If ePHI is encrypted using approved methods and is acquired by an unauthorized person, is it a reportable breach?
- A.No, properly encrypted ePHI is considered unusable and not a breach requiring notification
- B.Yes, always, because acquisition by an unauthorized person is a breach regardless of encryption status
- C.Only if the encryption key is also compromised, in which case the notification duty falls on the key custodian rather than the covered entity
- D.Only if more than 500 records are involved, the threshold at which the breach definition itself begins to apply
Why A is correct
If ePHI is encrypted per HHS guidance and the encryption key is not compromised, the data is considered unusable and the incident is not a reportable breach.
Know someone studying for HIPAA? Send them this one.