Sec. 13400. Definitions
In this subtitle, except as specified otherwise:
(A) In General.—The term ‘‘breach’’ means the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.
(B) Exceptions.—The term ‘‘breach’’ does not include—
(I) such acquisition, access, or use was made in good faith and within the course and scope of the employment or other professional relationship of such employee or individual, respectively, with the covered entity or business associate; and
(ii) any inadvertent disclosure from an individual who is otherwise authorized to access protected health information at a facility operated by a covered entity or business associate to another similarly situated individual at same facility; and
(5) Electronic Health Record.—The term ‘‘electronic health record’’ means an electronic record of health-related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff.
(9) National Coordinator.—The term ‘‘National Coordinator’’ means the head of the Office of the National Coordinator for Health Information Technology established under section 3001(a) of the Public Health Service Act, as added by section 13101.
(11) Personal Health Record.—The term ‘‘personal health record’’ means an electronic record of PHR identifiable health information (as defined in section 13407(f)(2)) on an individual that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual.
(13) Secretary.—The term ‘‘Secretary’’ means the Secretary of Health and Human Services.
(15) State.—The term ‘‘State’’ means each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.
(18) Vendor of Personal Health Records.—The term ‘‘vendor of personal health records’’ means an entity, other than a covered entity (as defined in paragraph (3)), that offers or maintains a personal health record.