What is the HIPAA Enforcement Rule?
The HIPAA Enforcement Rule is administered by the U.S. Department of Health and Human Services (HHS). The Rule determines how the Office for Civil...
3 min read
Tshedimoso Makhene
February 14, 2024
While the terms may be related, a security incident is an event that compromises the integrity, confidentiality, or availability of an information asset. On the other hand, a data breach is a prohibited use or disclosure under the HIPAA Privacy Rule that compromises the security or privacy of protected health information (PHI).
Misunderstandings can sometimes exist when distinguishing between a HIPAA security incident and the definition of a HIPAA breach. Although they are often interconnected, it is important to note that not all security incidents result in breaches, nor are all breaches caused by security incidents.
Misconceptions surrounding the two terms can arise because their definitions are located in different sections of the Administrative Simplification Regulations. The definition of a HIPAA security incident appears in §164.304 of the Security Rule as: “the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.” However, the definition of HIPAA breach does not appear until §164.402 of the Breach Notification Rule. This is because breaches are events that can compromise PHI, regardless of the media on which PHI is maintained.
According to the U.S. Department of Health and Human Services (HHS), a breach is “an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information.”
Therefore, the attempted infiltration of an information system does not necessarily have to be successful before the event qualifies as a HIPAA security incident. Similarly, an impermissible verbal disclosure qualifies as a HIPAA breach even though no security incident has occurred.
See also:
See also: 7 common HIPAA violations you need to avoid
See also: HIPAA Compliant Email: The Definitive Guide
How can healthcare organizations prevent HIPAA incidents and breaches?
Healthcare organizations can implement robust security measures, such as access controls, encryption, employee training, regular risk assessments, incident response plans, and compliance audits, to prevent HIPAA incidents and breaches and safeguard patient information.
What should individuals do if they suspect a HIPAA incident or breach has occurred?
Individuals who suspect a HIPAA incident or breach should report their concerns to the relevant healthcare provider or entity responsible for safeguarding their information. They may also contact the HHS Office for Civil Rights (OCR) to file a complaint.
Go deeper: Filing a HIPAA complaint
The HIPAA Enforcement Rule is administered by the U.S. Department of Health and Human Services (HHS). The Rule determines how the Office for Civil...
The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to protect sensitive patient health information from being...
In the event of a healthcare data breach, organizations must promptly notify affected individuals, the OCR, and, potentially, the media. Following...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.