View Rule
View EO 12866 Meetings | Printer-Friendly Version Download RIN Data in XML |
HHS/OCR | RIN: 0945-AA04 | Publication ID: Spring 2020 |
Title: HIPAA Enforcement and Privacy Rules: Annual Penalty Limits and Sharing Civil Money Penalties or Monetary Settlements With Harmed Individuals and Accounting of Disclosures Under the HITECH Act | |
Abstract:
This proposed rule would solicit tthe public's views on proposals to modify the HIPAA Enforcement Rule by adjusting some annual limits on CMPs under the HITECH Act and establishing a methodology for the distribution of civil money penalties and monetary settlements with those harmed by an offense under HIPAA relating to privacy or security. It also would propose to modify the HIPAA Privacy Rule as necessary to implement the accounting of disclosures provisions of section 13405(c) of the Health Information Technology for Economic and Clinical Health Act (title XIII of the American Recovery and Reinvestment Act of 2009). We plan to withdraw the current Accounting of Disclosures NPRM that was issued in 2011 when the new NPRM is issued. |
|
Agency: Department of Health and Human Services(HHS) | Priority: Other Significant |
RIN Status: Previously published in the Unified Agenda | Agenda Stage of Rulemaking: Proposed Rule Stage |
Major: No | Unfunded Mandates: No |
EO 13771 Designation: Other | |
CFR Citation: 45 CFR 160 45 CFR 164 | |
Legal Authority: Health Information Technology for Economic and Clinical Health (HITECH) Act, Pub. L. 111-5, sec. 13410(c)(3) & (4) Social Security Act, sec. 1776 42 U.S.C. 1320d-5, as amended by HITECH Act sec. 13410(a), (d), and (f) PL 111-5, sec 13405(c) |
Legal Deadline:
|
||||||||||||
Overall Description of Deadline: The statutory deadline to issue a rule on the requirements on the sharing of civil monetary penalties (CMP) or monetary settlements with individuals harmed by the actions for which CMPs were imposed was February 17, 2012, pursuant to the HITECH Act. Issuing a rule on Accounting of Disclosures is statutory not later than 6 months after the Secretary adopts standards on accounting of disclosures described in HITECH section 13101. |
||||||||||||
Timetable:
|
Regulatory Flexibility Analysis Required: No | Government Levels Affected: None |
Small Entities Affected: No | Federalism: No |
Included in the Regulatory Plan: No | |
RIN Information URL: www.hhs.gov/ocr/privacy | |
RIN Data Printed in the FR: No | |
Agency Contact: Marissa Gordon-Nguyen Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy Department of Health and Human Services Office for Civil Rights 200 Independence Avenue SW, Washington, DC 20201 Phone:800 368-1019 TDD Phone:800 537-7697 Email: ocrprivacy@hhs.gov |