HIPAA Omnibus Rule is the current HIPAA rule set

January 25, 2013

About: HIPAA

#version-updates

On January 25, 2013, the U.S. Department of Health and Human Services (HHS) published the Health Insurance Portability and Accountability Act (HIPAA) Omnibus Final Rule. It took effect on March 26, 2013, with a compliance date of September 23, 2013. The Omnibus Rule implemented the Health Information Technology for Economic and Clinical Health (HITECH) Act, made business associates directly liable, tightened the breach notification standard, and consolidated earlier amendments into the Privacy, Security, and Breach Notification Rules that remain in force today.

This item was added to the change feed at launch so followers can see the kind of rule update a HIPAA subscription covers. It is not a new announcement.

What changed

Before the Omnibus Rule, much of the HITECH Act’s tightening sat in earlier, piecemeal updates. The 2013 rule put those pieces together:

  • Business associates (and their subcontractors) became directly liable for the Security Rule and for specified Privacy Rule provisions, not only for contract promises in a business associate agreement (BAA).
  • Breach notification moved to a more objective harm standard, so more incidents had to be treated as breaches unless a documented risk assessment showed a low probability of compromise.
  • Enforcement and penalty tiers from HITECH were folded into the standing rule set.

HIPAA still has no official certification and no required auditor. Covered entities and business associates demonstrate compliance through a current risk analysis, policies, training, BAAs, and breach documentation.

What did not change

The covered-entity definitions (health plans, healthcare clearinghouses, and providers that transmit health information electronically for standard transactions) did not become a new census of who is in. Employment records held by an employer are still not protected health information (PHI). A proposed Security Rule update published in January 2025 is not in force; see HIPAA Security Rule update delayed for that proposal’s status.

What to do now

  1. Write down whether you are a covered entity, a business associate, both, or neither. That record is the first thing an investigator asks about.
  2. If you handle PHI for a provider or plan, confirm you have a signed BAA and that your subcontractors do too.
  3. Treat a current, documented risk analysis as the core Security Rule record, not as optional homework.
  4. Read the HIPAA page for applicability, the three rules, and what to ask customers and vendors.
  5. Follow HIPAA on this site for rulemaking, enforcement, and guidance updates.

#version-updates

← Back to news