- INTRODUCTION
- BACKGROUND
- GENERAL ADMINISTRATIVE REQUIREMENTS
- SUBPART A - General Provisions
- §160.103 Definitions
- SUBPART B - Preemption of State Law
- §160.203 The General Rule
- SUBPART C - Compliance and Enforcement
- § 160.304 Principles for achieving compliance
- § 160.306 Complaints to the Secretary
- § 160.308 Compliance reviews
- § 160.310 Responsibilities of covered entities
- § 160.314 Investigational subpoenas and inquiries
- § 160.316 Refraining from intimidation or retaliation
- SUBPART D - Imposition of Civil Money Penalties
- § 160.404 Amount of a civil money penalty
- § 160.408 Factors considered in determining the amount of a civil money penalty
- § 160.410 Affirmative defenses
- § 160.418 Penalty not exclusive
- HIPAA PRIVACY RULE
- § 164.500 Applicability
- § 164.501 Definitions
- § 164.502 Uses and disclosures of protected health information: general rules
- § 164.504 Uses and disclosures: Organizational requirements
- § 164.506 Uses and disclosures to carry out treatment, payment, or health care operations
- § 164.508 Uses and disclosures for which an authorization is required
- § 164.510 Uses and disclosures requiring an opportunity for the individual to agree or to object
- § 164.512 Uses and disclosures for which an authorization or opportunity to agree or object is not required
- § 164.514 Other requirements relating to uses and disclosures of protected health information
- § 164.520 Notice of privacy practices for protected health information
- § 164.522 Rights to request privacy protection for protected health information
- § 164.524 Access of individuals to protected health information
- § 164.526 Amendment of protected health information
- § 164.528 Accounting of disclosures of protected health information
- § 164.530 Administrative requirements
- HIPAA SECURITY RULE
- § 164.302 Applicability
- § 164.304 Definitions
- § 164.306 Security standards: General rule
- § 164.308 Administrative safeguards
- § 164.310 Physical safeguards
- § 164.312 Technical safeguards
- § 164.314 Organizational requirements
- § 164.316 Policies and procedures and documentation requirements
- § 164.318 Compliance dates for the initial implementation of the security standards
- THE HITECH ACT
- Enforcement
- Notification of Breach
- Electronic Health Record Access
- Business Associates
- Other Requirements
- Concluding Comments on the HITECH Act
- CONCLUSION
- RESOURCES
- U.S. Department of Health and Human Services (HHS)
- HITECH Act
- Blogs
- Standards Organizations
- Other Organizations
- Figure 1 HIPAA Title II
Make sure you are Omnibus Rule Compliant: HIPAA Privacy Checklist.