# Worked four-factor assessment

A fictional employee submits two identifiable patient summaries to an unapproved AI account. The assessment identifies evidence needs without inventing a final legal conclusion.

Synthetic incident only. No real patients, provider response, notice or completed investigation is represented.

Source: https://aona.ai/resources/guides/phi-uploaded-ai-hipaa-breach-assessment/
Sources checked: 2026-09-21

## Four questions before a conclusion

### Data

What PHI and identifiers were involved?

### Recipient

Who received or could access it?

### Exposure

Was it acquired or viewed?

### Mitigation

What was actually done and evidenced?

| Factor | Invented case fact | Assessment and next step |
| --- | --- | --- |
| Nature and extent | Two invented records include names and diagnoses. | Direct identifiers and health details require careful assessment; verify the actual payload. |
| Unauthorised recipient | An external AI account was used; its applicable terms are not established. | Identify the service, account and any other recipients before assessing their obligations. |
| Acquired or viewed | Employee saw an answer; provider access and retention facts are unknown. | Do not infer no acquisition from the absence of a human viewer; obtain relevant evidence. |
| Mitigation | A deletion request is proposed but not sent in this exercise. | Record any actual action and response; do not treat a draft request as completed mitigation. |
| Illustrative disposition | Material recipient and exposure facts remain unresolved. | No low-probability conclusion is demonstrated by this example; escalate the assessment. |

## Review checklist

- [ ] Secure the factual record
  Capture the exact service, account, time, data categories and source evidence without copying PHI unnecessarily.
- [ ] Address each HHS factor
  Separate established facts from unknown acquisition, recipient and mitigation details.
- [ ] Assign the legal decision
  Record the responsible privacy owner and applicable notification steps and dates; this worksheet does not send notices.

## Included example files

- phi-ai-breach-assessment.md
- phi-ai-breach-assessment.csv

## Source references

- HHS: Breach Notification Rule: https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html (2026-09-21)
- HHS: Guidance on HIPAA and cloud computing: https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
