How to Decide Whether a HIPAA Incident Is a Reportable Breach (Step-by-Step Guide)

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Decide Whether a HIPAA Incident Is a Reportable Breach (Step-by-Step Guide)

Kevin Henry

HIPAA

July 13, 2026

7 minutes read
Share this article
How to Decide Whether a HIPAA Incident Is a Reportable Breach (Step-by-Step Guide)

Determining whether a HIPAA incident is a reportable breach requires a disciplined, evidence‑based approach anchored in the HIPAA Breach Notification Rule. Use this step‑by‑step guide to apply the Four-Factor Risk Assessment, evaluate unauthorized disclosure scenarios, and make defensible decisions that meet incident reporting requirements.

Identify the Nature of the Incident

Confirm whether PHI was involved

Start by verifying that the data at issue is Protected Health Information (PHI). De-identified data is not PHI; limited data sets are PHI but typically carry less risk. Confirm the data source (EHR, billing, patient portal), the transmission method (email, fax, API), and whether disclosure or use was impermissible under HIPAA’s Privacy Rule.

Classify the event type

  • Unauthorized disclosure (e.g., wrong recipient, misdirected fax, CC error)
  • Impermissible use (e.g., snooping by staff, accessing outside role-based need)
  • Security incident (e.g., lost device, ransomware, misconfiguration exposing PHI)

Screen for breach rule exceptions

  • Unintentional, good‑faith access or use by an authorized workforce member within scope, with no further impermissible use
  • Inadvertent disclosure between two authorized persons within the same covered entity/business associate, with no further impermissible use
  • Good‑faith belief the unauthorized recipient could not reasonably retain the information (e.g., sealed and returned mail, secure message auto‑deleted before view)

If an exception applies, document the rationale and close as a non‑breach incident. Otherwise, proceed with the Four-Factor Risk Assessment.

Assess the Type of PHI Involved

Measure sensitivity and identifiability

Detail the data elements exposed. High‑risk elements include Social Security numbers, driver’s license numbers, financial account data, full clinical histories, diagnostic codes linked to stigmatizing conditions, substance use, or reproductive health details. Lower‑risk content might include limited demographics with minimal clinical context.

Consider format, volume, and protection state

  • Format: paper, electronic, image, audio, or oral disclosure
  • Volume: number of records, time span, and data granularity
  • Protection: encrypted to strong standards, password‑protected, tokenized, redacted

Encryption can materially reduce breach risk if the key was not compromised. Conversely, raw spreadsheets, plaintext emails, or open cloud buckets elevate risk.

Evaluate the Unauthorized Recipient

Assess who received or could access the PHI

Risk is lower if the recipient is another covered entity or business associate bound by HIPAA and they provide credible assurances of no retention or further use. Risk rises when recipients are unknown, members of the public, threat actors, the media, or parties with incentives to misuse data.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Gauge recipient intent and capability

  • Benign recipient (e.g., patient’s spouse mistakenly copied) who cooperates in deletion/return
  • Skilled recipient (e.g., security researcher vs. criminal actor)
  • Broad exposure (e.g., public website indexing) vs. contained exposure (e.g., bounced email)

Determine the Actual Access or Acquisition

Establish whether PHI was viewed, acquired, or exfiltrated

Use audit logs, DLP alerts, SIEM events, mailbox read receipts, and forensic artifacts to determine if PHI was actually accessed or could be reasonably retained. Evidence of download, forwarding, screen capture, or prolonged exposure indicates acquisition.

Differentiate potential from confirmed access

Potential exposure without indicators of viewing (e.g., misaddressed email that immediately bounced) carries lower risk than confirmed access (e.g., file opened, credentials used by unknown IP). When ambiguity remains, weigh likelihood using objective telemetry and documented attestations.

Assess Mitigation Efforts

Act quickly to contain and reduce risk

  • Recall or delete messages, disable shared links, revoke tokens, rotate keys, and reset passwords
  • Remote‑wipe lost devices, pull exposed content offline, and harden access controls
  • Obtain recipient attestations of non‑use/non‑retention and request written confirmation of destruction

Record concrete outcomes

Document the timing and effectiveness of each mitigation step. Verified destruction, rapid containment, and credible attestations can support a “low probability of compromise” finding under the Four-Factor Risk Assessment. Insufficient mitigation favors breach notification.

Apply the Breach Notification Decision Tree

Step-by-step pathway

  • Step 1: Was there an impermissible use or disclosure of PHI? If no, stop—document and close.
  • Step 2: Does a breach rule exception apply? If yes, document exception details and close.
  • Step 3: Conduct the Four-Factor Risk Assessment:
    • Nature and extent of PHI involved
    • Unauthorized recipient
    • Whether PHI was actually acquired or viewed
    • Extent to which the risk has been mitigated
  • Step 4: Decision. If there is not a low probability of compromise, treat as a reportable breach under the HIPAA Breach Notification Rule.

Notification and timing considerations

  • Individuals: without unreasonable delay and no later than 60 calendar days from discovery
  • HHS/OCR: breaches affecting 500+ individuals—within 60 days of discovery; fewer than 500—log and submit within 60 days after the end of the calendar year
  • Media: if 500+ residents of a single state or jurisdiction are affected
  • Business associates: notify the covered entity without unreasonable delay as required by the BAA, typically not later than 60 days from discovery

Always check state incident reporting requirements, which may be stricter or faster than federal timelines, and harmonize your notifications accordingly.

Use the Breach Decision Matrix

Translate analysis into a consistent outcome

  • Low sensitivity + low likelihood of acquisition (e.g., encrypted file, prompt verified deletion): document incident and close; no notification
  • Moderate sensitivity or uncertain acquisition with good mitigation (e.g., limited clinical data, cooperative recipient): consider individual notification; document rationale
  • High sensitivity and/or confirmed acquisition (e.g., SSNs, financials, threat actor access): notify individuals, HHS/OCR, and media if thresholds are met; consider breach risk mitigation such as credit monitoring

Make decisions defensible

Attach your matrix rating, Four-Factor Risk Assessment notes, evidence of mitigation, and leadership/legal approvals to the incident record. A standardized Breach Decision Matrix strengthens governance, improves training, and ensures repeatable outcomes across your compliance team.

Summary

To decide whether a HIPAA incident is a reportable breach, verify PHI involvement, apply the Four-Factor Risk Assessment, evaluate unauthorized disclosure circumstances, and measure mitigation effectiveness. Then use the Breach Notification Decision Tree and a clear Decision Matrix to produce a timely, well‑documented, and defensible outcome.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles