Federal
General Administrative Requirements
61 provisions · Centers for Medicare & Medicaid Services
Provisions
Citable source units
Statutory basis and purpose.
This provision identifies the legislative acts that provide the authority for the HIPAA administrative simplification requirements.
Group
Definitions Scope Authority
Category
Authority Preemption
Domain
Records
Topics
Hipaa statutory basis, Administrative simplification purpose
Applicability.
This provision defines the entities subject to HIPAA standards, including health plans, clearinghouses, and health care providers transmitting electronic health information.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Records
Topics
Hipaa applicability, Covered entities, Business associates
Definitions.
Except as otherwise provided, the following definitions apply to this subchapter:
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Records
Topics
Hipaa definitions, Administrative simplification, Protected health information
Modifications.
This provision outlines the process and frequency by which the Secretary may modify HIPAA standards and implementation specifications.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa standard modifications, Administrative simplification updates
Compliance dates for implementation of new or modified standards and implementation specifications.
This provision establishes the timeline for covered entities and business associates to comply with new or modified HIPAA standards.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa compliance dates, Implementation timelines
Statutory basis.
This provision identifies the legislative acts providing the authority for the HIPAA subpart regarding the preemption of state law.
Group
Definitions Scope Authority
Category
Authority Preemption
Domain
Records
Topics
Hipaa subpart statutory basis
Definitions.
For purposes of this subpart, the following terms have the following meanings:
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Records
Topics
Hipaa definitions, State law preemption, Privacy rule definitions
General rule and exceptions.
This provision establishes that federal HIPAA standards preempt contrary state laws, subject to specific exceptions for fraud, public health, and more stringent privacy protections.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa preemption, State law conflict, Privacy rule preemption
Process for requesting exception determinations.
This section outlines the formal process for states to request an exception from federal preemption for specific state laws.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa exception request, State law exception process
Duration of effectiveness of exception determinations.
This provision specifies the conditions under which an exception to federal preemption remains in effect or is revoked.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa exception duration, Regulatory exception expiration
Applicability.
This section defines the scope of the enforcement subpart, applying to covered entities and business associates regarding HIPAA compliance.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Records
Topics
Hipaa enforcement scope, Administrative simplification applicability
[Reserved]
This provision is reserved and contains no substantive regulatory requirements.
Group
Internal Review
Category
Source Placeholder
Domain
Not Service Specific
Topics
Reserved provision
Principles for achieving compliance.
This section outlines the Secretary's approach to achieving compliance through cooperation and the provision of technical assistance.
Group
Governance Quality Compliance
Category
Compliance Programs
Domain
Governance Quality
Topics
Hipaa compliance cooperation, Technical assistance
Complaints to the Secretary.
This section establishes the right to file a complaint regarding HIPAA noncompliance and outlines the requirements for filing and investigation.
Group
Governance Quality Compliance
Category
Incident Reporting
Domain
Records
Topics
Hipaa complaint filing, Privacy complaint process
Compliance reviews.
This section authorizes the Secretary to conduct compliance reviews to determine adherence to administrative simplification provisions.
Group
Governance Quality Compliance
Category
Compliance Programs
Domain
Records
Topics
Hipaa compliance review, Federal audit process
Responsibilities of covered entities and business associates.
This section mandates that covered entities and business associates maintain records, submit reports, and permit access for compliance investigations.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Hipaa record access, Covered entity responsibilities, Compliance reporting
Secretarial action regarding complaints and compliance reviews.
This section details the procedures for resolving noncompliance, including informal resolution, corrective action plans, and the imposition of civil money penalties.
Group
Governance Quality Compliance
Category
Compliance Programs
Domain
Records
Topics
Hipaa enforcement action, Corrective action plan, Civil money penalty
Investigational subpoenas and inquiries.
This provision outlines the Secretary's authority to issue subpoenas, conduct investigational inquiries, and manage witness testimony and evidence during compliance reviews.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Governance Quality
Topics
Investigational subpoenas, Compliance review procedures, Witness testimony
Refraining from intimidation or retaliation.
