2024 HIPAA Privacy Rule Changes: What to Know & Recommended Actions

The Office for Civil Rights (OCR) at the U.S. Department of Health & Human Services (HHS) issued a new Final Rule on April 22, 2024, with the aim of strengthening privacy protections under HIPAA related to reproductive healthcare information. The 2024 HIPAA Privacy Rule changes clarify how covered organizations can use and disclose protected health information (PHI) relating to abortion, pregnancy, contraception, and other reproductive health services without an individual’s signed authorization, with limited exceptions. Key points of the Final Rule include:

  • Defines “reproductive healthcare”
  • Limits disclosures of reproductive health PHI to law enforcement
  • Requires covered organizations to obtain a signed attestation that the use or disclosure of reproductive health PHI is not for a prohibited purpose
  • Requires covered organizations to revise their Notice of Privacy Practices to support reproductive health care privacy practices

The Final Rule is effective on June 25, 2024, with compliance dates of December 23, 2024, and February 16, 2025 (for applicable Notice of Privacy Practices requirements)

In anticipation of the Final Rule going into effect, Clearwater’s Privacy & Compliance experts recommend that organizations take the following actions:

  • Revise policies and procedures addressing disclosures of PHI for law enforcement purposes
  • Design a template attestation addressing uses or disclosures of reproductive health PHI
  • Revise your Notice of Privacy Practices to support reproductive healthcare privacy practices
  • Provide updated training and education to all members of the workforce within a reasonable period of time

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

Clinical Research Organizations: M&A Goldmine or Data Liability? Why Cybersecurity Must Be on Every Investor’s Radar

Clinical Research Organizations: M&A Goldmine or Data Liability? Why Cybersecurity Must Be on Every Investor’s Radar

The market for clinical trials is experiencing significant momentum in mergers and acquisitions (M&A). Private equity (PE) investment in Clinical Research Organizations (CROs) and Site Management Organizations (SMOs) is being spurred by site consolidation, expansion of specialized services, and technology innovation. These firms are important players in the pipeline of drug development and the best targets for investors who wish to capitalize on healthcare innovation.
8 Easy Ways to Prepare for an OCR HIPAA Compliance Audit

8 Easy Ways to Prepare for an OCR HIPAA Compliance Audit

The Office for Civil Rights (OCR) has officially launched its third round of HIPAA audits, following previous assessments in 2012 and 2016.  Learn 8 easy ways to prepare for an OCR HIPAA compliance audit and safeguard your health information against rising cyber threats. Past audits revealed widespread compliance gaps, prompting increased oversight.
OCR’s Proposed HIPAA Security Rule Notice of Proposed Rulemaking

OCR’s Proposed HIPAA Security Rule Notice of Proposed Rulemaking

In Part 1 of this blog, I provide an overview of OCR’s proposed changes to the HIPAA Security Rule, some commentary on the background, rationale and the potential impact on healthcare, descriptions of key changes in definitions, and OCR’s broader themes. In Part 2, I will dive into specific proposed new or updated standards and implementation specifications and speculate on what may happen next.

Connect
With Us