<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="cfr.xsl"?>
<CFRGRANULE xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="CFRMergedXML.xsd">
    <FDSYS>
        <CFRTITLE>45</CFRTITLE>
        <CFRTITLETEXT>Public Welfare</CFRTITLETEXT>
        <VOL>2</VOL>
        <DATE>2025-10-01</DATE>
        <COVERONLY>false</COVERONLY>
        <ORIGINALDATE>2025-10-01</ORIGINALDATE>
        <ANCESTORS>
            <PARENT HEADING="Title 45" SEQ="4">Public Welfare</PARENT>
            <PARENT HEADING="SUBTITLE A" SEQ="3">Department of Health and Human Services</PARENT>
            <PARENT HEADING="SUBCHAPTER C" SEQ="2">ADMINISTRATIVE DATA STANDARDS AND RELATED REQUIREMENTS</PARENT>
            <PARENT HEADING="PART 164" SEQ="1">SECURITY AND PRIVACY</PARENT>
            <PARENT HEADING="Subpart D" SEQ="0">Notification in the Case of Breach of Unsecured Protected Health Information</PARENT>
        </ANCESTORS>
    </FDSYS>
    <SECTION>
        <SECTNO>§ 164.402</SECTNO>
        <SUBJECT>Definitions.</SUBJECT>
        <P>As used in this subpart, the following terms have the following meanings:</P>
        <P>
            <E T="03">Breach</E>
             means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information.
        </P>
        <P>(1) Breach excludes:</P>
        <P>(i) Any unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or a business associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under subpart E of this part.</P>
        <P>
            (ii) Any inadvertent disclosure by a person who is authorized to access protected health information at a covered entity or business associate to another person authorized to access protected 
            <PRTPAGE P="683"/>
            health information at the same covered entity or business associate, or organized health care arrangement in which the covered entity participates, and the information received as a result of such disclosure is not further used or disclosed in a manner not permitted under subpart E of this part.
        </P>
        <P>(iii) A disclosure of protected health information where a covered entity or business associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.</P>
        <P>(2) Except as provided in paragraph (1) of this definition, an acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors:</P>
        <P>(i) The nature and extent of the protected health information involved, including the types of identifiers and the likelihood of re-identification;</P>
        <P>(ii) The unauthorized person who used the protected health information or to whom the disclosure was made;</P>
        <P>(iii) Whether the protected health information was actually acquired or viewed; and</P>
        <P>(iv) The extent to which the risk to the protected health information has been mitigated.</P>
        <P>
            <E T="03">Unsecured protected health information</E>
             means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of Public Law 111-5.
        </P>
        <CITA>[78 FR 5695, Jan. 25, 2013]</CITA>
    </SECTION>
</CFRGRANULE>
