EstatePass

HEALTH PROVISIONS · 5 MIN READ

HIPAA Privacy, Security, and Breach Notification

The HIPAA Privacy Rule governs when protected health information (PHI) may be used or disclosed. The default is simple: uses and disclosures beyond treatment, payment, and health care operations require the individual's written authorization. But the rule carves out permitted disclosures that need no authorization — categories that include disclosures required by law, public health reporting and surveillance, abuse and neglect reports, health oversight, judicial proceedings, law enforcement, organ donation, approved research, serious threats to health or safety, specialized government functions, and workers' compensation. Data can also escape the rule entirely by de-identification, accomplished two ways: the Safe Harbor method, which strips 18 categories of identifiers (names, geographic units smaller than a state, dates other than year, contact information, SSNs, record and account numbers, biometrics, full-face photos, and more — with one exception allowing the first three digits of a ZIP code if that ZIP3 area holds more than 20,000 people), or the Expert Determination method, where a qualified statistician documents a very small re-identification risk. A middle path, the limited data set, keeps some data elements but requires a data use agreement. The Security Rule requires administrative, physical, and technical safeguards for electronic PHI. The HITECH-era Breach Notification Rule then flipped the burden of proof on incidents: any impermissible use or disclosure of unsecured PHI is presumed a reportable breach unless the covered entity documents a low probability that the PHI was compromised, using a four-factor risk assessment — the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and how well the risk was mitigated. This replaced the older, softer 'significant risk of harm' standard. Enforcement runs through HHS's Office for Civil Rights, which audits covered entities and applies tiered civil penalties that scale with culpability — from lack of knowledge, through reasonable cause, up to willful neglect, with the harshest tier reserved for uncorrected willful neglect.

Key rules

Beyond treatment, payment, and operations, disclosure needs written authorization.

The listed public-interest categories — public health, oversight, law enforcement, workers' compensation, and the rest — are the exceptions that operate without the patient's permission.

Why the exam cares: Exam items present a disclosure scenario and ask whether authorization was required — public health reporting is the classic 'no' answer.

Safe Harbor de-identification removes 18 identifier categories.

Everything from names and small geographic units to device identifiers and full-face photos must go; the alternative is a documented expert determination of very small re-identification risk.

Why the exam cares: The exam tests both the count (18) and the notable exception for 3-digit ZIP codes.

ZIP3 may remain only when the area contains more than 20,000 people.

Under Safe Harbor, the first three ZIP digits survive if the combined geographic unit exceeds 20,000 residents; otherwise they become 000.

Why the exam cares: This precise threshold is a favorite hard-question detail on de-identification.

Impermissible uses of unsecured PHI are PRESUMED breaches.

The entity escapes notification only by documenting low probability of compromise via the four factors: nature/extent of the PHI, recipient, actual acquisition or viewing, and mitigation.

Why the exam cares: The shift from a harm threshold to a compromise presumption is the tested HITECH change.

Penalties tier by culpability, topping out at willful neglect uncorrected.

OCR's civil money penalty tiers escalate from unknowing violations through reasonable cause to willful neglect, corrected and uncorrected.

Why the exam cares: Ranking culpability levels — and knowing willful neglect draws the maximum — is how penalty questions are framed.

Numbers to memorize

  • 18 — identifier categories that Safe Harbor de-identification must remove
  • 20,000 people — minimum ZIP3 population for retaining the first three ZIP digits
  • 4 factors — breach risk assessment: PHI nature/extent, recipient, acquisition/viewing, mitigation
  • 3 safeguard families — administrative, physical, and technical, under the Security Rule

Common traps

  • Requiring patient authorization for public health reporting — disease surveillance and the other listed categories are permitted disclosures without authorization.
  • Applying the old 'significant risk of harm' test to breaches — the modern rule presumes a breach and demands a documented low-probability-of-compromise analysis to rebut it.
  • Assuming any truncated data is de-identified — Safe Harbor requires removing all 18 identifier categories, and the ZIP3 exception works only above the 20,000-person threshold.
  • Confusing a limited data set with de-identified data — the limited data set retains identifiers and therefore requires a data use agreement.

When a HIPAA scenario appears, ask three questions in order — is it PHI, is the disclosure in a permitted category, and if it leaked, can a four-factor analysis rebut the breach presumption?

Test it before the exam does

Our L&H bank drills Health Provisions with AI-explained answers. 20 questions free, no signup.

Taking the L&H exam in your state?

Studying for the Life & Health insurance exam? Track every lesson free — progress syncs with the app.

Start free