A covered entity or business associate may not threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual or other person for—
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Records
Topics
Non Retaliation policy, Whistleblower protection, Hipaa compliance
Applicability.
This provision establishes the scope of subpart D regarding the imposition of civil money penalties by the Secretary under 42 U.S.C. 1320d-5.
Group
Definitions Scope Authority
Category
Scope Applicability
Domain
Not Service Specific
Topics
Civil money penalty scope, Enforcement applicability
Definitions.
This provision defines key terms such as reasonable cause, reasonable diligence, and willful neglect for the purpose of civil money penalty assessments.
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Not Service Specific
Topics
Definition of reasonable cause, Definition of reasonable diligence, Definition of willful neglect
Basis for a civil money penalty.
This provision outlines the conditions under which the Secretary imposes civil money penalties, including liability for agents and affiliated covered entities.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Civil money penalty basis, Agent liability, Affiliated entity liability
Amount of a civil money penalty.
This provision specifies the tiered penalty amounts for HIPAA violations based on the level of culpability and correction status.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Civil money penalty amounts, Penalty tiers, Violation correction
Violations of an identical requirement or prohibition.
This provision explains how the Secretary determines the number of violations for the purpose of calculating civil money penalties, including continuing violations.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Violation counting, Continuing violations
Factors considered in determining the amount of a civil money penalty.
This provision lists the factors the Secretary considers when determining the amount of a civil money penalty, including the nature of the violation and the entity's financial condition.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Penalty determination factors, Mitigating factors, Aggravating factors
Affirmative defenses.
This provision outlines the affirmative defenses available to covered entities and business associates regarding the imposition of civil money penalties.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Affirmative defenses, Penalty mitigation, Violation correction
Waiver.
The Secretary may waive a civil money penalty in whole or in part if payment would be excessive relative to the violation.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Civil money penalty waiver, Hipaa enforcement, Penalty mitigation
Limitations.
Enforcement actions for HIPAA violations must be commenced by the Secretary within six years of the violation's occurrence.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Statute of limitations, Hipaa enforcement, Regulatory action timeline
Authority to settle.
The Secretary retains the authority to settle issues or cases and compromise penalties related to HIPAA violations.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Settlement authority, Hipaa enforcement, Penalty compromise
Penalty not exclusive.
Penalties imposed under this part are in addition to any other penalties prescribed by law, except as otherwise provided.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Cumulative penalties, Hipaa enforcement, Legal liability
Notice of proposed determination.
The Secretary must provide written notice to a respondent regarding the intent to impose a penalty, including findings of fact and instructions for requesting a hearing.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Notice of proposed determination, Hipaa enforcement, Due process
Failure to request a hearing.
If a respondent fails to request a hearing within the prescribed time, the Secretary will impose the proposed penalty, which becomes final upon receipt of notice.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Hearing request deadline, Hipaa enforcement, Final penalty determination
Collection of penalty.
Once a penalty determination is final, the Secretary may recover the amount through civil action or deduction from sums owed by the United States or a State agency.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Penalty collection, Hipaa enforcement, Civil action
Notification of the public and other agencies.
Upon a final penalty determination, the Secretary will notify the public and relevant professional, state, and licensing organizations of the penalty and the reasons for its imposition.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Public notification, Hipaa enforcement, Regulatory reporting
Applicability.
This subpart applies to hearings conducted regarding the imposition of civil money penalties by the Secretary under HIPAA.
Group
Health It Privacy Security
Category
HIPAA Privacy Security
Domain
Not Service Specific
Topics
Hearing applicability, Hipaa enforcement, Administrative law
Definitions.
Defines the 'Board' as the members of the HHS Departmental Appeals Board who issue decisions in panels of three.
Group
Definitions Scope Authority
Category
Definitions Context
Domain
Not Service Specific
Topics
Definitions, Departmental appeals board, Hipaa enforcement
Hearing before an ALJ.
This provision outlines the process for a respondent to request a hearing before an Administrative Law Judge regarding a proposed HIPAA enforcement determination.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Alj hearing request, Hipaa enforcement, Administrative hearing process
Rights of the parties.
