March 1, 2013

HIPAA Omnibus Rule: Checklist for Compliance

by Kim Stanger, Holland & Hart LLP

The new HIPAA omnibus rule modifies the privacy and security rules for covered entities (including health care providers and health plans), and their business associates. Although the new rules are effective March 26, 2013, covered entities and business associates generally have until September 23, 2013 to comply.1 Before then, covered entities and business associates need to do the following:

  1. Business Associates: Implement HIPAA Policies, Procedures and Safeguards. The HIPAA privacy and security rules now apply directly to business associates of covered entities.2 "Business associates" are those outside entities that create, receive, maintain or transmit protected health information in the course of performing functions on behalf of a covered entity, including contractors, consultants, data storage companies, health information organizations, and subcontractors of business associates.3 Business associates must now implement many of the same policies, procedures and safeguards that have been required of covered entities for years, including the following:
    1. Security Rule. Business associates will need to conduct and document a risk assessment of their information technology systems and implement the specific administrative, technical and physical safeguards specified in the Security Rule.4 The Office of Civil Rights' website contains helpful guidance for Security Rule compliance: http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/securityruleguidance.html.
    2. Privacy Rule. Most of the privacy rule provisions do not apply directly to business associates, but because business associates cannot use or disclose protected health information in a manner contrary to the limits placed on covered entities,5 business associates will need to implement many of the same policies and safeguards that the Privacy Rule mandates for covered entities, including rules governing uses and disclosure of protected health information and patient rights concerning their information.6 Those are typically outlined in the business associate's agreement with the covered entity. Since business associates are now directly liable for HIPAA violations, they should ensure they understand and train their employees concerning HIPAA Privacy and Security Rule requirements.
    3. Breach Notification. If a business associate becomes aware of a breach of unsecured health information, they must notify the covered entity and assist the covered entity in responding to the breach.7
  2. Identify New Business Associates and Execute Agreements. Covered entities are required to have business associate agreements with their business associates before allowing them to use or disclose protected health information. The omnibus rule expanded the definition of "business associates" to include entities that provide data transmission services and require routine access to information such as health information organizations.8 Covered entities should identify any such business associates and execute appropriate agreements with them. Business associates must execute appropriate business associate agreements with their own subcontractors if the subcontractor creates, receives, maintains or transmits protected health information for the business associate.9
  3. Review and, If Necessary, Amend Business Associate Agreements. Covered entities and business associates must ensure that their existing and future agreements contain the elements required by 45 CFR § 164.314(a) and .504(e). In addition to previous requirements, the agreement must require the business associate to:
    1. Comply with the security rule.
    2. Execute business associate agreements with their subcontractors.
    3. To the extent the business associate carries out on obligation of a covered entity, comply with any HIPAA rule applicable to such obligation.
    4. Report breaches of unsecured protected health information to the covered entity.

    The OCR has published updated sample business associate language at http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractprov.html. The omnibus rule confirms that covered entities are liable for the misconduct of business associates if the business associate is acting as the agent of the covered entity.10 To minimize their exposure, covered entities and business associates should ensure their agreements confirm that their business associates and subcontractors are acting as independent contractors and not as the agents of the covered entity or business associate, and that the agreements do not give the covered entity too much control over day-to-day operations of the business associate.11 Covered entities may also want to include indemnification or similar clauses to protect themselves. Covered entities have up to September 22, 2014 to modify business associate agreements if (1) the agreement they had in place on January 25, 2013, complied with the HIPAA rules as of that date, and (2) the agreement does not expire or renew (other than through evergreen clauses) prior to September 22, 2014.12

