supernav-iconDrataverse - June 22 | Drata’s user and compliance summit
Drata Wordmark Black
  • Solutions
    • Platform
      • Startup
      • Scale
      • Audit Hub
      • Trust Center
      • Risk Management
      • Open API
      • Integrations
    • Frameworks
      • SOC 2
      • ISO 27001
      • HIPAA
      • GDPR
      • Custom Frameworks
      • All Frameworks
    • SOC 2 Compliance: A Beginner's Guide
      Access the Guide
      SOC 2 Guide
  • Resources
    • Resources
      • Blog
      • Drata Events
      • Webinars
      • Reports
      • Compliance Glossary
      • Community
      • API Documentation
    • June 22: Attend Drata's Inaugural User and Compliance Summit
      Register
      Attend Drata's Inaugural User and Compliance Summit
  • Auditors
  • Customers
  • Company
    • Company
      • Careers
      • Auditors
      • Partners
      • Press
      • Security
      • Contact Us
    • Drata Named One of the Best Workplaces in Technology
      Read More
      Drata Linkedin Global Nav
  • Sign In
  • Get Started
  • Sign In
  • Get Started
HomeCompliance GlossaryWhat is a HIPAA Breach?

What is a HIPAA Breach?

A HIPAA breach is defined as the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted by HIPAA regulations, which compromises the security or privacy of the PHI. Impermissible use or disclosure of protected health information is presumed to be a breach unless it can be shown that the probability of protected health information having been compromised is low, based on a multifactor risk assessment. The risk assessment should review the nature and extent of the PHI involved; to whom the disclosure of PHI was made; whether the PHI was in fact acquired or viewed; and the extent to which the risk to the PHI was mitigated, among other elements.


In the event of a breach of unsecured PHI, the HIPAA Breach Notification Rule requires that covered entities communicate notification of the breach to any affected individuals, the U.S. Department of Health & Human Services, and in some cases, the media.


HIPAA compliance is required of organizations and employees who work in or with the healthcare industry, or who have access to protected health information. A covered entity or business associate that fails to adhere to one or more of the HIPAA Rules is in violation of HIPAA; organizations that violate the provisions of the HIPAA Rules may be penalized. Penalties for HIPAA breaches are strict and can significantly impact an organization’s finances and reputation.

Join the thousands of companies that trust Drata

See All Case Studies
Abnormal Logo
Airbase
BambooHR Logo
BigID Logo
Clearbit Logo
Clearco Logo
Lemonade Logo
Fivetran Logo
Notion Logo
Vercel Logo
Wordpress VIP
Calendly Logo

View Drata Glossary

Learn more about other compliance and cybersecurity concepts in our glossary.

Read More
Drata Wordmark White

Drata is a security and compliance automation platform that continuously monitors and collects evidence of a company’s security controls, while streamlining workflows to ensure audit-readiness.

Solutions

StartupScaleEnhanceDrata PlatformIntegrations
Frameworks
SOC 2ISO 27001HIPAAGDPRCustom FrameworksAll Frameworks
Resources
BlogDrata EventsWebinarsReportsCompliance GlossaryCommunityAPI Documentation
Company
Careers
HIRING
CustomersAuditorsPartnersPressContact Us
Trust
Security and ComplianceTrust CenterSystem Status
Become a Trusted Newsletter Insider

The latest security and compliance news, delivered.

Secured DesktopSecured Desktop

© 2023 Drata Inc. All rights reserved.

Privacy PolicyGDPRTermsCookiesDisclosure PolicySub-processorsData Processing Addendum