<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-10-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA04</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202104</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>HIPAA Rules: Request for Information on Sharing Civil Money Penalties or Monetary Settlements With Harmed Individuals, and Recognized Security Practices Under HITECH</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This Request for Information (RFI) would solicit the public's views on establishing a methodology for the distribution of CMPs and monetary settlements to those harmed by an offense under the HIPAA Rules relating to privacy or security. It also would seek additional comment on modifying the HIPAA Privacy Rule as necessary to implement the accounting of disclosures provisions of the HITECH Act, sec. 13405(c). OCR plans to withdraw the Accounting of Disclosures NPRM that was issued in 2011 when a new NPRM on accounting of disclosures is issued.&nbsp; The RFI also would seek comment on ways to implement in regulation the requirement for OCR to consider certain recognized security practices of covered entities and business associates when making certain HIPAA enforcement determinations.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Prerule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Social Security Act, sec. 1776 (42 U.S.C. 1320d-5) added by Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. 104-191, sec. 264 (August 21, 1996)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Information Technology for Economic and Clinical Health (HITECH) Act (title XIII of the American Recovery and Reinvestment Act of 2009)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 111-5, sec 13410(c)(3) and (4)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>sec. 3412 as added by Pub. L. 116-321 (January 5, 2021)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>42 U.S.C. 1320d-5, as amended</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>Final</DLINE_ACTION_STAGE>
                <DLINE_DATE>02/17/2012</DLINE_DATE>
                <DLINE_DESC>The statutory deadline for issuing a rule on sharing of civil money penalties (CMPs) or monetary settlements was 2/17/2012.</DLINE_DESC>
            </LEGAL_DLINE_INFO>
        </LEGAL_DLINE_LIST>
        <LEGAL_DLINE_OVERALL_DESC>There is no statutory deadline on taking recognized security practices into account in HIPAA enforcement actions as the HITECH amendment does not require rulemaking.

The statutory deadline for issuing a rule on accounting of disclosures is not later than 6 months after the Secretary adopts standards on accounting of disclosures as described in HITECH Act sec. 13101. Pub. L. 116-321 on taking recognized security practices into account in HIPAA enforcement actions does not require rulemaking.</LEGAL_DLINE_OVERALL_DESC>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>05/31/2011</TTBL_DATE>
                <FR_CITATION>76 FR 31426</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>08/01/2011</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>RFI</TTBL_ACTION>
                <TTBL_DATE>11/00/2021</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>No</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
            <GOVT_LEVEL>Tribal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>www.hhs.gov/ocr/privacy</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