  4. Update Privacy Policies. Covered entities should update their privacy policies to comply with the new omnibus rules, including the following as applicable to the covered entity:
    1. Deceased Persons. Covered entities may now disclose protected health information to family members or others who were involved in the decedent's health care or payment for their care prior to the decedent's death so long as the disclosure is relevant to the person's involvement and is not inconsistent with the decedent's prior expressed wishes.13
    2. Patient Access to Electronic Information. If a patient requests an electronic copy of their information, covered entities must generally produce it in the form requested if readily producible.14 If the patient directs the covered entity in writing to transmit a copy of the electronic information to another person, the covered entity must generally comply.15
    3. Response to Request for Access. Covered entities must generally respond to a patient's request to access their information within 30 days; the omnibus rule eliminated the provision that gave covered entities extra time to respond if records were maintained offsite.16
    4. Limits on Disclosures to Insurers. Covered entities cannot disclose information about a patient's care to an insurer if (1) the insurer seeks the information for treatment or payment purposes; (2) the patient or someone on the patient's behalf paid for the care to which the information pertains; and (3) the patient requests that the information be withheld from the insurer.17 Good luck implementing this requirement. Developing a workable solution may take some advance preparation. Fortunately, the limit only applies if a patient requests nondisclosure; most patients will not request this restriction unless asked, so covered entities should not raise the issue with the patient. If a patient does request nondisclosure, covered entities should require that such requests be directed to a central person who can coordinate the efforts among billing, medical records, IT, and other relevant departments to ensure the protected data is sequestered.
    5. School Immunizations. Covered entities may now disclose information about immunizations to a school if (1) state law requires such information for school enrollment; and (2) the patient or their personal representative consents to the disclosure. The consent may be oral.18
    6. Sale of Information. Covered entities must obtain written authorization to sell a patient's information, and the authorization must disclose that the sale will result in remuneration to the covered entity.19
    7. Marketing. Covered entities must obtain written authorization to use the patient's information for marketing purposes, including most non-face-to-face communications for treatment purposes if the covered entity receives financial remuneration to make the communication.20 If remuneration is involved, the marketing authorization must disclose that fact.
    8. Fundraising. The new rule allows covered entities to disclose more information to institutionally related foundations to assist with fundraising, but fundraising communications must explain how the recipient may opt out of receiving such communications and the opt out method cannot be burdensome.21
    9. Research. If the covered entity engages in research, it should review new standards applicable to research as described in 45 CFR § 164.508(b).
  5. Update Breach Notification Policies. The omnibus rule modified the standard for reporting breaches of unsecured health information. Under the new standard, the unauthorized acquisition, access use or disclosure of protected health information in violation of the Privacy Rule is presumed to be a reportable breach unless (1) the covered entity or business associate demonstrates there is a low probability that the information has been compromised based on a risk assessment of certain factors, or (2) the breach fits within certain exceptions.22 Covered entities must ensure that their policies incorporate and that they apply this new, arguably lower standard. For more information about the breach notification standard, see my recent Healthcare Update at http://www.hollandhart.com/pubs/uniEntity.aspx?xpST=PubDetail&pub=2094. Given the lower standard, covered entities and business associates may want to consider encrypting records to the extent possible to avoid reportable breaches.
  6. Modify Notice of Privacy Practices. Covered entities must update their notices of privacy practices to add the following:
    1. A description of the types of information that require an authorization, i.e., psychotherapy notes, marketing, and sale of information.23
    2. A statement that other uses or disclosures not described in the notice will require an authorization.24
    3. A statement that the recipient of fundraising materials may opt out.25
    4. A description of the individual's right to limit disclosures to insurers if the patient paid for the relevant care.26
    5. A statement that the covered entity must notify the patient of a breach of unsecured protected health information.27
  7. Train Employees. Covered entities and business associates must train their employees concerning the new rules.28
  8. Review HIPAA Compliance. Given the new, lower breach notification standard, covered entities will likely to be required to self-report more breaches. Those reports may result in more patient complaints and government investigations. Accordingly, it is a good time to review and, as necessary, improve your compliance with all the HIPAA rules, not just the new omnibus rules. Doing so may help you avoid reportable breaches and, if a breach occurs, sidestep HIPAA penalties, which can range from $100 to more than $50,000 per violation. Having the required policies and safeguards in place coupled with prompt action to correct any breach will likely establish an affirmative defense to any penalties. For suggested steps to avoid penalties, see my recent Healthcare Update at http://www.hollandhart.com/pubs/uniEntity.aspx?xpST=PubDetail&pub=1898.

Resources. To assist clients in complying with the new omnibus rule and HIPAA in general, I have prepared sample Privacy Rule policies, forms, and agreements. If you would like to obtain a set of the sample documents, please contact me at kcstanger@hollandhart.com.


145 CFR § 160.105
2Id. at § 164.104(b)
3Id. at § 164.103
4Id. at §§ 164.302 to .316
5Id. at § 164.502(a)(3)
6Id. at § 164.502 to .528
7Id. at § 164.410
8Id. at § 164.103
9Id. at § 164.314(a)(2) and .502(e)(1)
10Id. at § 164.402(c)
11See 78 FR 5581
1245 CFR § 164.532(e)
13Id. at § 164.510(b)(5)
14Id. at § 164.524(c)(2)(ii)
15Id. at § 164.524(c)(3)(ii)
16Id. at § 164.524
17Id. at § 164.522(a)(1)(vi)
18Id. at § 164.512(b)(1)(vi)
19Id. at § 164.502(a)(5)(ii) and .508(a)(4)
20Id. at § 164.501 and .508(c)
21Id. at § 164.514(f)
22Id. at § 164.402
23 Id. at § 164.520(b)(1)(ii)(E)
24Id. at § 164.520(b)(1)(ii)(E)
25Id. at § 164.520(b)(1)(iii)
26Id. at § 164.520(b)(1)(iv)(A)
27Id. at § 164.520(b)(1)(V)(A)
28 Id. at § 164.530(b)


For questions regarding this update, please contact
Kim C. Stanger
Holland & Hart, U.S. Bank Plaza, 101 S. Capitol Boulevard, Suite 1400, Boise, ID 83702-7714
email: kcstanger@hollandhart.com, phone: 208-383-3913

This news update is designed to provide general information on pertinent legal topics. The statements made are provided for educational purposes only. They do not constitute legal advice nor do they necessarily reflect the views of Holland & Hart LLP or any of its attorneys other than the author. This news update is not intended to create an attorney-client relationship between you and Holland & Hart LLP. If you have specific questions as to the application of the law to your activities, you should seek the advice of your legal counsel.