HIPAA Privacy Rule: Potential Impacts of Proposed Changes

Patient Safety and Cybersecurity

By: Wes Morris, Managing Principal Consultant and Dawn Morgenstern, Senior Principal Consultant

This past Thursday, the Office for Civil Rights (OCR) issued a statement of intent to publish a Notice of Proposed Rulemaking (NPRM) proposing to modify the HIPAA Privacy Rule. These modifications are proposed to improve health information sharing for more effective healthcare, empower individuals with their own protected health information (PHI), and alleviate unnecessary administrative burdens on covered healthcare providers and health plans.

The NPRM has not yet been published in the Federal Register at the time of this writing; however, it can be expected any day. Once published, a 60-day period for review and comments will begin. After the comment period, OCR will review and issue a final rule. Covered Entities and Business Associates must comply with the new or modified standards and implementation specifications no later than 180 day from the effective date of the final rule. Thus, we can reasonably expect the modifications to the Privacy Rule to be in force sometime in 2021.

Our initial review of the proposed modifications reveals the following key objectives:

  • Improving individual’s right of access, and their right to direct PHI to third parties
  • Expanding on care coordination and case management activities (including a modification to the minimum necessary standard for these activities)
  • Improving ability to disclose PHI to social services agencies and home-based/community-based organizations for individual level care coordination and case management
  • Requiring modifications to the Notice of Privacy Practices (NPP)
  • Removing the burden to get acknowledgement of receipt of the NPP from the patient

Clearwater is closely monitoring the publication of updates, and we will continue to provide our insights as new information becomes available. Contact us today if you have any questions regarding these proposed modifications or HIPAA compliance in general.

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

RSA 2025 Recap: AI, Innovation, and Identity Take Center Stage

RSA 2025 Recap: AI, Innovation, and Identity Take Center Stage

The cybersecurity world descended on San Francisco last week for RSA Conference 2025, and Clearwater was proud to be there alongside our Redspin colleagues. From AI to identity, from innovation to infrastructure, this year’s RSA reflected both the rapid evolution of cybersecurity technology, and the mounting pressure on organizations to stay ahead of new threats. Here’s what stood out to our team on the ground.
Clearwater at RSA 2025: Spotlighting Healthcare Cybersecurity and Critical Infrastructure

Clearwater at RSA 2025: Spotlighting Healthcare Cybersecurity and Critical Infrastructure

Clearwater is heading to RSA this year, and we couldn't be more excited to join the global cybersecurity community from April 28–May 1 in San Francisco. With an impressive lineup of speakers, innovative sessions, and timely conversations about the future of cyber regulation, we’re looking forward to digging into what matters most to the healthcare sector—paying special attention to sessions on protecting our nation’s critical infrastructure.
No results found.

Connect
With Us


Let us know who referred you, if you went to an event, found us in search, or liked one of our LinkedIn posts.