<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0991-AC05</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>201804</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0991</CODE>
            <NAME>Office of the Secretary</NAME>
            <ACRONYM>OS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Privacy Act Regulations</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>45 CFR part 5b details how the Department of Health and Human Services (HHS) implements its Privacy Act program to comply with Federal law as specified in the Privacy Act of 1974. The rule governs how HHS collects, maintains, uses, and disseminates personally identifiable information about individuals that is maintained in Systems of Records. This rule is divided into the following sections: 1. Purpose, Definitions, and Policy; 2. Maintenance of Records; 3. Classified Information; 4. Requests for notification and access; 5. Special procedures for notification of or access to medical records; 6. Requests for correction or amendment; 7. Requests for accountings of disclosures; 8. Consent requirement and exceptions; 9. Appeals; 10. Records Preservation; 11. Fees; 12. Notice of court-ordered and emergency disclosures; 13. Security; 14. Contractors; 15. Social security numbers; 16. Relationship to the Health Insurance Portability and Accountability Act (HIPAA); 17. Employee standards of conduct; 18. Sanctions and penalties; 19. Other rights and services; 20. Exempt systems of records.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Prerule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <EO_13771_DESIGNATION>Fully or Partially Exempt</EO_13771_DESIGNATION>
        <CFR_LIST>
            <CFR>None</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Not Yet Determined</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>ANPRM</TTBL_ACTION>
                <TTBL_DATE>05/00/2018</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <ADDITIONAL_INFO>This is an administrative, no-cost rule.  This rule will update a rule that was last published in 1975 and, therefore, is significantly outdated.   Updated regulations are needed to include not only significant changes to the HHS organization but also changes in the law that have been implemented since the HHS regulations were last updated in 1975.  The updated rule will aid the general public in its ability to understand and use the Privacy Act of 1974.  Since the Privacy Act provides U.S. citizens the right of access to records the Federal government keeps on them, it is essential that the HHS Privacy Act Regulations are up-to-date and accurate.</ADDITIONAL_INFO>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Michael</FIRST_NAME>
                <LAST_NAME>Marquis</LAST_NAME>
                <TITLE>FOIA Director</TITLE>
                <AGENCY>
                    <CODE>0991</CODE>
                    <NAME>Office of the Secretary</NAME>
                    <ACRONYM>OS</ACRONYM>
                </AGENCY>
                <PHONE>202 260-7100</PHONE>
                <EMAIL>michael.marquis@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW, Suite 729H,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
            <CONTACT>
                <FIRST_NAME>Beth</FIRST_NAME>
                <LAST_NAME>Kramer</LAST_NAME>
                <TITLE>Privacy Act Officer</TITLE>
                <AGENCY>
                    <CODE>0900</CODE>
                    <NAME>Department of Health and Human Services</NAME>
                    <ACRONYM>HHS</ACRONYM>
                </AGENCY>
                <PHONE>202 690-6941</PHONE>
                <FAX>202 690-8320</FAX>
                <EMAIL>beth.kramer@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW, Suite 729H,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
