HHS OCR HIPAA FAQ 206

Is a covered entity required to prevent any incidental use or disclosure of protected health information?

Length: 50 wordsOfficial source
No. The HIPAA Privacy Rule does not require that all risk of incidental use or disclosure be eliminated to satisfy its standards. Rather, the Rule requires only that covered entities implement reasonable safeguards to limit incidental uses or disclosures. See 45 CFR 164.530 (c)(2). Date Created: 12/19/2002 Last Updated: 03/14/2006
HHS OCR HIPAA FAQ 206: Is a covered entity required to prevent any incidental use or disclosure of protected health information? | Justis AI