federal_register: E9-20169
Data license: Public Domain (U.S. Government data) · Data source: Federal Register API & Regulations.gov API
This data as json
| document_number | title | type | abstract | publication_date | pub_year | pub_month | html_url | pdf_url | agency_names | agency_ids | excerpts | regulation_id_numbers |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| E9-20169 | Breach Notification for Unsecured Protected Health Information | Rule | The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to require notification of breaches of unsecured protected health information. Section 13402 of the Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the American Recovery and Reinvestment Act of 2009 (ARRA) that was enacted on February 17, 2009, requires HHS to issue interim final regulations within 180 days to require covered entities under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and their business associates to provide notification in the case of breaches of unsecured protected health information. For purposes of determining what information is "unsecured protected health information," in this document HHS is also issuing an update to its guidance specifying the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals. | 2009-08-24 | 2009 | 8 | https://www.federalregister.gov/documents/2009/08/24/E9-20169/breach-notification-for-unsecured-protected-health-information | https://www.govinfo.gov/content/pkg/FR-2009-08-24/pdf/E9-20169.pdf | Health and Human Services Department | 221 | The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to require notification of breaches of unsecured protected health information. Section 13402 of the Health Information Technology for... |