HHS Publishes Long-Awaited Final Omnibus Rules for HIPAA


The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) published today the final regulations for the HIPAA Privacy, Security, Enforcement and Breach Notification Rules (the Omnibus Rules). The Omnibus Rules include significant changes that will impact all covered entities and business associates. Our initial impressions of the Omnibus Rules are as follows:

  • Business associates, as well as their subcontractors that create, receive, maintain or transmit protected health information (PHI), will now have direct liability under HIPAA and must comply with its security and privacy standards.
  • The definition of a data “breach” was changed. The Omnibus Rules replaced the more subjective “harm standard” with a more objective test that requires the covered entity to determine (based on a four-factor risk assessment) whether protected health information has been “compromised.”
  • Covered entities are restricted from using PHI for marketing and fundraising purposes, and are prohibited from selling PHI without prior authorization, with limited exceptions.
  • Penalties have been increased for violations under HIPAA based on the level of negligence, with maximum penalties of $1.5 million per violation.

The Omnibus Rules, when read in the context of recent OCR guidance and press releases, suggests increased enforcement in this area is likely.

Snell & Wilmer’s health care, employee benefits and data privacy attorneys will be distributing a variety of educational materials and resources on the Omnibus Rules in the coming weeks. Stay tuned for more details.

Written by:

Published In:


DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Snell & Wilmer | Attorney Advertising

Don't miss a thing! Build a custom news brief:

Read fresh new writing on compliance, cybersecurity, Dodd-Frank, whistleblowers, social media, hiring & firing, patent reform, the NLRB, Obamacare, the SEC…

…or whatever matters the most to you. Follow authors, firms, and topics on JD Supra.

Create your news brief now - it's free and easy »

All the intelligence you need, in one easy email:

Great! Your first step to building an email digest of JD Supra authors and topics. Log in with LinkedIn so we can start sending your digest...

Sign up for your custom alerts now, using LinkedIn ›

* With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name.