HIPAA Breach Notification Rule
Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule

HIPAA Breach Notification Rule 164.402risk: Low probability of compromise risk assessment

An impermissible use or disclosure of PHI is presumed a breach unless the covered entity or business associate demonstrates, through a documented risk assessment, a low probability that the PHI has been compromised, considering at least the four factors in 164.402: the nature and extent of the PHI involved (including identifiers and re-identification risk); the unauthorized person who used the PHI or to whom it was disclosed; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated.

Maintained by Gerard Blokdyk

Other controls in Breach definition and risk assessment (164.400, 164.402) – HIPAA Breach Notification Rule

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.