• Home
  • Blog
  • Contact
HIPAA ComplianceHIPAA Compliance
HIPAA ComplianceHIPAA Compliance
  • Home
  • Blog
  • Contact

HHS Pulls Breach Notification Final Rule

July 30, 2010 American Recovery and Reinvestment Act, Enforcement, Health IT and HITECH, HIPAA Law, Privacy, Security No Comments

The HIPAA Administrative Simplification; Notification in the Case of Breach Final Rule (Regulation Identifier Number (RIN) 0991-AB56) has been at the Office of Management and Budget (OMB) since May 14, 2010, for Executive Order (EO) 12866 review and approval prior to publication in the Federal Register. On July 28, 2010, HHS “withdrew” this Final Rule, with the following explanation:

“The Interim Final Rule for Breach Notification for Unsecured Protected Health Information, issued pursuant to the Health Information Technology for Economic and Clinical Health (HITECH) Act, was published in the Federal Register on August 24, 2009, and became effective on September 23, 2009. During the 60-day public comment period on the Interim Final Rule, HHS received approximately 120 comments.

HHS reviewed the public comment on the interim rule and developed a final rule, which was submitted to the Office of Management and Budget (OMB) for Executive Order 12866 regulatory review on May 14, 2010.  At this time, however, HHS is withdrawing the breach notification final rule from OMB review to allow for further consideration, given the Department’s experience to date in administering the regulations.  This is a complex issue and the Administration is committed to ensuring that individuals’ health information is secured to the extent possible to avoid unauthorized uses and disclosures, and that individuals are appropriately notified when incidents do occur.  We intend to publish a final rule in the Federal Register in the coming months.”

You may follow developments with this Final Rule at the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Web site, and HIPAA.com will bring you updates as well.

Stay tuned!

[20100730]

Tags: 0991-AB56August 24 2009Breach Notification Final RuleDEPARTMENT OF HEALTH AND HUMAN SERVICESEO 12866Executive OrderFederal RegisterHealth Information Technology for Economic and Clinical Health ActHHSHITECH ActInterim Final RuleOCROffice for Civil RightsOffice of Management and BudgetOMBRINSeptember 23 2009unauthorized uses and disclosuresunsecured protected health information
No Comments
Share
0

You also might be interested in

HHS Issues Interim Final Rule for HITECH ‘Breach Notification’

Aug 21, 2009

U.S. Department of Health and Human Services Secretary, Kathleen Sebelius,[...]

Facility Access Controls: Maintenance Records-What to Do and How to Do It

Apr 29, 2009

In our series on the HIPAA Administrative Simplification Security Rule,[...]

HHS Issues HIPAA NPRM for Unique Health Plan Identifier and One Year Delay for ICD-10 Code Set Compliance

Apr 11, 2012

April 10, 2012.  Yesterday, the Office of the Secretary of[...]

Leave a Reply Cancel Reply

Categories

  • 5010
  • American Recovery and Reinvestment Act
  • Enforcement
  • GINA
  • Health Care Reform
  • Health IT and HITECH
  • HIPAA Law
  • Identifiers
  • Meaningful Use
  • Privacy
  • Red Flags Rules
  • Security
  • Transactions & Code Sets
  • Uncategorized

Recent Posts

  • Contracting with Vendors that are NOT HIPAA Business Associates: Best Practices
  • HIPAA Breach: Who You Gonna Call?
  • Can I Be Sued for a HIPAA Violation?
  • Business Associate Agreements – a First Look at Indemnification
  • Gmail, Google Apps for Business HIPAA Business Associate Agreements

Archives

Contact Us

We're currently offline. Send us an email and we'll get back to you, asap.

Send Message
HIPAA- Health Insurance Portability Accountability Act

© 2023 · hipaa.com

Prev Next