<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-30-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0991-AB57</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>201010</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0991</CODE>
            <NAME>Office of the Secretary</NAME>
            <ACRONYM>OS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act</RULE_TITLE>
        <ABSTRACT><![CDATA[The Department of Health and Human Services Office for Civil Rights will issue rules to modify the HIPAA Privacy, Security, and Enforcement Rules as necessary to implement the privacy, security, and certain enforcement provisions of subtitle D of the Health Information Technology for Economic and Clinical Health Act (title XIII of the American Recovery and Reinvestment Act of 2009).]]></ABSTRACT>
        <PRIORITY_CATEGORY>Economically Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>PL 111-5, secs 13400 to 13410</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>NPRM</DLINE_ACTION_STAGE>
                <DLINE_DATE>02/17/2010</DLINE_DATE>
                <DLINE_DESC> </DLINE_DESC>
            </LEGAL_DLINE_INFO>
        </LEGAL_DLINE_LIST>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[The Office for Civil Rights will issue rules to modify the HIPAA Privacy, Security, and Enforcement Rules to implement the privacy and security provisions in sections 13400 to 13410 of the Health Information Technology for Economic and Clinical Health Act (title XIII of Division A of the American Recovery and Reinvestment Act of 2009, Pub. L. 111-5). These regulations will improve the privacy and security protection of health information.]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[Subtitle D of the Health Information Technology for Economic and Clinical Health Act (title XIII of the American Recovery and Reinvestment Act of 2009) requires the Office for Civil Rights to modify certain provisions of the HIPAA Privacy and Security Rules to implement sections 13400 to 13410 of the Act.]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[The Office for Civil Rights is statutorily mandated to make modifications to the HIPAA Privacy and Security Rules to implement the privacy provisions at sections 13400 to 13410 of the Health Information Technology for Economic and Clinical Health Act (title XIII of the American Recovery and Reinvestment Act of 2009).]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[These modifications to the HIPAA Privacy, Security, and Enforcement Rules will benefit health care consumers by strengthening the privacy and security protections afforded their health information by HIPAA covered entities and their business associated. The Agency believe the primary cost associate with this regulation will be for covered entities to revise and redistribute their notices of privacy practices to ensure health care consumers are informed of their new rights and protections. The Agency estimates the cost of revising and redistributing these notices to total approximates $166.1 million over the first year following the effective date of the regulation.  Of this total, the cost heal care providers is estimated to be approximately $46 million and to health plans to be approximately $120.1 million.  The Agency does not believe that the additional modification to Privacy, Security, or Enforcement Rules required by this regulation will significantly increase covered entity or business associates and in some cases will reduce burden.  Further, it is expected that the costs of modifying business associate contracts will be mitigated both by the additional one-year transition period which will allow the costs of modifying contracts to be incorporated into the normal renegotiation of contracts as the contracts expire, as well as sample business associate contract language to be provided by the Agency.]]></COSTS_AND_BENEFITS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Final Action</TTBL_ACTION>
                <TTBL_DATE>03/00/2011</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
            <GOVT_LEVEL>Local</GOVT_LEVEL>
            <GOVT_LEVEL>State</GOVT_LEVEL>
            <GOVT_LEVEL>Tribal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Andra</FIRST_NAME>
                <LAST_NAME>Wicks</LAST_NAME>
                <TITLE>Health Information Privacy Specialist</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>202 205-2292</PHONE>
                <FAX>202 205-4786</FAX>
                <EMAIL>andra.wicks@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW.,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
