<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-03-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA04</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202304</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Rulemaking Implementing Provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act, as Amended</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rule would propose a methodology for the distribution of CMPs and monetary settlements to those harmed by an offense under the HIPAA Rules relating to privacy or security. The NPRM also would seek comment on a proposal to address in regulation the requirement for OCR to consider certain recognized security practices of covered entities and business associates when making certain HIPAA enforcement determinations.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Social Security Act, sec. 1776 (42 U.S.C. 1320d-5) added by Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. 104-191, sec. 264 (August 21, 1996)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Information Technology for Economic and Clinical Health (HITECH) Act (title XIII of the American Recovery and Reinvestment Act of 2009)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 111-5, sec. 13410(c)(3) and (4)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>sec. 13412 as added by Pub. L. 116-321 (January 5, 2021)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>42 U.S.C. 1320d-5, as amended</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>Final</DLINE_ACTION_STAGE>
                <DLINE_DATE>02/17/2012</DLINE_DATE>
                <DLINE_DESC>The statutory deadline for issuing a rule on sharing of civil money penalties (CMPs) or monetary settlements was 2/17/2012.</DLINE_DESC>
            </LEGAL_DLINE_INFO>
        </LEGAL_DLINE_LIST>
        <LEGAL_DLINE_OVERALL_DESC>The statutory deadline for issuing a rule establishing a methodology for the distribution of CMPs and monetary settlements to those harmed by an offense under the HIPAA Rules relating to privacy or security is not later than three years after the enactment of the HITECH Act.</LEGAL_DLINE_OVERALL_DESC>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>RFI</TTBL_ACTION>
                <TTBL_DATE>04/06/2022</TTBL_DATE>
                <FR_CITATION>87 FR 19833</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>RFI End of Comment Period</TTBL_ACTION>
                <TTBL_DATE>06/06/2022</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>03/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>No</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
            <GOVT_LEVEL>Tribal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <FURTHER_INFO_URL>www.hhs.gov/ocr/privacy</FURTHER_INFO_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
