HIPAA Omnibus Rule
What is the HIPAA Omnibus Rule?
Who must comply with the HIPAA Omnibus Rule?
Key updates introduced by the HIPAA Omnibus Rule
Breach notification rule: What changed?
Business Associate Agreements (BAAs): Strengthened and essential
Enhanced security and privacy for PHI
Increased penalties for non-compliance
Ensuring compliance with the HIPAA Omnibus Rule
Protecting healthcare data in 2026 and beyond
What is the HIPAA Omnibus Rule?
The HIPAA Omnibus Rule is a 2013 update to the Health Insurance Portability and Accountability Act of 1996 (HIPPA). It strengthens privacy and security protections for patient health information, extends liability to business associates and increases penalties for non-compliance. It also introduces stricter breach notification requirements and ensures patients’ access to their own data, enhancing transparency and accountability in healthcare.
The HIPAA Omnibus Rule is a set of modifications to HIPAA that strengthen the privacy and security protections of patient health information. It implements provisions from the Health Information Technology for Economic and Clinical Health (HITECH) Act and enhances the ability to enforce HIPAA requirements.
The rule also extends liability to business associates of HIPAA-covered entities and increases penalties for non-compliance. In addition, it introduces requirements for breach notification and patient access to their own data.
It also includes provisions to improve transparency and accountability in the handling of electronic protected health information (ePHI).
Who must comply with the HIPAA Omnibus Rule?
HIPAA compliance isn’t exclusive to healthcare providers. It also applies to other businesses, their partners, suppliers and subcontractors who handle protected health information (PHI).
The Omnibus rule makes sure all parties play by the same rules. If any of these parties mishandle patient data, they could incur HIPAA violations.
This legislation keeps patient data safe and secure within two main groups:
1. Covered entities
These are the institutions that are directly involved in the delivery and payment of healthcare services. They are responsible for ensuring that PHI and ePHI are protected throughout their operations in hospitals, at healthcare providers, in health plans through insurance and in clearinghouses that process healthcare claims.
2. Business associates
Organizations like cloud providers, IT vendors, medical billing companies and third-party administrators that perform functions on behalf of covered entities and also have access to PHI and ePHI.
Subcontractors who handle PHI on behalf of business associates also need to closely follow HIPAA’s strict protocols. This contractual requirement guarantees that everyone remains accountable and upholds the minimum necessary standard to keep patient data safe from unauthorized access and breaches.
Key updates introduced by the HIPAA Omnibus Rule
The Omnibus Rule introduced several key changes to HIPPA:
Patient rights expansion
This rule mandates that covered entities must comply with patients’ requests for electronic copies of their records. This requirement reinforces transparency and empowers individuals to manage their health data more effectively.
Business associate agreements (BAAs)
There are now more stringent provisions in contracts between covered entities and vendors that handle PHI and ePHI. This guarantees that business associates adhere to HIPAA regulations, and it greatly reduces the risk of data mishandling.
Specifically, the rule imposes direct liability on business associates for compliance with certain HIPAA provisions to further safeguard protected information.
Breach notifications
Covered entities must take more accountability and notify affected individuals within 60 days of discovering a breach involving unsecured PHI.
Additionally, they are required to inform the Department of Health and Human Services (HHS) and, in certain cases, the media.
This enhanced notification protocol aims to improve transparency and offer timely communication. The goal here is to allow patients whose information has been exposed to take necessary precautions to protect themselves.
Marketing and PHI restrictions
The Omnibus Rule limits the ability of covered entities and their business associates to use protected information for marketing purposes without explicit patient consent.
This includes prohibiting its sale without authorization. This adjustment seeks to protect patient privacy and make sure that their data is not exploited for commercial gain without their full consent.
Breach notification rule: What changed?
The HIPAA Omnibus Rule has notably expanded the definition of what constitutes a breach. Now, any unauthorized access, use or disclosure of unprotected PHI is presumed to be one, unless an the covered entity or business associate can demonstrate a low probability that this information has been compromised. This helps make sure that even minor incidents are thoroughly evaluated. Risk assessment plays a crucial role in this process.
Instead of automatically reporting all breaches, organizations must determine whether there is a low probability of compromise based on factors like:
-
the nature of the PHI.
-
who accessed it.
-
whether it was viewed or acquired.
-
the extent to which the risk to the PHI has been mitigated.
-
the likelihood that the PHI could be re-identified.
Assessments must be documented thoroughly to justify any decision to avoid unnecessary notifications when appropriate, while still complying with HIPAA requirements.
When a breach occurs, covered entities, associates and subcontractors must act quickly and methodically to mitigate the damage. Implementing audit trails to track all access to sensitive data and establishing robust compliance reporting mechanisms are critical steps to maintain transparency and accountability throughout the process.
Business Associate Agreements (BAAs): strengthened and essential
BAAs must clearly define the business associate’s obligation to protect PHI, report breaches promptly and implement appropriate safeguards to maintain data security.
These contracts must also outline the specific actions the business associate will take to assist covered entities in responding to breaches and complying with HIPAA’s requirements.
The legislation made business associates and their subcontractors directly liable for non-compliance, along with the covered entities that hire their services.
Because of their direct involvement in handling PHI, these entities can now also face civil and criminal penalties if they fail to meet HIPAA standards.
Enhanced security and privacy for PHI
The Omnibus Rule expands patients' rights, giving them more control over their electronic health records. This includes the ability to request copies in electronic formats and limit data sharing, which requires yet another layer of protection.
Encryption and secure access are both best practices for securing ePHI under Omnibus Rule standards.
Some include:
-
Multi-factor authentication (MFA). This security process requires users to provide two or more verification factors to gain access to a system. It enhances protection beyond just a username and password.
-
Regular audit logs. Detailed records of all activity track who accessed what data and when. This helps organizations identify and respond to security incidents more easily.
-
Routine user access reviews. Implementing periodic evaluations of user access permissions confirms users have appropriate credentials based on roles and responsibilities, and allows access to be adjusted or revoked as needed.
Increased penalties for non-compliance
The Omnibus Rule introduced a tiered penalty structure, where fines are imposed based on the level of negligence. Penalties range from $100 to $50,000 per violation, with a maximum annual cap of $1.5 million for repeat violations. The severity increases with unaddressed violations and willful neglect.
Ensuring compliance with the HIPAA Omnibus Rule
Staying compliant with the HIPAA Omnibus Rule requires regular risk assessments to identify vulnerabilities and guarantee that all potential threats to ePHI are addressed.
To stay compliant, organizations should revise breach response protocols to include swift notification procedures and detailed documentation practices. Auditing and monitoring are crucial to maintaining continuous compliance. Organizations should conduct access control reviews and incorporate enhanced data-handling practices into their policies.
Real-time monitoring detects unauthorized access or potential breaches as they occur, allowing for an immediate response.