HHS Proposes Changes to HIPAA Privacy, Security and Enforcement Regulations


Contained within the 2009 stimulus package known as the American Recovery and Reinvestment Act is the Health Information Technology for Economic and Clinical Health Act1 (HITECH).  Among other things, HITECH supplemented and broadened a number of the privacy and security requirements under the Health Insurance Portability and Accountability Act of 19962 (HIPAA). On July 14, 2010, the Department of Health and Human Services, Office of Civil Rights (OCR), issued a notice of proposed rulemaking3 (NPRM) implementing certain provisions of HITECH.

The most notable of the proposed changes relate to business associates—their legal obligations, their relationships with covered entities and their own subcontractors, and the required components of business associate agreements.  This Bulletin summarizes the most notable proposed changes affecting business associates and describes certain other noteworthy changes set forth in the NPRM.

Proposed Changes Affecting Business Associates

Other Privacy Rule Changes

Compliance Date

Many of the modifications proposed under the NPRM will not become effective before the corresponding effective dates under HITECH.  OCR recognized that covered entities and business associates will need a period of time following the publication of the final rulemaking to come into compliance with the new requirements.  To that effect, OCR proposes that the compliance deadline of the modified requirements will be 180 days after the publication of the final rule.  OCR further proposes to allow covered entities and business associates a period of up to one year following the compliance deadline to make the requisite modifications to existing business associate agreements.

Comments

OCR is accepting comments on the NPRM through September 14, 2010. The NPRM and public comments submitted to date are available on the Federal eRulemaking Program website, regulations.gov.


1  Division A, Title XIII, Subtitle D of the American Recovery and Reinvestment Act of 2009, Pub. L. No. 111-5 (Feb. 17, 2009) (to be codified at 42 U.S.C. §§ 17921-17940).

2  Pub. L. 104-191, 110 Stat. 2033 (1996).

3  Modifications to HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, 75 Fed. Reg. 40,868 (to be codified at 45 C.F.R. pt. 160 and pt. 164) (proposed July 14, 2010).


© 2025 Vedder Price
National Law Review, Volume , Number 258