I. Background
A. Need for privacy standards.
B. Statutory background.
C. Administrative costs.
D. Consultations.
E. Summary and purpose of the proposed rule.
- Applicability.
- General rules.
- Scalability.
- Uses and disclosures with individual authorization.
- Uses and disclosures for treatment, payment and health care
operations.
- Permissible uses and disclosures for purposes other than treatment,
payment and health care operations.
- Individual rights.
- Administrative requirements and policy development and
documentation.
- Preemption.
- Enforcement.
- Conclusion.
II. Provisions of the proposed rule.
A. Applicability.
- Covered entities.
- Covered information.
- Interaction with other standards.
- References to other laws.
B. Definitions.
- Act.
- Covered entity.
- Health care.
- Health care clearinghouse.
- Health care provider.
- Health information.
- Health plan.
- Secretary.
- Small health plan.
- Standard.
- State.
- Transaction.
- Business partner.
- Designated record set.
- Disclosure.
- Health care operations.
- Health oversight agency.
- Individual.
- Individually identifiable health information.
- Law enforcement official.
- Payment.
- Protected health information.
- Psychotherapy notes.
- Public health authority.
- Research.
- Research information unrelated to treatment.
- Treatment.
- Use.
- Workforce.
C. General rules.
- Use and disclosure for treatment, payment, and health care
operations.
- Minimum necessary use and disclosure.
- Right to restrict uses and disclosures.
- Creation of de-identified information.
- Application to business partners.
- Application to information about deceased persons.
- Adherence to the notice of information practices.
- Application to covered entities that are components of organizations
that are not covered entities
D. Uses and disclosures with individual authorization.
- Requirements when the individual has initiated the authorization.
- Requirements when the covered entity initiates the authorization.
- Model forms.
- Plain language requirement.
- Prohibition on conditioning treatment or payment.
- Inclusion in the accounting for uses and disclosures.
- Revocation of an authorization by the individual.
- Expired, deficient, or false authorization.
E. Uses and disclosures permitted without individual authorization.
- Uses and disclosures for public health activities.
- Use and disclosure for health oversight activities.
- Use and disclosure for judicial and administrative proceedings.
- Disclosure to coroners and medical examiners.
- Disclosure for law enforcement.
- Uses and Disclosure for governmental health data systems.
- Disclosure of directory information.
- Disclosure for banking and payment processes.
- Uses and disclosures for research.
- Uses and Disclosures in emergency circumstances.
- Disclosure to next-of-kin.
- Additional uses and disclosures required by other law.
- Application to specialized classes.
F. Rights of individuals.
- Rights and procedures for a written notice of information practices.
- Rights and procedures for access for inspection and copying.
- Rights and procedures with respect to an accounting of disclosures.
- Rights and procedures for amendment and correction.
G. Administrative requirements.
- Designation of a privacy official.
- Training.
- Safeguards.
- Internal complaint process.
- Sanctions.
- Duty to mitigate.
H. Development and documentation of policies and procedures.
- Uses and disclosures of protected health information.
- Individual requests for restricting uses and disclosures.
- Notice of information practices.
- Inspection and copying.
- Amendment or correction.
- Accounting for disclosures.
- Administrative requirements.
- Record keeping requirements.
I. Relationship to other laws
- Relationship to State laws.
- Relationship to other federal laws.
J. Compliance and Enforcement.
- Compliance
- Enforcement.
III. Small Business Assistance
- Notice to individuals of information practices.
- Access of individuals to protected health information.
- Accounting for uses and disclosures.
- Amendment and correction.
- Designated Privacy official.
- Training.
- Safeguards.
- Complaints.
- Sanctions.
- Documentation of policies and procedures.
- Minimum Necessary.
- Business partners.
- Special disclosures that do not require authorization public
health, research, etc.
- Verification.
IV. Preliminary Regulatory Impact Analysis
A. Relationship of this Analysis to Analyses in Other HIPAA
Regulations.
B. Summary of Costs and Benefits.
C. Need for the Proposed Action.
D. Baseline Privacy Protections.
- Professional Codes of Conduct and the Protection of Health
Information.
- State Laws.
- Federal Laws.
E. Costs.
F. Benefits.
G. Examination of Alternative Approaches.
- Creation of de-identified information.
- General rules.
- Use and disclosure for treatment, payment, and health care
operations.
- Minimum necessary use and disclosure.
- Right to restrict uses and disclosures.
- Application to business partners.
- Application to information about deceased persons.
- Uses and disclosures with individual authorization.
- Uses and disclosures permitted without individual authorization.
- Clearinghouses and the rights of individuals.
- Rights and procedures for a written notice of information practices.
- Rights and procedures for access for inspection and copying.
- Rights and procedures with respect to an accounting of disclosures.
- Rights and procedures for amendment and correction.
- Administrative requirements.
- Development and documentation of policies and procedures.
- Compliance and Enforcement.
V. Initial Regulatory Flexibility Analysis
A. Introduction.
B. Economic Effects on Small Entities
- Number and Types of Small Entities Affected.
- Activities and Costs Associated with Compliance.
- The burden on a typical small business.
VI. Unfunded Mandates
A. Future Costs.
B. Particular regions, communities, or industrial sectors.
C. National productivity and economic growth.
D. Full employment and job creation.
E. Exports.
VII. Environmental Impact
VIII. Collection of Information Requirements
IX. Executive Order 12612: Federalism
X. Executive Order 13086: Consultation and Coordination with Indian
Tribal Governments
List of Subjects in 45 CFR Parts 160 and 164.
Appendix: Sample Provider Notice of Information Practices