2015 US Code
Title 42 - The Public Health and Welfare (Sections 1 - 18445)
Chapter 156 - Health Information Technology (Sections 17901 - 17953)
Subchapter III - Privacy (Sections 17921 - 17953)
Sec. 17921 - Definitions
Publication Title | United States Code, 2012 Edition, Supplement 3, Title 42 - THE PUBLIC HEALTH AND WELFARE |
Category | Bills and Statutes |
Collection | United States Code |
SuDoc Class Number | Y 1.2/5: |
Contained Within | Title 42 - THE PUBLIC HEALTH AND WELFARE CHAPTER 156 - HEALTH INFORMATION TECHNOLOGY SUBCHAPTER III - PRIVACY Sec. 17921 - Definitions |
Contains | section 17921 |
Date | 2015 |
Laws In Effect As Of Date | January 3, 2016 |
Positive Law | No |
Disposition | standard |
Source Credit | Pub. L. 111-5, div. A, title XIII, §13400, Feb. 17, 2009, 123 Stat. 258. |
Statutes at Large References | 123 Stat. 258 |
Public and Private Laws | Public Law 111-5 |
Download PDF
In this subchapter, except as specified otherwise:
(1) Breach(A) In generalThe term "breach" means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B) ExceptionsThe term "breach" does not include—
(i) any unintentional acquisition, access, or use of protected health information by an employee or individual acting under the authority of a covered entity or business associate if—
(I) such acquisition, access, or use was made in good faith and within the course and scope of the employment or other professional relationship of such employee or individual, respectively, with the covered entity or business associate; and
(II) such information is not further acquired, accessed, used, or disclosed by any person; or
(ii) any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at 1 same facility; and
(iii) any such information received as a result of such disclosure is not further acquired, accessed, used, or disclosed without authorization by any person.
(2) Business associateThe term "business associate" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(3) Covered entityThe term "covered entity" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(4) DiscloseThe terms "disclose" and "disclosure" have the meaning given the term "disclosure" in section 160.103 of title 45, Code of Federal Regulations.
(5) Electronic health recordThe term "electronic health record" means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.
(6) Health care operationsThe term "health care operation" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
(7) Health care providerThe term "health care provider" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(8) Health planThe term "health plan" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(9) National CoordinatorThe term "National Coordinator" means the head of the Office of the National Coordinator for Health Information Technology established under section 300jj–11(a) of this title, as added by section 13101.2
(10) PaymentThe term "payment" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
(11) Personal health recordThe term "personal health record" means an electronic record of PHR identifiable health information (as defined in section 17937(f)(2) of this title) on an individual that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
(12) Protected health informationThe term "protected health information" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(13) SecretaryThe term "Secretary" means the Secretary of Health and Human Services.
(14) SecurityThe term "security" has the meaning given such term in section 164.304 of title 45, Code of Federal Regulations.
(15) StateThe term "State" means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
(16) TreatmentThe term "treatment" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
(17) UseThe term "use" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
(18) Vendor of personal health recordsThe term "vendor of personal health records" means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.
(Pub. L. 111–5, div. A, title XIII, §13400, Feb. 17, 2009, 123 Stat. 258.)
REFERENCES IN TEXTThis subchapter, referred to in text, was in the original "this subtitle", meaning subtitle D (§13400 et seq.) of title XIII of div. A of Pub. L. 111–5, Feb. 17, 2009, 123 Stat. 258, which is classified principally to this subchapter. For complete classification of subtitle D to the Code, see Tables.
Section 13101, referred to in par. (9), means section 13101 of div. A of Pub. L. 111–5.
1 So in original. Probably should be followed by "the".
2 See References in Text note below.
Disclaimer: These codes may not be the most recent version. The United States Government Printing Office may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the US site. Please check official sources.