In this subchapter, except as specified otherwise:
The term "breach" means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
The term "breach" does not include-
The term "business associate" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The term "covered entity" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The terms "disclose" and "disclosure" have the meaning given the term "disclosure" in section 160.103 of title 45, Code of Federal Regulations.
The term "electronic health record" means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.
The term "health care operation" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
The term "health care provider" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The term "health plan" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The term "National Coordinator" means the head of the Office of the National Coordinator for Health Information Technology established under section 300jj-11(a) of this title, as added by section 13101.2
The term "payment" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
The term "personal health record" means an electronic record of PHR identifiable health information (as defined in section 17937(f)(2) of this title) on an individual that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
The term "protected health information" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The term "Secretary" means the Secretary of Health and Human Services.
The term "security" has the meaning given such term in section 164.304 of title 45, Code of Federal Regulations.
The term "State" means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
The term "treatment" has the meaning given such term in section 164.501 of title 45, Code of Federal Regulations.
The term "use" has the meaning given such term in section 160.103 of title 45, Code of Federal Regulations.
The term "vendor of personal health records" means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.
1 So in original. Probably should be followed by "the".
2 See References in Text note below.
42 U.S.C. § 17921
EDITORIAL NOTES
REFERENCES IN TEXTThis subchapter, referred to in text, was in the original "this subtitle", meaning subtitle D (§13400 et seq.) of title XIII of div. A of Pub. L. 111-5, 123 Stat. 258, which is classified principally to this subchapter. For complete classification of subtitle D to the Code, see Tables. Section 13101, referred to in par. (9), means section 13101 of div. A of Pub. L. 111-5.
- Secretary
- the term "Secretary" means- (A) the Secretary of Education for purposes of subtitle A (other than section 3201),(B) the Secretary of Agriculture for purposes of the amendments made by section 3201, and(C) the Secretary of Health and Human Services for purposes of subtitle B,