HIPAA Related Links — Corrective action / RA
Resolution —
Penalty
Corrective action / RA
Action type
Resolution agreement
Entity profile
—
Case number
—
What went wrong
HIPAA Related Links
- Navigate to: HIPAA for Professionals Regulatory Initiatives Privacy Summary of the Privacy Rule Guidance Combined Text of All Rules HIPAA Related Links Security Security Rule NPRM Summary of the Security Rule Security Guidance Cyber Security Guidance Breach Notification Breach Reporting Guidance Reports to Congress Regulation History Compliance & Enforcement Enforcement Rule Enforcement Process En
Full description
Navigate to: HIPAA for Professionals Regulatory Initiatives Privacy Summary of the Privacy Rule Guidance Combined Text of All Rules HIPAA Related Links Security Security Rule NPRM Summary of the Security Rule Security Guidance Cyber Security Guidance Breach Notification Breach Reporting Guidance Reports to Congress Regulation History Compliance & Enforcement Enforcement Rule Enforcement Process Enforcement Data Resolution Agreements Case Examples Audit Reports to Congress State Attorneys General Special Topics Parental Access Mental and Behavioral Health Change Healthcare Cybersecurity Incident FAQs HIPAA and COVID-19 HIPAA and Reproductive Health HIPAA and Final Rule Notice HIPAA and Telehealth HIPAA and FERPA Research Public Health Emergency Response Health Information Technology Health Apps Patient Safety Covered Entities & Business Associates Business Associate Contracts Business Associates Training & Resources FAQs for Professionals Other Administrative Simplification Rules Substance Use Disorder Confidentiality HIPAA Related Links Guidance for Ryan White CARE Act GranteesThe HIV/AIDS Bureau of the Health Resources and Services Administration (HRSA) developed “Protecting Health Information Privacy and Complying with Federal Regulations.” The guide highlights provisions of the Privacy Rule that are especially relevant to Ryan White Comprehensive AIDS Resources Emergency (CARE) Act grantees.Substance Abuse and Mental Health Services Administration - Guidance for Substance Abuse Treatment ProgramsThe Substance Abuse and Mental Health Services Administration (SAMHSA) issued The Confidentiality Of Alcohol And Drug Abuse Patient Records Regulation And The HIPAA Privacy Rule: Implications For Alcohol And Substance Abuse Programs as guidance for substance use disorder (SUD) treatment programs that are subject to the confidentiality requirements of “Part 2” Regulations (The Part 2 regulations apply to SUD treatment “programs” as defined by 42 CFR § 2.11 that are “federally assisted” as defined by 42 CFR § 2.12(b)). It explains which programs must also comply with the Privacy Rule and outlines some compliance requirements.Centers for Medicare & Medicaid Services (CMS)CMS enforces the Administrative Simplification standards adopted by HHS that do not relate to health information privacy. Visit the CMS Web site for more guidance on these regulations and CMS’s enforcement activities.Transaction and Code Set Standard (TCS), 65 FR 50313 (August 17, 2000)National Employer Identifier Number (EIN) Rule, 67 FR 38009 (May 31, 2002)National Provider Identifier Rule, 69 FR 3434 (January 23, 2004)National Plan Identifier Rule (currently under development).National Committee on Vital and Health Statistics (NCVHS)NCVHS advises the Secretary on implementation of the Administrative Simplification provisions of HIPAA. Visit the NCVHS Web site for the Committee's calendar of meetings and latest reports and recommendations.Workgroup for Electronic Data Interchange (WEDI)WEDI focuses on improving the quality of healthcare by informing and educating WEDI members and other healthcare stakeholders about the benefits of and strategies for improving information exchange and management. WEDI has a number of policy and advisory groups which work to facilitate a collaborative, industry-wide approach and readiness to health information technology (HIT), clinical initiatives, and standards including those for security, privacy, EDI transactions, code sets, and identifiers. Visit the WEDI Web site for more information about WEDI activities.The Department of Labor (DOL) - Portability of Health CoverageThe Privacy Rule was authorized by the Administrative Simplification subtitle of HIPAA. Other subtitles of HIPAA increase consumer access to health insurance. These provisions provide protections for coverage under group health plans, that limit exclusions for preexisting conditions; prohibit discrimination against employees and dependents based on their health status; and allow a special opportunity to enroll in a new plan to individuals in certain circumstances. HIPAA may also give you a right to purchase individual coverage if you have no group health plan coverage available, and have exhausted COBRA or other continuation coverage. Visit the DOL Web site for more information regarding these HIPAA portability of coverage provisions.Back to Top Content last reviewed April 1, 2025
Timeline
- Resolution—
- Incident and investigation milestones are not consistently published by OCR in machine-readable form.
Key takeaways for your organization
- Treat internet-facing systems and vendor-hosted environments as in-scope for HIPAA risk analysis and technical safeguards testing.
- Maintain an actionable risk analysis tied to remediation milestones; evidence should map to Security Rule implementation specifications.
- Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.
- Run tabletop exercises for breach response, OCR inquiry handling, and privilege-preserving communications with counsel.
Related actions
Source
U.S. Department of Health and Human Services release
Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use — not legal advice.