fewer than 500, log the event and report to HHS within 60 days after the end of the calendar year.
  • Media: If 500+ residents of a state or jurisdiction are affected, provide prominent media notice.
  • Business associates: Must notify the covered entity without unreasonable delay and within 60 days, supplying affected individuals’ identities and relevant facts.

Document the date of discovery, decision logic, and all notices sent. Where permitted, coordinate with law enforcement if notification would impede an investigation.

FAQs

What are the four factors in a HIPAA breach risk assessment?

The factors are: the nature and extent of PHI involved (including sensitivity and Risk of Re-identification), the unauthorized person who used or received the PHI, whether the PHI was actually acquired or viewed, and the extent to which any risk has been mitigated through timely, effective actions.

How do clinics determine if PHI was actually acquired or viewed?

Clinics corroborate with objective evidence such as email and server logs, read receipts, cloud storage access histories, EHR audit trails, endpoint forensics, and recipient attestations. Proof of download, preview, forwarding, or device access indicates acquisition or viewing; verified non-access and secure deletion support a lower probability of compromise.

What mitigation steps are required after a HIPAA breach?

Act immediately to contain and remediate: retrieve or delete exposed data, revoke access, remote-wipe if possible, rotate credentials, monitor for misuse, notify affected parties when required, and implement corrective actions like DLP, encryption, and workforce retraining. Record all steps and timings to support the four-factor analysis and subsequent auditing.

When is a breach notification required under HIPAA?

Notification is required when the incident involves unsecured PHI and your four-factor analysis does not demonstrate a low probability of compromise. In that case, notify individuals without unreasonable delay and within 60 days of discovery, and notify HHS (and, for large incidents, media) according to the thresholds and timelines in the Breach Notification Rule.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles