Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties

Steven M. Harris, Esq.  |  Issue: April 2013  |  April 1, 2013

  1. The nature and extent of the PHI, including the types of identifiers and the likelihood of re-identification;
  2. The unauthorized person who used or accessed the PHI;
  3. Whether the PHI was actually acquired or viewed; and
  4. The extent to which the risk is mitigated (e.g., by obtaining reliable assurances by a recipient of PHI that the information will be destroyed or will not be used or disclosed).

Expansion of Business Associate Obligations

The Final Rule implements the HITECH Act’s expansion of business associates’ HIPAA obligations by applying the Privacy and Security Rules directly to business associates and by imposing civil and criminal penalties on them for HIPAA violations. The Final Rule also extends obligations and potential penalties to direct and indirect subcontractors of business associates if they delegate a function, activity, or service to the subcontractor and the subcontractor creates, receives, maintains, or transmits PHI on behalf of the business associate. Any business associate that delegates a function involving the use or disclosure of PHI to a subcontractor will be required to enter into a business associate agreement with the subcontractor.

Additional Provisions of the Final Rule

The Final Rule also:

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE
  • Requires covered entities to modify their Notices of Privacy Practices;
  • Requires covered entities to agree to an individual’s request to restrict disclosure of PHI to a health plan when the individual (or someone other than the health plan) pays for the health care item or service in full;
  • Permits compound authorizations for clinical research studies;
  • Revises the definition of PHI to exclude information about a person who has been deceased for more than 50 years;
  • Prohibits the sale of PHI without authorization from the individual, and adds a requirement of authorization in order for a covered entity to receive remuneration for disclosing PHI;
  • Restricts marketing activities;
  • Allows individuals to obtain a copy of PHI in an electronic format if the covered entity uses an electronic health record;
  • Clarifies OCR’s view that covered entities are allowed to send electronic PHI to individuals in unencrypted e-mails only after notifying the individual of the risk;
  • Prohibits health plans from using or disclosing genetic information for underwriting, as required by the Genetic Information Nondiscrimination Act of 2008;
  • Allows covered entities to disclose relevant PHI of a deceased person to a family member, close friend, or other person designated by the deceased, unless the disclosure is inconsistent with the deceased person’s known prior expressed preference;
  • Allows disclosure of proof of immunization to schools if agreed by the parent, guardian, or individual;
  • Revises the Enforcement Rule (which was previously revised in 2009 as an interim final rule) to:
    • Require the Secretary of HHS to investigate a HIPAA complaint if a preliminary investigation indicates a possible violation due to willful neglect;
    • Permit HHS to disclose PHI to other government agencies (including state attorneys general) for civil or criminal law enforcement purposes; and
    • Revise standards for determining the levels of civil money penalties.

Effective Date and Compliance Date

Although most provisions of the Final Rule became effective on March 26, 2013, covered entities and business associates (including subcontractors) have until September 23, 2013 to become compliant. The 180-day compliance period does not apply to modifications of the Enforcement Rule, which will apply beginning on the March 26, 2013 effective date. Moreover, breach notification continues to be governed by the interim Breach Notification Rule until the September 23, 2013, compliance date.

Page: 1 2 3 | Single Page
Share: 

Filed under:Legal UpdatesLegislation & Advocacy Tagged with:Department of Health and Human ServicesHIPAALegalprotected health information

Related Articles

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Email & Text in the World of HIPAA

    May 17, 2019

    The world we live in necessitates infor­mation be communicated in a quick and easy manner. This remains true in the healthcare setting. The ability to text or email staff and patients has become a priority for many healthcare entities. However, maintaining patient privacy and confidentiality is essential to ensure we meet compliance standards. Although emailing…

    HHS Enforces Stricter Rules on HIPAA

    April 1, 2010

    As of February 17, 2010, entities covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), such as group health plans and their business associates, will have to take certain actions to ensure continued compliance with the privacy and security provisions of the act.

    HIPAA Privacy Rules Bring New Enforcement Guidelines

    November 1, 2014

    Focus shifts from voluntary to punitive; makes business associates more accountable for breaches of personal health information

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences