{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-06",
    "fingerprint": "ewai:se:4b4d64",
    "proof": "sha256:8dbfde280d6caf67f3fc7bafe57f19e828f9750679df62655aa4913aa89fc10a",
    "jurisdiction": "se",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "object_type": "risk_chain",
  "object_id": "risk_chain:us:hipaa--covered-entity",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/risk_chain",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity",
  "judgment": {
    "id": "us:hipaa--covered-entity",
    "text": "https://legal.exploreworldai.com/api/public/v1/judgment-text?id=us:hipaa--covered-entity"
  },
  "siblings": {
    "risk": "https://legal.exploreworldai.com/api/public/v1/obj/risk/us:hipaa--covered-entity",
    "relation": "https://legal.exploreworldai.com/api/public/v1/obj/relation/us:hipaa--covered-entity",
    "change": "https://legal.exploreworldai.com/api/public/v1/obj/change/us:hipaa--covered-entity",
    "agent": "https://legal.exploreworldai.com/api/public/v1/obj/agent/us:hipaa--covered-entity",
    "provenance": "https://legal.exploreworldai.com/api/public/v1/obj/provenance/us:hipaa--covered-entity",
    "status": "https://legal.exploreworldai.com/api/public/v1/obj/status/us:hipaa--covered-entity",
    "precedent": "https://legal.exploreworldai.com/api/public/v1/obj/precedent/us:hipaa--covered-entity",
    "edge": "https://legal.exploreworldai.com/api/public/v1/obj/edge/us:hipaa--covered-entity",
    "element": "https://legal.exploreworldai.com/api/public/v1/obj/element/us:hipaa--covered-entity",
    "decision": "https://legal.exploreworldai.com/api/public/v1/obj/decision/us:hipaa--covered-entity",
    "obligation": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa--covered-entity",
    "sanction": "https://legal.exploreworldai.com/api/public/v1/obj/sanction/us:hipaa--covered-entity",
    "weight": "https://legal.exploreworldai.com/api/public/v1/obj/weight/us:hipaa--covered-entity",
    "conflict": "https://legal.exploreworldai.com/api/public/v1/obj/conflict/us:hipaa--covered-entity",
    "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa--covered-entity",
    "provision_link": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:hipaa--covered-entity",
    "brief": "https://legal.exploreworldai.com/api/public/v1/obj/brief/us:hipaa--covered-entity",
    "citation_graph": "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:hipaa--covered-entity",
    "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa--covered-entity",
    "compliance_effect": "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa--covered-entity",
    "answer_node": "https://legal.exploreworldai.com/api/public/v1/obj/answer_node/us:hipaa--covered-entity",
    "exception": "https://legal.exploreworldai.com/api/public/v1/obj/exception/us:hipaa--covered-entity",
    "timeline": "https://legal.exploreworldai.com/api/public/v1/obj/timeline/us:hipaa--covered-entity",
    "package": "https://legal.exploreworldai.com/api/public/v1/obj/package/us:hipaa--covered-entity",
    "case_kit": "https://legal.exploreworldai.com/api/public/v1/obj/case_kit/us:hipaa--covered-entity",
    "documentation_requirement": "https://legal.exploreworldai.com/api/public/v1/obj/documentation_requirement/us:hipaa--covered-entity",
    "sme_kit": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/us:hipaa--covered-entity",
    "action_kit": "https://legal.exploreworldai.com/api/public/v1/obj/action_kit/us:hipaa--covered-entity"
  },
  "source": "NovaCopilot",
  "precedent_graph": "https://legal.exploreworldai.com/api/public/v1/precedent-graph/us:hipaa--covered-entity",
  "item": {
    "act": "hipaa",
    "jurisdiction": "us",
    "role": "covered-entity",
    "path": "element → obligation → breach → sanction → leading judgment",
    "steps": [
      {
        "elements": [],
        "obligation": "obligation:us:hipaa-art-164-404-covered-entity",
        "role": "covered-entity",
        "article": "164.404",
        "breach": "Failure to: Notify each affected individual of a breach of unsecured protected health information without unreasonable delay.",
        "sanctions": [
          {
            "sanction_id": "sanction:us:hipaa-art-1320d-5",
            "type": "civil_penalty",
            "max_amount": "USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3)",
            "max_turnover_pct": null,
            "authority": "HHS Office for Civil Rights"
          }
