Definitions

42 U.S. Code § 17921. Definitions

In this subchapter, except as specified otherwise:
(1) Breach
(A) In general
The term “breach” means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B) ExceptionsThe term “breach” does not include—
(i) any unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if—
(I)
such acquisition, access, or use was made in good faith and within the course and scope of the employment or other professional relationship of such employee or individual, respectively, with the covered entity or business associate; and
(II)
such information is not further acquired, accessed, used, or disclosed by any person; or
(ii)
any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at [1] same facility; and
(iii)
any such information received as a result of such disclosure is not further acquired, accessed, used, or disclosed without authorization by any person.
This document is only available to subscribers. Please log in or purchase access.