By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: The HIPAA Omnibus Rule
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > The HIPAA Omnibus Rule
eHealth

The HIPAA Omnibus Rule

onlinetech
onlinetech
Share
3 Min Read
SHARE

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

The HIPAA omnibus rule, which extends the reach of liability to include business associates and subcontractors, should be out by the end of summer, according to Farzad Mostashari, the national coordinator for health information technology.

Submitted in March, the Office of Management and Budget will have up to 90 days to review the rule. HealthDataManagement.com reports Mostashari made the announcement during the opening keynote of the Health Privacy Summit in Washington, D.C.

More Read

HealthCare Twitter for Beginners-Basic Info!
Transforming the Experience and Delivery of Health Care at the Mayo Clinic
Is Your Patient Education Strategy Outdated?
Two Tools To Streamline Your Healthcare Social Media
How to Sell Your EHR and IT Products to Clinics and Physician Practices

When it comes to specific technology and HIPAA hosting requirements, the rule requires:

  1. Information system activity review – organizations must implement procedures to regularly review records of system activity, such as audit logs, access reports and security incident tracking reports. Log monitoring is a service that can address this requirement.
  2. Security reminders – take note of periodic security updates and implement them.
  3. Protection from malicious software – implement procedures for guarding against, detecting and reporting malicious software.
  4. Login monitoring – establish procedures for monitoring login attempts and reporting discrepancies. Multi-factor authentication, or two-factor authentication, is a low-cost and easy way to implement an additional security measure and method of verifying authorized access.
  5. Password management – document procedures for creating, changing and safeguarding passwords.

To ensure any lost or stolen data is recoverable and integrity is intact, the rule also requires:

  1. Data backup plan – establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information (ePHI).
  2. Disaster recovery plan- establish (and implement as needed) procedures to restore any loss of data. [Read more about IT disaster recovery solutions].

According to Lexology.com, overall, the omnibus rule will propose changes to:

  • The Breach Notification Rule.
  • The HIPAA Enforcement Rule, implementing changes mandated by the HITECH Act.
  • The Privacy and Security Rules, implementing changes mandated by the HITECH Act, as well as other changes to the Privacy Rule proposed in July 2010.
  • The Privacy Rule, implementing changes required by the Genetic Information Nondiscrimination Act.

Do and be able to prove your due diligence as a covered entity. Find out the Top 5 Questions to Ask Your HIPAA Hosting Provider and read our HIPAA white paper for a deeper dive into staying compliant and working with business associates.

References:
HIPAA/HITECH Act Privacy Rule Coming in July 2012?
Mostashari: HIPAA Rules Out by Summer’s End

TAGGED:HIT
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

high-risk mdical case
Countdown To Care: What Happens In The 48 Hours Before A High-Risk Medical Case
Health Infographics
March 12, 2026
healthcare facilities
Behind The Cabinets: Why Secure Storage Matters In Modern Healthcare Facilities
Global Healthcare Infographics
March 12, 2026
beyond emergency rooms
Beyond The Emergency Room: Long Term Health Effects After Major Accidents
Health Infographics
March 12, 2026
nurse leaders
Shaping Tomorrow’s Healthcare: The Role of Nurse Leaders
Nursing
March 10, 2026

You Might also Like

Telemedicine in North Carolina

August 14, 2012
HIMSS Virtual Event - mHealth
eHealthMobile Health

Protecting Health Information in the Era of Mobile Devices: The Practicalities & Problems of BYOD

December 12, 2012
AprilSage
eHealth

Accretive Health: No Liability

August 1, 2012
Image
Mobile HealthSocial Media

Tips for Appealing to Millennials: The New Healthcare Boom Market

April 6, 2016
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?