The presumption of a breach
US federal guidance is direct: when ransomware encrypts electronic protected health information (ePHI), a breach is presumed to have occurred. The reasoning is that the data was 'acquired' — the ransomware took control of it — which counts as an unauthorized disclosure under the HIPAA Breach Notification Rule.
That presumption can be rebutted, but the burden is on the organization. You must demonstrate, through a documented risk assessment, that there is a low probability the PHI was compromised. Absent that, notification obligations apply.
The four-factor risk assessment
Rebutting the presumption means working through the Breach Notification Rule's risk assessment, which weighs factors including the nature and extent of the PHI involved, who accessed or acquired it, whether it was actually viewed or exfiltrated, and the extent to which the risk has been mitigated.
Here is the practical trap: many organizations cannot answer these questions with confidence because they lack the visibility. If you can't prove what an attacker touched, you can't argue low probability of compromise — so the breach presumption stands, and you notify.
- Was the ePHI encrypted (by you) before the attack? Properly encrypted data may fall under a safe-harbor.
- Can you show what the attacker accessed and whether data left the environment?
- Do you have immutable logs that a regulator will accept as evidence?
Notification timelines
If notification is required, the clock matters. Affected individuals and HHS must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people in a jurisdiction also trigger media notification and prompt HHS posting on its public breach portal.
Modern double-extortion attacks — where data is stolen before encryption — make the breach determination even clearer, since exfiltration is a disclosure by any reading.
How visibility changes the outcome
The difference between a manageable incident and a compliance crisis often comes down to evidence. An organization that can show, with tamper-proof records, exactly what an attacker reached and whether data left is in a far stronger position — both to rebut the breach presumption where legitimate and to notify accurately where required.
Immune's immutable audit logging and network-level visibility are designed for precisely this. By recording what happened during an incident in a form that can't be altered, and by surfacing exfiltration as it occurs, Immune helps hospitals make the breach determination on facts rather than assumptions — and supports the notification obligations that follow.
Sources
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