        ]
      },
      {
        "elements": [],
        "obligation": "obligation:us:hipaa-art-164-406-covered-entity",
        "role": "covered-entity",
        "article": "164.406",
        "breach": "Failure to: Notify prominent media outlets when a breach involves more than 500 residents of a State or jurisdiction.",
        "sanctions": [
          {
            "sanction_id": "sanction:us:hipaa-art-1320d-5",
            "type": "civil_penalty",
            "max_amount": "USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3)",
            "max_turnover_pct": null,
            "authority": "HHS Office for Civil Rights"
          }
        ]
      },
      {
        "elements": [],
        "obligation": "obligation:us:hipaa-art-164-408-covered-entity",
        "role": "covered-entity",
        "article": "164.408",
        "breach": "Failure to: Notify the Secretary of HHS of breaches of unsecured protected health information.",
        "sanctions": [
          {
            "sanction_id": "sanction:us:hipaa-art-1320d-5",
            "type": "civil_penalty",
            "max_amount": "USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3)",
            "max_turnover_pct": null,
            "authority": "HHS Office for Civil Rights"
          }
        ]
      },
      {
        "elements": [],
        "obligation": "obligation:us:hipaa-art-164-308-covered-entity",
        "role": "covered-entity",
        "article": "164.308",
        "breach": "Failure to: Conduct an accurate and thorough risk analysis and implement security measures to reduce risks to electronic protected health information.",
        "sanctions": [
          {
            "sanction_id": "sanction:us:hipaa-art-1320d-5",
            "type": "civil_penalty",
            "max_amount": "USD 100 to 50 000 per violation in four culpability tiers, at most USD 1 500 000 per calendar year for identical violations (statute text; inflation-adjusted under 45 CFR 102.3)",
            "max_turnover_pct": null,
            "authority": "HHS Office for Civil Rights"
          }
        ]
      }
    ],
    "risk_level": "medium",
    "max_turnover_pct": null,
    "leading_judgments": [
      "us:iowa-25-2197-2026-10-02",
      "us:calctapp-e086667m-2026-09-23",
      "us:texag-kp-0530-2026-09-17"
    ],
    "gaps": [],
    "method": "Obligation and sanction registers joined on obligation ID; leading judgments are the newest in the outcome sample.",
    "links": {
      "obligations": [
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-404-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-406-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-408-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/obligation/us:hipaa-art-164-308-covered-entity"
      ],
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
      "compliance_effects": [
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-404-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-406-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-408-covered-entity",
        "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/us:hipaa-art-164-308-covered-entity"
      ],
      "leading": [
        "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:iowa-25-2197-2026-10-02",
        "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:calctapp-e086667m-2026-09-23",
        "https://legal.exploreworldai.com/api/public/v1/obj/citation_graph/us:texag-kp-0530-2026-09-17"
      ]
    },
    "hash": "80f6a5426cd630197e6e57e0507a90f3738cd6edd51f507746c33ead6559586a"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/us:hipaa",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/us:hipaa",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/us:hipaa"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "us:hipaa--covered-entity"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=us",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:8dbfde280d6caf67f3fc7bafe57f19e828f9750679df62655aa4913aa89fc10a",
  "version": "legal-2026-10-06",
  "expires": "2026-10-07T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-06+legal-2026-10-06+2026-10-06T16:51:49",
    "content_hash": "sha256:8dbfde280d6caf67f3fc7bafe57f19e828f9750679df62655aa4913aa89fc10a",
    "revalidate_after": "2026-10-06T19:10:13.706Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/us:hipaa--covered-entity",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}