HIPAA Breach Notification Exceptions

Several years ago, the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS), updated the HIPAA Rules with…

Read More

Jim Hook, MPH

By Jim Hook, MPH | April 3, 2025

Clear glass cubes and one green one - representing hipaa breach notification exceptions.

Several years ago, the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS), updated the HIPAA Rules with the addition of the Breach Notification Rule. Much of the Breach Notification Rule addressed the breach notification requirements Covered Entities (CEs) and Business Associates (BAs) must comply with when they have confirmed a reportable breach of protected health information (PHI). But the new Rule also contained definitions of three exceptions to the definition of a “breach”

Understanding the Three Exceptions to the HIPAA Breach Notification Rule

If a disclosure does not meet the definition of a HIPAA breach, then the other provisions of the Breach Notification Rule, such as the requirement to notify affected individuals, HHS, or State Attorneys General, do not apply. These exceptions provide a safeguard for healthcare providers and business associates, ensuring that unintentional or low-risk disclosures do not result in unnecessary administrative burdens. Understanding these three exceptions is crucial for maintaining HIPAA compliance and properly assessing whether a disclosure requires notification.

Let’s look at the three definitions described in the Rule.

Exception No. 1 – Unintentional acquisition by Workforce members

Exception No. 1: surprised healthcare worker at a screen

The definition of the first exception goes like this:

“Unintentional acquisition, access, or use of protected health information by a workforce member or a person acting under the authority of a CE or BA, if such acquisition, access, or use was made in good faith and within the scope of the person’s authority. The information cannot be further used or disclosed in a manner not permitted by the Privacy Rule.

There are five components to this definition:

  1. Unintentional means not by intention or design.
  2. The person accessing the PHI must be a workforce member. Workforce means employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid by the covered entity or business associate. In some states, individuals like physicians or allied health practitioners or other members of an organized medical staff may not be employees of an institution like a hospital. Yet, for this purpose, they would be considered workforce members, subject to the HIPAA Privacy Rule with respect to PHI they encounter as part of their duties.
  3. Good faith means sincere conduct free from malice or a desire to defraud others.
  4. Scope of authority means the range of authority granted by a CE or BA to act on behalf of that entity.
  5. Information cannot be further used or disclosed means the person receiving the information cannot further disclose it except in accordance with other methods for disclosing PHI.

Unintentional access to PHI happens all the time. For instance, a workforce member is looking up a patient medical record, and chooses the wrong patient on the screen. Most of the time, employees do not spend a lot of time perusing medical records they do not need for a specific task, so there is no question about not defining this accidental disclosure as a breach. But occasionally, workforce members do look up medical records or other records with PHI when they are not acting with a good faith belief. Employee snooping is endemic at healthcare providers using electronic medical records.

Exception No. 2 – Inadvertent Disclosure of PHI

Exception No. 2: document being handed over

The definition of the second exception goes like this:

“Inadvertent disclosure of protected health information by a person authorized to access PHI at a CE or BA to another person authorized to access PHI at the CE or BA, or at an organized health care arrangement in which the covered entity participates.  The information cannot be further used or disclosed in a manner not permitted by the Privacy Rule.”

There are three components to this definition:

  1. Inadvertent means without knowledge or intent. It also has the connotation of a mistake.
  2. Person authorized to access PHI at the CE or BA means an authorized person who accesses PHI, based on their status as a workforce member or independent contractor.
  3. An Organized Healthcare Arrangement (OHCA) means a clinically integrated care setting in which individuals typically receive health care from more than one health care provider. It also means an organized system of health care in which more than one covered entity participates, and in which the participating covered entities hold themselves out as participating in joint activities such as utilization review, quality improvement, or payment activities. An example would be a hospital with associated (but not owned) medical groups that utilize a community electronic health record system to support their respective healthcare operations.

Inadvertent and accidental are pretty close in terms of meaning. The distinction between these two exceptions is the populations described as sharing or receiving PHI. The first exception addresses disclosures by workforce members with the authority to disclose PHI. The second exception applies to individuals with access to PHI disclosing it to any other person at the CE or BA, or to someone who is part of the organizations making up an organized healthcare arrangement.

Exception No. 3 – Good Faith Belief that Information was not able to be retained

The definition of the third exception goes like this:

Exception No. 3: organized filing system

“If the covered entity or business associate has a good faith belief that the unauthorized person to whom the impermissible disclosure was made, would not have been able to retain the information.”

There are two major components to this definition.

  1. Good faith means sincere conduct free from malice or a desire to defraud others.
  2. “Would not have been able to retain the information” means the unauthorized person does not have the capacity or other means to retain the PHI involved.

The first two exceptions may be easy to analyze and determine if the use or disclosure met the definition and the exception applies. However, it is highly advisable to conduct a risk assessment when trying to decide if the third exception applies. For instance, it is not uncommon for test results or imaging study reports to be sent by mail or by email to patients. Then someone calls to report they received PHI about another person, and agrees to return or destroy the information. Can covered entities rely on the person reporting the receipt of another patient’s PHI to return or destroy the information? This would be central to reach the risk assessment conclusion that there is a low probability PHI was compromised based on sending it to the wrong person.

In any event, it is important to have an effective reporting and logging system for all reports of impermissible use or disclosure of PHI. The OCR only investigates a small number of the thousands of breach notifications it receives each calendar year. It usually looks into situations where there has been a breach involving hundreds or thousands of records, or when the same complaint about covered entities has been received from affected individuals. BUT, when the OCR comes to investigate, they don’t just focus on the complaint or self-reported breach notification. They perform a top-to-bottom review of all aspects of HIPAA compliance at the regulated entity. This includes the policies and procedures of the entity or business associate, business associate agreements, workforce member training and records of all reports and disposition of HIPAA breaches or complaints.

There is just no substitute for having a comprehensive HIPAA compliance program, and today, you can even get a reduction in penalties if you are found to have introduced recognized security practices in your organization.