An impermissible use or disclosure of PHI is presumed a breach unless the covered entity or business associate demonstrates, through a documented risk assessment, a low probability that the PHI has been compromised, considering at least the four factors in 164.402: the nature and extent of the PHI involved (including identifiers and re-identification risk); the unauthorized person who used the PHI or to whom it was disclosed; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.