2024 HIPAA Privacy Rule Changes: What to Know & Recommended Actions

The Office for Civil Rights (OCR) at the U.S. Department of Health & Human Services (HHS) issued a new Final Rule on April 22, 2024, with the aim of strengthening privacy protections under HIPAA related to reproductive healthcare information. The 2024 HIPAA Privacy Rule changes clarify how covered organizations can use and disclose protected health information (PHI) relating to abortion, pregnancy, contraception, and other reproductive health services without an individual’s signed authorization, with limited exceptions. Key points of the Final Rule include:

  • Defines “reproductive healthcare”
  • Limits disclosures of reproductive health PHI to law enforcement
  • Requires covered organizations to obtain a signed attestation that the use or disclosure of reproductive health PHI is not for a prohibited purpose
  • Requires covered organizations to revise their Notice of Privacy Practices to support reproductive health care privacy practices

The Final Rule is effective on June 25, 2024, with compliance dates of December 23, 2024, and February 16, 2025 (for applicable Notice of Privacy Practices requirements)

In anticipation of the Final Rule going into effect, Clearwater’s Privacy & Compliance experts recommend that organizations take the following actions:

  • Revise policies and procedures addressing disclosures of PHI for law enforcement purposes
  • Design a template attestation addressing uses or disclosures of reproductive health PHI
  • Revise your Notice of Privacy Practices to support reproductive healthcare privacy practices
  • Provide updated training and education to all members of the workforce within a reasonable period of time

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

Rethinking the HIPAA Security Rule: Why Forward Path 2025 Might Be the Better Way Forward

Rethinking the HIPAA Security Rule: Why Forward Path 2025 Might Be the Better Way Forward

Late last year, the US Department of Health and Human Services (HHS) introduced a more prescriptive regulatory framework for the HIPAA Security Rule, which comes at a critical time. As the industry faces unprecedented numbers of breach-related sensitive record exposures, it’s clear healthcare organizations and their supporting partners need to do more to protect patient data, but is the Notice of Proposed Rulemaking (NPRM) to update the HIPAA Security Rule the answer?
Assumed Breach Simulation: Lateral Movement Explained

Assumed Breach Simulation: Lateral Movement Explained

A cyberattack doesn’t always start with an exposed perimeter. Sometimes, all it takes is a single compromised workstation — compromised through social engineering attacks, use of weak access management. To help clients gauge the potential for a breach to occur through these attack vectors, I and my colleagues on Clearwater’s Technical Testing team perform what is called assumed breach testing – a cybersecurity assessment that evaluates an organization’s ability detect, respond to, and recover from a breach.
RSA 2025 Recap: AI, Innovation, and Identity Take Center Stage

RSA 2025 Recap: AI, Innovation, and Identity Take Center Stage

The cybersecurity world descended on San Francisco last week for RSA Conference 2025, and Clearwater was proud to be there alongside our Redspin colleagues. From AI to identity, from innovation to infrastructure, this year’s RSA reflected both the rapid evolution of cybersecurity technology, and the mounting pressure on organizations to stay ahead of new threats. Here’s what stood out to our team on the ground.
No results found.

Connect
With Us