Omnibus HIPAA rule lays out 'sweeping changes'

Share this article:

The Department of Health and Human Services issued an “omnibus” rule Thursday, comprehensively updating Health Insurance Portability and Accountability Act privacy and security regulations passed as part of the American Recovery and Reinvestment Act of 2009.

The 563-page rule is wide-ranging. Among its notable provisions, it expands direct liability for breaches to contractors, subcontractors and other “business associates” of healthcare providers, plans and insurers, according to an HHS announcement. It also defines noncompliance penalties, which vary depending on level of negligence and are capped at $1.5 million per violation.

The rule expands patient rights in a variety of ways, such as by improving access to electronic versions of health records and giving patients the right to limit disclosure of treatments paid for out-of-pocket.

“This final omnibus rule marks the most sweeping changes to the HIPAA Privacy and Security Rules since they were first implemented,” said HHS Office of Civil Rights Director Leon Rodriguez. “These changes not only greatly enhance a patient's privacy rights and protections, but also strengthen the ability of my office to vigorously enforce the HIPAA privacy and security protections, regardless of whether the information is being held by a health plan, a health care provider, or one of their business associates.”

HHS recently issued its first-ever HIPAA fine for a breach of health information for less than 500 people.

The rule will be published in the Federal Register on Jan. 25.

Share this article:

More in News

Medicare rates could be adjusted for start and end of hospice care ...

Medicare payments could be adjusted to reflect how hospice services tend to be more intensive at the beginning and end, according to findings recently published by the Centers for Medicare & Medicaid Services Office of Information Products & Data Analytics.

Nursing home resident dies after allegedly being smothered by son

A terminally ill nursing home resident in Ohio has died after his son is alleged to have smothered him, according to police.

Medicare should pay for skilled nursing services without a qualifying hospital stay, experts tell Senators

Medicare should pay for skilled nursing services without ...

The time has come to eliminate hospital stay requirements for beneficiaries to qualify for Medicare coverage of skilled nursing services, experts told a Senate committee Wednesday.