2024 HIPAA Privacy Rule Changes: What to Know & Recommended Actions

The Office for Civil Rights (OCR) at the U.S. Department of Health & Human Services (HHS) issued a new Final Rule on April 22, 2024, with the aim of strengthening privacy protections under HIPAA related to reproductive healthcare information. The 2024 HIPAA Privacy Rule changes clarify how covered organizations can use and disclose protected health information (PHI) relating to abortion, pregnancy, contraception, and other reproductive health services without an individual’s signed authorization, with limited exceptions. Key points of the Final Rule include:

  • Defines “reproductive healthcare”
  • Limits disclosures of reproductive health PHI to law enforcement
  • Requires covered organizations to obtain a signed attestation that the use or disclosure of reproductive health PHI is not for a prohibited purpose
  • Requires covered organizations to revise their Notice of Privacy Practices to support reproductive health care privacy practices

The Final Rule is effective on June 25, 2024, with compliance dates of December 23, 2024, and February 16, 2025 (for applicable Notice of Privacy Practices requirements)

In anticipation of the Final Rule going into effect, Clearwater’s Privacy & Compliance experts recommend that organizations take the following actions:

  • Revise policies and procedures addressing disclosures of PHI for law enforcement purposes
  • Design a template attestation addressing uses or disclosures of reproductive health PHI
  • Revise your Notice of Privacy Practices to support reproductive healthcare privacy practices
  • Provide updated training and education to all members of the workforce within a reasonable period of time

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

Navigating the HIPAA Privacy Rule for Reproductive Healthcare: Compliance Essentials Before the December 2024 Deadline

Navigating the HIPAA Privacy Rule for Reproductive Healthcare: Compliance Essentials Before the December 2024 Deadline

In an era where the privacy of reproductive healthcare has become a topic for debate, healthcare organizations face growing fears and challenges over the potential misuse of sensitive patient data. Recent legal developments, coupled with the shifts following the Dobbs v. Jackson decision, have shown the urgent need for robust safeguards. Notably, the December 23, 2024 compliance deadline for the HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy offers a pivotal moment to address these concerns.
The Health Care Cybersecurity and Resiliency Act of 2024: Key Takeaways and Implications

The Health Care Cybersecurity and Resiliency Act of 2024: Key Takeaways and Implications

The Cybersecurity and Resiliency Act (HCCRA) of 2024 is yet another proposed bill aimed at strengthening the healthcare sector’s cybersecurity posture and resilience. It focuses on improving coordination between government organizations, updating cybersecurity standards, increasing breach reporting requirements, and providing grants to rural healthcare organizations that lack both financial and human resources needed to address growing cybersecurity vulnerabilities and increasing threats.

Connect
With Us