United States Code (Last Updated: May 24, 2014) |
Title 42. THE PUBLIC HEALTH AND WELFARE |
Chapter 156. HEALTH INFORMATION TECHNOLOGY |
SubChapter III. PRIVACY |
§ 17921. Definitions
-
In this subchapter, except as specified otherwise: (1) Breach (A) In general The term “breach” means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B) Exceptions The term “breach” does not include— (i) any unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if— (I) such acquisition, access, or use was made in good faith and within the course and scope of the employment or other professional relationship of such employee or individual, respectively, with the covered entity or business associate; and (II) such information is not further acquired, accessed, used, or disclosed by any person; or (ii) any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at (10) Payment The term “payment” has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
(11) Personal health record The term “personal health record” means an electronic record of PHR identifiable health information (as defined in section 17937(f)(2) of this title) on an individual that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
(12) Protected health information The term “protected health information” has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(13) Secretary The term “Secretary” means the Secretary of Health and Human Services.
(14) Security The term “security” has the meaning given such term in section 164.304 of title 45, Code of Federal Regulations.
(15) State The term “State” means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
(16) Treatment The term “treatment” has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
(17) Use The term “use” has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(18) Vendor of personal health records The term “vendor of personal health records” means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.
References In Text
This subchapter, referred to in text, was in the original “this subtitle”, meaning subtitle D (§ 13400 et seq.) of title XIII of div. A of Pub. L. 111–5,
Section 13101, referred to in par. (9), means section 13101 of div. A of Pub. L. 111–5.