<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-19-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA20</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202310</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Proposed Modifications to the HIPAA Privacy Rule to Support Reproductive Health Care Privacy</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This final rule will modify the Standards for Privacy of Individually Identifiable Health Information (Privacy Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will modify existing standards permitting uses and disclosures of protected health information (PHI) by limiting uses and disclosures of PHI for certain purposes.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Section 3(f)(1) Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Health Insurance Portability and Accountability Act (PL 104-191)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Executive Order 14076, Protecting Access to Reproductive Healthcare Services</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HIPAA and the HIPAA Rules promote access to health care by establishing standards for the privacy of PHI to protect the confidentiality of individuals&rsquo; health information. These protections promote the development and maintenance of confidence and trust between individuals and covered entities, and help to improve the completeness and accuracy of individual medical records. The Privacy Rule, as it has been amended over time, carefully balances the interests of individuals and society in identifiable health information by establishing when and how such information may be used and disclosed, with and without the individual&rsquo;s permission. The Department has received communications from members of Congress and the public and reviewed media reports indicating concerns and confusion regarding the role of the Privacy Rule in protecting the privacy of individual&rsquo;s health information, given the evolution of state law in the area of reproductive health care.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The current HIPAA Privacy Rule has not been updated to reflect the evolution in state law that undermines the privacy of individuals&rsquo; protected health information, particularly for use in investigations into or legal proceedings against persons in connection with reproductive health care. The final rule is consistent with Executive Order 14076, which directed the Secretary of Health and Human Services to consider actions to strengthen the protection of sensitive information related to reproductive healthcare services and bolster patient-provider confidentiality.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS considered whether these policy changes could be implemented through guidance. However, the Department determined that this would be insufficient to address the concerns that have arisen in the wake of the recent evolution in state law pertaining to reproductive health care that has jeopardize the privacy of individuals&rsquo; protected health information and affected individuals&rsquo; relationship with their health care providers and the U.S. health care system. Revisions to the existing HIPAA Privacy Rule are necessary to reestablish that trust and to ensure the privacy of individuals&rsquo; protected health information.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS estimates that the effects of the requirements for regulated entities would result in new costs of $611,831,396 within 12 months of implementing the final rule, followed by approximately $67,831,396 of recurring annual costs in years two through five. The Department anticipates that this rulemaking will result in significant benefits that are difficult to quantify because the area of health care the proposed rule addresses is among the most sensitive for patients and providers if privacy is violated. Additionally, the value of privacy, which cannot be recovered once lost, and trust that privacy will be protected by others, is difficult to quantify fully. The rule would prevent or reduce numerous harms, resulting in non-quantifiable benefits to patient and providers.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>To be determined.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>04/17/2023</TTBL_DATE>
                <FR_CITATION>88 FR 23506</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>06/16/2023</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Action</TTBL_ACTION>
                <TTBL_DATE>03/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
            <GOVT_LEVEL>Tribal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Yes</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
