HIPAA Alert: Omnibus Final Rule Issued

Written by: Sarah S. Murdough, Esq.

On January 17, 2013, the Department of Health and Human Services (“HHS”) Office of Civil Rights (“OCR”) released the long-awaited final HIPAA omnibus regulation (the “Omnibus Final Rule”). The official version of the Omnibus Final Rule was published in the January 25, 2013 edition of the Federal Register and is actually comprised of four final rules addressing the following four main topics: (1) final modifications to the HIPAA Privacy, Security, and Enforcement Rules mandated by HITECH; (2) changes to the HIPAA Enforcement Rule to incorporate HITECH’s increased civil monetary penalty and tiered structure; (3) revisions to the Breach Notification Rule replacing the interim rule’s “harm” threshold with a purported more “objective” standard; and (4) certain modification to the HIPAA Privacy Rule as required by the Genetic Information Nondiscrimination Act (“GINA”).

Note that the Omnibus Final Rule will be effective on March 26, 2013 and compliance will be required by September 23, 2013. Stay tuned here for future articles that will provide additional details regarding significant changes made by the Omnibus Final Rule, as well as any additional guidance from the OCR as it becomes available.

If you have any questions about HIPAA compliance and implementing changes mandated by the Omnibus Final Rule, please contact Sarah S. Murdough or any member of our firm’s Health Care Practice Group.