A breach risk assessment is what stands between an impermissible use of protected health information and a notifiable breach. Under the HIPAA Breach Notification Rule the impermissible use or disclosure is presumed to be a breach — the presumption is rebutted only if you demonstrate a low probability that the PHI has been compromised, based on a risk assessment of at least four defined factors.
This guide covers the four factors as the regulation states them, the three exclusions that stop the analysis before it starts, and how to document a decision that survives an OCR review.

Start with the exclusions
Three situations are excluded from the definition of a breach entirely, and checking them first can end the analysis in a paragraph:
- Unintentional acquisition, access or use by a workforce member or person acting under the authority of a covered entity or business associate — provided it was in good faith, within the scope of authority, and does not result in further impermissible use or disclosure.
- Inadvertent disclosure between authorized persons at the same covered entity, business associate or organized health care arrangement — again provided the information is not further used or disclosed impermissibly.
- A good faith belief that the unauthorized recipient would not reasonably have been able to retain the information.
Each carries conditions, and the conditions are where these fail. “A colleague opened the wrong chart” is excluded only if it was good faith, in scope, and went no further. Record which exclusion you relied on and why the conditions were met — an unexplained “not a breach” is the finding.
The four breach risk assessment factors
Where no exclusion applies, a breach risk assessment is required: the impermissible use or disclosure is presumed to be a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment of at least these factors:
| Factor | What to assess |
|---|---|
| 1. Nature and extent of the PHI | The types of identifiers involved and the likelihood of re-identification — plus the sensitivity of the clinical or financial content |
| 2. The unauthorized person | Who used it or received it — another covered entity bound by HIPAA is a different proposition from an unknown recipient |
| 3. Whether the PHI was actually acquired or viewed | Evidence of access, not just opportunity — forensic logs, a returned unopened envelope, a confirmed deletion |
| 4. Extent to which the risk has been mitigated | What you did afterwards — retrieval, attestations of destruction, remote wipe — and how reliable that mitigation is |
“At least” is the operative phrase. The four are a floor, not a checklist; where another factor is material to whether the information was compromised, assess it and say so.
The factor that decides most cases
Factor three. The difference between “a laptop was lost” and “a laptop was lost and forensics show the encrypted volume was never mounted” is the difference between notification and a documented low-probability conclusion. Build the evidence capability before you need it: access logs that record reads rather than only writes, mail-return handling that preserves the envelope, and device management that reports encryption state at the time of loss.
Note that PHI rendered unusable, unreadable or indecipherable to unauthorized persons through encryption meeting the specified standards falls outside the notification obligation altogether. Encryption is not merely a mitigating factor — done properly it removes the question.
Documenting the breach risk assessment
A breach risk assessment is a record you may have to produce years later, and the burden of demonstrating the low probability sits with you. A defensible file contains:
- The facts — what happened, when, discovered how and by whom, and how many individuals are affected.
- The exclusion analysis — which was considered, which applied, and why the conditions were met or not.
- Each factor addressed separately, with the evidence behind the conclusion rather than an assertion.
- The overall conclusion and who reached it, with a date.
- Consequential actions — notification if required, or the corrective action taken if not.
Two habits weaken the file. The first is a conclusion written before the evidence — a template with “low probability” pre-filled. The second is treating small incidents as beneath assessment: the obligation does not scale with headcount, and a pattern of undocumented single-record events is exactly what an audit will find.
Timing, and who tells whom
Notification timing runs from discovery of the incident, not from completion of the breach risk assessment, not from the completion of your assessment, so the assessment has to be prompt rather than leisurely. Business associates notify the covered entity; the covered entity notifies individuals, and the Secretary — immediately for larger incidents, annually for smaller ones — with media notice where the numbers require it. Get the business associate notification timeline into the agreement itself; our guide to the business associate agreement covers what that contract has to carry.
Frequently asked questions
Is every impermissible disclosure a breach?
It is presumed to be one unless an exclusion applies or a risk assessment demonstrates a low probability that the PHI was compromised.
What are the four factors?
The nature and extent of the PHI including identifiers and re-identification likelihood; the unauthorized person involved; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated.
Does encryption remove the obligation?
Where PHI is rendered unusable, unreadable or indecipherable to unauthorized persons by methods meeting the specified standards, it is not unsecured PHI and notification does not arise.
Who performs the assessment?
The covered entity or business associate holding the burden of demonstration — in practice privacy and security together, with legal involved where the conclusion is finely balanced.
How long do we keep it?
With the rest of your HIPAA documentation, for the required retention period. The record is the only thing that proves a decision not to notify was reasoned.
Where this leaves you
Run the breach risk assessment in the regulation’s own order: exclusions first, then the four factors, each with evidence rather than assertion. Invest in the capability that answers factor three, because “we cannot tell whether it was viewed” always resolves against you. Write the conclusion after the evidence, keep the file, and remember that the burden of demonstrating low probability is yours — a decision not to notify is only as good as the record behind it.
References
- 45 CFR § 164.402 — the definition of breach, the exclusions and the four risk assessment factors.
- HHS — Breach Notification Rule — notification timing, thresholds and reporting routes.
More on HIPAA
- The breach risk assessment — you are here
- The HIPAA security risk analysis
- The business associate agreement
- The HIPAA safeguards
Assessment templates, notification letters and the incident log are in the HIPAA Compliance Toolkit, or start with the free ISO templates.