- prev
- next
42 USC § 17921 - Definitions
In this subchapter, except as specified otherwise:
(1)
Breach
(A)
In general
The term “breach” means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B)
Exceptions
The term “breach” does not include—
(i)
any unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if—
(ii)
any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at
[1]
same facility; and
(2)
Business associate
The term “business associate” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(3)
Covered entity
The term “covered entity” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(4)
Disclose
The terms “disclose” and “disclosure” have the meaning given the term “disclosure” in section
160.103 of title 45, Code of Federal Regulations.
(5)
Electronic health record
The term “electronic health record” means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.
(6)
Health care operations
The term “health care operation” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(7)
Health care provider
The term “health care provider” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(8)
Health plan
The term “health plan” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(10)
Payment
The term “payment” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(12)
Protected health information
The term “protected health information” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(14)
Security
The term “security” has the meaning given such term in section
164.304 of title 45, Code of Federal Regulations.
(15)
State
The term “State” means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
(16)
Treatment
The term “treatment” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(17)
Use
The term “use” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(18)
Vendor of personal health records
The term “vendor of personal health records” means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.
[1] So in original. Probably should be followed by “the”.
[2] See References in Text note below.
prev | next
In this subchapter, except as specified otherwise:
(1)
Breach
(A)
In general
The term “breach” means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B)
Exceptions
The term “breach” does not include—
(i)
any unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if—
(ii)
any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at
[1]
same facility; and
(2)
Business associate
The term “business associate” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(3)
Covered entity
The term “covered entity” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(4)
Disclose
The terms “disclose” and “disclosure” have the meaning given the term “disclosure” in section
160.103 of title 45, Code of Federal Regulations.
(5)
Electronic health record
The term “electronic health record” means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.
(6)
Health care operations
The term “health care operation” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(7)
Health care provider
The term “health care provider” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(8)
Health plan
The term “health plan” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(10)
Payment
The term “payment” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(12)
Protected health information
The term “protected health information” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(14)
Security
The term “security” has the meaning given such term in section
164.304 of title 45, Code of Federal Regulations.
(15)
State
The term “State” means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
(16)
Treatment
The term “treatment” has the meaning given such term in section
164.501 of title 45, Code of Federal Regulations.
(17)
Use
The term “use” has the meaning given such term in section
160.103 of title 45, Code of Federal Regulations.
(18)
Vendor of personal health records
The term “vendor of personal health records” means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.
[1] So in original. Probably should be followed by “the”.
[2] See References in Text note below.
Source
(Pub. L. 111–5, div. A, title XIII, § 13400,Feb. 17, 2009, 123 Stat. 258.)
References in Text
This subchapter, referred to in text, was in the original “this subtitle”, meaning subtitle D (§ 13400 et seq.) of title XIII of div. A of Pub. L. 111–5, Feb. 17, 2009, 123 Stat. 258, which is classified principally to this subchapter. For complete classification of subtitle D to the Code, see Tables.
Section
13101, referred to in par. (9), means section 13101 of div. A of Pub. L. 111–5.
The table below lists the classification updates, since Jan. 3, 2012, for this section. Updates to a broader range of sections may be found at the update page for containing chapter, title, etc.
The most recent Classification Table update that we have noticed was Friday, May 3, 2013
An empty table indicates that we see no relevant changes listed in the classification tables. If you suspect that our system may be missing something, please double-check with the Office of the Law Revision Counsel.
| 42 USC | Description of Change | Session Year | Public Law | Statutes at Large |
|---|
LII has no control over and does not endorse any external Internet site that contains links to or references LII.