# Worked four-factor assessment

Synthetic incident only. No real patients, provider response, notice or completed investigation is represented.

A fictional employee submits two identifiable patient summaries to an unapproved AI account. The assessment identifies evidence needs without inventing a final legal conclusion.

| Factor | Invented case fact | Assessment and next step |
| --- | --- | --- |
| Nature and extent | Two invented records include names and diagnoses. | Direct identifiers and health details require careful assessment; verify the actual payload. |
| Unauthorised recipient | An external AI account was used; its applicable terms are not established. | Identify the service, account and any other recipients before assessing their obligations. |
| Acquired or viewed | Employee saw an answer; provider access and retention facts are unknown. | Do not infer no acquisition from the absence of a human viewer; obtain relevant evidence. |
| Mitigation | A deletion request is proposed but not sent in this exercise. | Record any actual action and response; do not treat a draft request as completed mitigation. |
| Illustrative disposition | Material recipient and exposure facts remain unresolved. | No low-probability conclusion is demonstrated by this example; escalate the assessment. |

## Review steps

- Secure the factual record: Capture the exact service, account, time, data categories and source evidence without copying PHI unnecessarily.
- Address each HHS factor: Separate established facts from unknown acquisition, recipient and mitigation details.
- Assign the legal decision: Record the responsible privacy owner and applicable notification steps and dates; this worksheet does not send notices.

## Synthetic evidence request list

- What exact information was submitted, through which account and feature?
- Was the input stopped locally or received by the service?
- Which entity and other recipients could process or access it?
- What retention, access and deletion facts can the provider substantiate?
- What mitigation was actually completed, and when?

## Example decision record

Assessment status: facts incomplete.
Low-probability conclusion: not demonstrated by this fictional evidence.
Notification determination: for the authorised privacy/legal owner.
Notices sent: none; this is a teaching exercise.

## Source and scope

Guide: https://aona.ai/resources/guides/phi-uploaded-ai-hipaa-breach-assessment/

Source check: 21 September 2026. General information; no professional approval or installed-product result is represented.

- HHS: Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