This provision defines the procedural rights of parties during an administrative hearing, including representation, discovery, and evidence presentation.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Hearing party rights, Legal representation, Evidence presentation
Authority of the ALJ.
This provision details the powers and limitations of the Administrative Law Judge in conducting hearings, including managing evidence, motions, and procedural conduct.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Alj authority, Hearing management, Procedural rulings
Ex parte contacts.
This provision prohibits unauthorized private communications between parties and the Administrative Law Judge regarding matters at issue in a case.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Ex parte communication, Hearing integrity
Prehearing conferences.
This provision mandates the scheduling of prehearing conferences to simplify issues, manage discovery, and facilitate potential settlement of administrative cases.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Prehearing conference, Case management, Settlement discussions
Authority to settle.
This provision establishes that the Secretary of HHS maintains exclusive authority to settle any issue or case without the consent of the Administrative Law Judge.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Settlement authority, Hhs enforcement
Discovery.
This provision governs the production of documents and data during the discovery phase of an administrative hearing, including limitations and protective orders.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Discovery process, Document production, Protective orders
Exchange of witness lists, witness statements, and exhibits.
This provision requires parties to exchange witness lists, statements, and exhibits within specified timeframes prior to an administrative hearing.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Witness list exchange, Evidence exchange, Hearing preparation
Subpoenas for attendance at hearing.
This provision outlines the process for requesting and serving subpoenas to compel witness attendance and document production for administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Subpoena process, Witness attendance, Document production
Fees.
This provision requires the party requesting a subpoena to pay the associated witness fees and mileage costs as determined by federal court standards.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Witness fees, Subpoena costs
Form, filing, and service of papers.
This provision establishes the requirements for the form, filing, and service of documents in administrative hearings regarding HIPAA violations.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Legal filing requirements, Hipaa enforcement
Computation of time.
This provision defines the methods for calculating time periods for filings and responses in administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Time computation rules
Motions.
This provision outlines the requirements for filing and responding to motions during administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Motion practice
Sanctions.
The ALJ may sanction a person, including any party or attorney, for failing to comply with an order or procedure, for failing to defend an action or for other misconduct that interferes with the speedy, orderly or fair conduct of the hea...
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Governance Quality
Topics
Administrative law judge sanctions, Hearing misconduct, Procedural compliance
Collateral estoppel.
This provision specifies that a final determination of a HIPAA violation in a prior proceeding is binding in subsequent proceedings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Collateral estoppel
The hearing.
This provision outlines the conduct of the administrative hearing, including burdens of proof and public access requirements.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Burden of proof, Hearing conduct
Statistical sampling.
This provision allows the Secretary to use statistical sampling as evidence of violations in administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Statistical evidence, Burden of proof
Witnesses.
This provision governs the presentation of witness testimony, including cross-examination and exclusion of witnesses in administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Witness testimony, Cross examination
Evidence.
This provision outlines the rules for the admissibility and exclusion of evidence in administrative hearings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Evidentiary rules
The record.
This provision defines the composition of the hearing record and requirements for transcripts and public access.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Hearing record
Post hearing briefs.
This provision authorizes the ALJ to require post-hearing briefs and sets timelines for their submission.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative hearing procedures, Post hearing briefs
ALJ's decision.
This provision outlines the requirements for an Administrative Law Judge to issue a decision based on the record, including findings of fact and conclusions of law, and establishes the timeline for finality.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative law judge decision, Civil money penalty enforcement
Appeal of the ALJ's decision.
This provision details the procedures for appealing an Administrative Law Judge's decision to the Board, including filing requirements, standards of review, and the process for judicial review.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Administrative appeal process, Civil money penalty appeals, Judicial review
Stay of the Secretary's decision.
This provision establishes the process for a respondent to request a stay of a penalty pending judicial review, contingent upon posting a bond or security.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Stay of penalty, Judicial review of penalties
Harmless error.
This provision mandates that the ALJ and the Board must disregard procedural errors that do not affect the substantial rights of the parties in administrative proceedings.
Group
Governance Quality Compliance
Category
Survey Certification Enforcement
Domain
Not Service Specific
Topics
Harmless error doctrine, Administrative hearing procedures
