A breach is the acquisition, access, use or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI, per 164.402. Excluded: unintentional acquisition, access or use by a workforce member acting in good faith and within the scope of authority, not resulting in further impermissible use or disclosure; inadvertent disclosure between persons similarly authorized to access PHI at the same covered entity, business associate or organized health care arrangement, again with no further impermissible use or disclosure; and a disclosure where the covered entity or business associate has a good faith belief the unauthorized recipient could not reasonably have retained the information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.