New HIPAA Attestation Form Requirements


A new HIPAA Attestation Form is a reminder that HIPAA compliance remains an important part of compliance efforts for health plans. The new form is related to an update to the HIPAA regulations that, among other changes, add protections around data that might relate to reproductive rights.

Starting December 23, 2024, the new guidance prohibits the use or disclosure of protected health information (PHI) that may relate to legally provided reproductive health care when provided for either of the following purposes:

To enforce this new restriction, the HIPAA Attestation Form was created and should be used whenever a request for the use or disclosure of PHI relating to reproductive health care is received. In addition to the new form, the new requirements should be incorporated into your existing training, policies and procedures, and Business Associate Agreements (BAAs). These are not the only changes. For example, by February 2026, virtually all Notices of Privacy Practices (NPPs) must be updated.

What does this mean for health plans?

All plans should take this as an important reminder to review their HIPAA compliance. The level of detail and number of documents and policies associated with HIPAA, and the level of modifications that may be needed, can vary significantly depending on how your plan is administered and operated. 


© 2025 Varnum LLP
National Law Review, Volume XIV, Number 340