Don’t do SECURITY. Do business SECURELY.

HIPAA Omnibus Rule compliance deadline arrives

US covered entities and business associates must now comply with the HIPAA Omnibus Rule, which extends HIPAA obligations directly to business associates.

The compliance deadline for the HIPAA Omnibus Rule, which implements the HITECH Act changes to the HIPAA Privacy, Security and Breach Notification Rules, arrives today in the United States.

Key points

  • Business associates, and their subcontractors, are now directly liable for compliance with the HIPAA Security Rule.
  • The breach notification standard shifts to a presumption of breach unless a risk assessment shows a low probability of compromise.
  • Business associate agreements must be updated to reflect the new requirements.
  • Tiered civil penalties of up to $1.5 million per year for each type of violation apply.

UK organisations providing software, hosting or services that handle US health data for covered entities are likely to be business associates and now carry direct regulatory responsibility.

Source: HIPAA Omnibus final rule, 78 FR 5566 (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights