Policy Prism AI

General Administrative Requirements

Federal

General Administrative Requirements

61 provisions · Centers for Medicare & Medicaid Services

Provisions

Citable source units

45 CFR § 160.101Authority PreemptionHIPAA Privacy Security

Statutory basis and purpose.

This provision identifies the legislative acts that provide the authority for the HIPAA administrative simplification requirements.

Group

Definitions Scope Authority

Category

Authority Preemption

Domain

Records

Topics

Hipaa statutory basis, Administrative simplification purpose

Read provision
45 CFR § 160.102Scope ApplicabilityHIPAA Privacy Security

Applicability.

This provision defines the entities subject to HIPAA standards, including health plans, clearinghouses, and health care providers transmitting electronic health information.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Records

Topics

Hipaa applicability, Covered entities, Business associates

Read provision
45 CFR § 160.103Definitions ContextHIPAA Privacy Security

Definitions.

Except as otherwise provided, the following definitions apply to this subchapter:

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Records

Topics

Hipaa definitions, Administrative simplification, Protected health information

Read provision
45 CFR § 160.104HIPAA Privacy Security

Modifications.

This provision outlines the process and frequency by which the Secretary may modify HIPAA standards and implementation specifications.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa standard modifications, Administrative simplification updates

Read provision
45 CFR § 160.105HIPAA Privacy Security

Compliance dates for implementation of new or modified standards and implementation specifications.

This provision establishes the timeline for covered entities and business associates to comply with new or modified HIPAA standards.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa compliance dates, Implementation timelines

Read provision
45 CFR § 160.201Authority PreemptionHIPAA Privacy Security

Statutory basis.

This provision identifies the legislative acts providing the authority for the HIPAA subpart regarding the preemption of state law.

Group

Definitions Scope Authority

Category

Authority Preemption

Domain

Records

Topics

Hipaa subpart statutory basis

Read provision
45 CFR § 160.202Definitions ContextHIPAA Privacy Security

Definitions.

For purposes of this subpart, the following terms have the following meanings:

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Records

Topics

Hipaa definitions, State law preemption, Privacy rule definitions

Read provision
45 CFR § 160.203HIPAA Privacy SecurityAuthority Preemption

General rule and exceptions.

This provision establishes that federal HIPAA standards preempt contrary state laws, subject to specific exceptions for fraud, public health, and more stringent privacy protections.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa preemption, State law conflict, Privacy rule preemption

Read provision
45 CFR § 160.204HIPAA Privacy SecurityAuthority Preemption

Process for requesting exception determinations.

This section outlines the formal process for states to request an exception from federal preemption for specific state laws.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa exception request, State law exception process

Read provision
45 CFR § 160.205HIPAA Privacy SecurityAuthority Preemption

Duration of effectiveness of exception determinations.

This provision specifies the conditions under which an exception to federal preemption remains in effect or is revoked.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa exception duration, Regulatory exception expiration

Read provision
45 CFR § 160.300Scope ApplicabilityHIPAA Privacy Security

Applicability.

This section defines the scope of the enforcement subpart, applying to covered entities and business associates regarding HIPAA compliance.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Records

Topics

Hipaa enforcement scope, Administrative simplification applicability

Read provision
45 CFR § 160.302Source Placeholder

[Reserved]

This provision is reserved and contains no substantive regulatory requirements.

Group

Internal Review

Category

Source Placeholder

Domain

Not Service Specific

Topics

Reserved provision

Read provision
45 CFR § 160.304Compliance ProgramsHIPAA Privacy Security

Principles for achieving compliance.

This section outlines the Secretary's approach to achieving compliance through cooperation and the provision of technical assistance.

Group

Governance Quality Compliance

Category

Compliance Programs

Domain

Governance Quality

Topics

Hipaa compliance cooperation, Technical assistance

Read provision
45 CFR § 160.306Incident ReportingHIPAA Privacy Security

Complaints to the Secretary.

This section establishes the right to file a complaint regarding HIPAA noncompliance and outlines the requirements for filing and investigation.

Group

Governance Quality Compliance

Category

Incident Reporting

Domain

Records

Topics

Hipaa complaint filing, Privacy complaint process

Read provision
45 CFR § 160.308Compliance ProgramsHIPAA Privacy Security

Compliance reviews.

This section authorizes the Secretary to conduct compliance reviews to determine adherence to administrative simplification provisions.

Group

Governance Quality Compliance

Category

Compliance Programs

Domain

Records

Topics

Hipaa compliance review, Federal audit process

Read provision
45 CFR § 160.310HIPAA Privacy SecurityCompliance Programs

Responsibilities of covered entities and business associates.

This section mandates that covered entities and business associates maintain records, submit reports, and permit access for compliance investigations.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Hipaa record access, Covered entity responsibilities, Compliance reporting

Read provision
45 CFR § 160.312Compliance ProgramsHIPAA Privacy Security

Secretarial action regarding complaints and compliance reviews.

This section details the procedures for resolving noncompliance, including informal resolution, corrective action plans, and the imposition of civil money penalties.

Group

Governance Quality Compliance

Category

Compliance Programs

Domain

Records

Topics

Hipaa enforcement action, Corrective action plan, Civil money penalty

Read provision
45 CFR § 160.314Survey Certification EnforcementMedical Records

Investigational subpoenas and inquiries.

This provision outlines the Secretary's authority to issue subpoenas, conduct investigational inquiries, and manage witness testimony and evidence during compliance reviews.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Governance Quality

Topics

Investigational subpoenas, Compliance review procedures, Witness testimony

Read provision
45 CFR § 160.316HIPAA Privacy SecurityPatient Rights

Refraining from intimidation or retaliation.

A covered entity or business associate may not threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual or other person for—

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Records

Topics

Non Retaliation policy, Whistleblower protection, Hipaa compliance

Read provision
45 CFR § 160.400Scope ApplicabilitySurvey Certification Enforcement

Applicability.

This provision establishes the scope of subpart D regarding the imposition of civil money penalties by the Secretary under 42 U.S.C. 1320d-5.

Group

Definitions Scope Authority

Category

Scope Applicability

Domain

Not Service Specific

Topics

Civil money penalty scope, Enforcement applicability

Read provision
45 CFR § 160.401Definitions ContextSurvey Certification Enforcement

Definitions.

This provision defines key terms such as reasonable cause, reasonable diligence, and willful neglect for the purpose of civil money penalty assessments.

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Not Service Specific

Topics

Definition of reasonable cause, Definition of reasonable diligence, Definition of willful neglect

Read provision
45 CFR § 160.402Survey Certification Enforcement

Basis for a civil money penalty.

This provision outlines the conditions under which the Secretary imposes civil money penalties, including liability for agents and affiliated covered entities.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Civil money penalty basis, Agent liability, Affiliated entity liability

Read provision
45 CFR § 160.404Survey Certification Enforcement

Amount of a civil money penalty.

This provision specifies the tiered penalty amounts for HIPAA violations based on the level of culpability and correction status.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Civil money penalty amounts, Penalty tiers, Violation correction

Read provision
45 CFR § 160.406Survey Certification Enforcement

Violations of an identical requirement or prohibition.

This provision explains how the Secretary determines the number of violations for the purpose of calculating civil money penalties, including continuing violations.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Violation counting, Continuing violations

Read provision
45 CFR § 160.408Survey Certification Enforcement

Factors considered in determining the amount of a civil money penalty.

This provision lists the factors the Secretary considers when determining the amount of a civil money penalty, including the nature of the violation and the entity's financial condition.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Penalty determination factors, Mitigating factors, Aggravating factors

Read provision
45 CFR § 160.410Survey Certification Enforcement

Affirmative defenses.

This provision outlines the affirmative defenses available to covered entities and business associates regarding the imposition of civil money penalties.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Affirmative defenses, Penalty mitigation, Violation correction

Read provision
45 CFR § 160.412HIPAA Privacy SecuritySurvey Certification Enforcement

Waiver.

The Secretary may waive a civil money penalty in whole or in part if payment would be excessive relative to the violation.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Civil money penalty waiver, Hipaa enforcement, Penalty mitigation

Read provision
45 CFR § 160.414HIPAA Privacy SecuritySurvey Certification Enforcement

Limitations.

Enforcement actions for HIPAA violations must be commenced by the Secretary within six years of the violation's occurrence.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Statute of limitations, Hipaa enforcement, Regulatory action timeline

Read provision
45 CFR § 160.416HIPAA Privacy SecuritySurvey Certification Enforcement

Authority to settle.

The Secretary retains the authority to settle issues or cases and compromise penalties related to HIPAA violations.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Settlement authority, Hipaa enforcement, Penalty compromise

Read provision
45 CFR § 160.418HIPAA Privacy SecuritySurvey Certification Enforcement

Penalty not exclusive.

Penalties imposed under this part are in addition to any other penalties prescribed by law, except as otherwise provided.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Cumulative penalties, Hipaa enforcement, Legal liability

Read provision
45 CFR § 160.420HIPAA Privacy SecuritySurvey Certification Enforcement

Notice of proposed determination.

The Secretary must provide written notice to a respondent regarding the intent to impose a penalty, including findings of fact and instructions for requesting a hearing.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Notice of proposed determination, Hipaa enforcement, Due process

Read provision
45 CFR § 160.422HIPAA Privacy SecuritySurvey Certification Enforcement

Failure to request a hearing.

If a respondent fails to request a hearing within the prescribed time, the Secretary will impose the proposed penalty, which becomes final upon receipt of notice.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Hearing request deadline, Hipaa enforcement, Final penalty determination

Read provision
45 CFR § 160.424HIPAA Privacy SecuritySurvey Certification Enforcement

Collection of penalty.

Once a penalty determination is final, the Secretary may recover the amount through civil action or deduction from sums owed by the United States or a State agency.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Penalty collection, Hipaa enforcement, Civil action

Read provision
45 CFR § 160.426HIPAA Privacy SecuritySurvey Certification Enforcement

Notification of the public and other agencies.

Upon a final penalty determination, the Secretary will notify the public and relevant professional, state, and licensing organizations of the penalty and the reasons for its imposition.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Public notification, Hipaa enforcement, Regulatory reporting

Read provision
45 CFR § 160.500HIPAA Privacy SecurityScope Applicability

Applicability.

This subpart applies to hearings conducted regarding the imposition of civil money penalties by the Secretary under HIPAA.

Group

Health It Privacy Security

Category

HIPAA Privacy Security

Domain

Not Service Specific

Topics

Hearing applicability, Hipaa enforcement, Administrative law

Read provision
45 CFR § 160.502Definitions ContextHIPAA Privacy Security

Definitions.

Defines the 'Board' as the members of the HHS Departmental Appeals Board who issue decisions in panels of three.

Group

Definitions Scope Authority

Category

Definitions Context

Domain

Not Service Specific

Topics

Definitions, Departmental appeals board, Hipaa enforcement

Read provision
45 CFR § 160.504Survey Certification EnforcementHIPAA Privacy Security

Hearing before an ALJ.

This provision outlines the process for a respondent to request a hearing before an Administrative Law Judge regarding a proposed HIPAA enforcement determination.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Alj hearing request, Hipaa enforcement, Administrative hearing process

Read provision
45 CFR § 160.506Survey Certification EnforcementHIPAA Privacy Security

Rights of the parties.

This provision defines the procedural rights of parties during an administrative hearing, including representation, discovery, and evidence presentation.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Hearing party rights, Legal representation, Evidence presentation

Read provision
45 CFR § 160.508Survey Certification EnforcementHIPAA Privacy Security

Authority of the ALJ.

This provision details the powers and limitations of the Administrative Law Judge in conducting hearings, including managing evidence, motions, and procedural conduct.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Alj authority, Hearing management, Procedural rulings

Read provision
45 CFR § 160.510Survey Certification EnforcementHIPAA Privacy Security

Ex parte contacts.

This provision prohibits unauthorized private communications between parties and the Administrative Law Judge regarding matters at issue in a case.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Ex parte communication, Hearing integrity

Read provision
45 CFR § 160.512Survey Certification EnforcementHIPAA Privacy Security

Prehearing conferences.

This provision mandates the scheduling of prehearing conferences to simplify issues, manage discovery, and facilitate potential settlement of administrative cases.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Prehearing conference, Case management, Settlement discussions

Read provision
45 CFR § 160.514Survey Certification EnforcementHIPAA Privacy Security

Authority to settle.

This provision establishes that the Secretary of HHS maintains exclusive authority to settle any issue or case without the consent of the Administrative Law Judge.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Settlement authority, Hhs enforcement

Read provision
45 CFR § 160.516Survey Certification EnforcementHIPAA Privacy Security

Discovery.

This provision governs the production of documents and data during the discovery phase of an administrative hearing, including limitations and protective orders.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Discovery process, Document production, Protective orders

Read provision
45 CFR § 160.518Survey Certification EnforcementHIPAA Privacy Security

Exchange of witness lists, witness statements, and exhibits.

This provision requires parties to exchange witness lists, statements, and exhibits within specified timeframes prior to an administrative hearing.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Witness list exchange, Evidence exchange, Hearing preparation

Read provision
45 CFR § 160.520Survey Certification EnforcementHIPAA Privacy Security

Subpoenas for attendance at hearing.

This provision outlines the process for requesting and serving subpoenas to compel witness attendance and document production for administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Subpoena process, Witness attendance, Document production

Read provision
45 CFR § 160.522Survey Certification EnforcementHIPAA Privacy Security

Fees.

This provision requires the party requesting a subpoena to pay the associated witness fees and mileage costs as determined by federal court standards.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Witness fees, Subpoena costs

Read provision
45 CFR § 160.524Survey Certification EnforcementHIPAA Privacy Security

Form, filing, and service of papers.

This provision establishes the requirements for the form, filing, and service of documents in administrative hearings regarding HIPAA violations.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Legal filing requirements, Hipaa enforcement

Read provision
45 CFR § 160.526Survey Certification EnforcementHIPAA Privacy Security

Computation of time.

This provision defines the methods for calculating time periods for filings and responses in administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Time computation rules

Read provision
45 CFR § 160.528Survey Certification EnforcementHIPAA Privacy Security

Motions.

This provision outlines the requirements for filing and responding to motions during administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Motion practice

Read provision
45 CFR § 160.530Survey Certification EnforcementAuthority Preemption

Sanctions.

The ALJ may sanction a person, including any party or attorney, for failing to comply with an order or procedure, for failing to defend an action or for other misconduct that interferes with the speedy, orderly or fair conduct of the hea...

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Governance Quality

Topics

Administrative law judge sanctions, Hearing misconduct, Procedural compliance

Read provision
45 CFR § 160.532Survey Certification EnforcementHIPAA Privacy Security

Collateral estoppel.

This provision specifies that a final determination of a HIPAA violation in a prior proceeding is binding in subsequent proceedings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Collateral estoppel

Read provision
45 CFR § 160.534Survey Certification EnforcementHIPAA Privacy Security

The hearing.

This provision outlines the conduct of the administrative hearing, including burdens of proof and public access requirements.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Burden of proof, Hearing conduct

Read provision
45 CFR § 160.536Survey Certification EnforcementHIPAA Privacy Security

Statistical sampling.

This provision allows the Secretary to use statistical sampling as evidence of violations in administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Statistical evidence, Burden of proof

Read provision
45 CFR § 160.538Survey Certification EnforcementHIPAA Privacy Security

Witnesses.

This provision governs the presentation of witness testimony, including cross-examination and exclusion of witnesses in administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Witness testimony, Cross examination

Read provision
45 CFR § 160.540Survey Certification EnforcementHIPAA Privacy Security

Evidence.

This provision outlines the rules for the admissibility and exclusion of evidence in administrative hearings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Evidentiary rules

Read provision
45 CFR § 160.542Survey Certification EnforcementHIPAA Privacy Security

The record.

This provision defines the composition of the hearing record and requirements for transcripts and public access.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Hearing record

Read provision
45 CFR § 160.544Survey Certification EnforcementHIPAA Privacy Security

Post hearing briefs.

This provision authorizes the ALJ to require post-hearing briefs and sets timelines for their submission.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative hearing procedures, Post hearing briefs

Read provision
45 CFR § 160.546Survey Certification EnforcementDefinitions Context

ALJ's decision.

This provision outlines the requirements for an Administrative Law Judge to issue a decision based on the record, including findings of fact and conclusions of law, and establishes the timeline for finality.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative law judge decision, Civil money penalty enforcement

Read provision
45 CFR § 160.548Survey Certification Enforcement

Appeal of the ALJ's decision.

This provision details the procedures for appealing an Administrative Law Judge's decision to the Board, including filing requirements, standards of review, and the process for judicial review.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Administrative appeal process, Civil money penalty appeals, Judicial review

Read provision
45 CFR § 160.550Survey Certification Enforcement

Stay of the Secretary's decision.

This provision establishes the process for a respondent to request a stay of a penalty pending judicial review, contingent upon posting a bond or security.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Stay of penalty, Judicial review of penalties

Read provision
45 CFR § 160.552Survey Certification Enforcement

Harmless error.

This provision mandates that the ALJ and the Board must disregard procedural errors that do not affect the substantial rights of the parties in administrative proceedings.

Group

Governance Quality Compliance

Category

Survey Certification Enforcement

Domain

Not Service Specific

Topics

Harmless error doctrine, Administrative hearing procedures

Read provision