HHS Publishes Long-Awaited Final Omnibus Rules for HIPAA


The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) published today the final regulations for the HIPAA Privacy, Security, Enforcement and Breach Notification Rules (the Omnibus Rules). The Omnibus Rules include significant changes that will impact all covered entities and business associates. Our initial impressions of the Omnibus Rules are as follows:

  • Business associates, as well as their subcontractors that create, receive, maintain or transmit protected health information (PHI), will now have direct liability under HIPAA and must comply with its security and privacy standards.
  • The definition of a data “breach” was changed. The Omnibus Rules replaced the more subjective “harm standard” with a more objective test that requires the covered entity to determine (based on a four-factor risk assessment) whether protected health information has been “compromised.”
  • Covered entities are restricted from using PHI for marketing and fundraising purposes, and are prohibited from selling PHI without prior authorization, with limited exceptions.
  • Penalties have been increased for violations under HIPAA based on the level of negligence, with maximum penalties of $1.5 million per violation.

The Omnibus Rules, when read in the context of recent OCR guidance and press releases, suggests increased enforcement in this area is likely.

Snell & Wilmer’s health care, employee benefits and data privacy attorneys will be distributing a variety of educational materials and resources on the Omnibus Rules in the coming weeks. Stay tuned for more details.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Snell & Wilmer | Attorney Advertising

Written by:


Snell & Wilmer on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:

Sign up to create your digest using LinkedIn*

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.

Already signed up? Log in here

*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.