HIPAA compliance

HIPAA Omnibus Rule: How It Changed Healthcare Compliance

The HIPAA Omnibus Rule is the most significant expansion of the Health Insurance Portability and Accountability Act since the law was enacted in 1996. Published by the U.S.

HIPAA Omnibus Rule: How It Changed Healthcare Compliance

The HIPAA Omnibus Rule is the most significant expansion of the Health Insurance Portability and Accountability Act since the law was enacted in 1996. Published by the U.S. Department of Health and Human Services (HHS) on January 25, 2013, and effective September 23, 2013, the Rule brought Business Associates under direct HIPAA enforcement, strengthened patient rights, restructured civil penalty tiers, and replaced the previous breach notification standard with a stricter presumption-of-breach model. Any organization that handles Protected Health Information (PHI)—directly or indirectly—operates under rules shaped by the rule.

What Is the HIPAA Omnibus Rule and Who Does It Apply To?

The HIPAA Omnibus Rule is a federal regulation that amended and consolidated four existing HIPAA rules into one enforceable framework to close critical gaps that had emerged as healthcare moved into the digital era.

The rule applies to two categories of entities. The first is Covered Entities—hospitals, physician practices, health plans, and healthcare clearinghouses. The second is Business Associates (BAs)—any third-party vendor, contractor, or subcontractor that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity.

Before this rule, business associates had limited direct liability. After September 23, 2013, the Office for Civil Rights (OCR) at HHS gained authority to audit and fine business associates directly — without requiring a covered entity to be involved. Subcontractors of Business Associates are also covered. The chain of liability now extends to every link in the PHI supply chain.

Why Was the HIPAA Omnibus Rule Introduced?

 

Connection to the HITECH Act and Digital Transformation

The HITECH Act (Health Information Technology for Economic and Clinical Health Act), enacted in 2009, created the legal foundation for the rule. The HITECH Act expanded HIPAA's scope to cover business associates, authorized HHS to increase civil penalties, and mandated new breach notification requirements. This rule implemented these HITECH Act provisions into enforceable regulations.

The shift to Electronic Health Records (EHRs) created a new landscape for PHI exposure. By 2013, millions of patient records were being transmitted digitally across covered entities, business associates, and subcontractors. The pre-2013 regulatory structure had not kept pace with that transformation.

 

Rising Data Breach Trends in Healthcare

Healthcare data breaches were accelerating when the Omnibus Rule was drafted. According to data from the HHS Office for Civil Rights breach portal, the run-up to the Omnibus Rule saw a sharp increase in compromises, with over 500 major health data breaches reported between 2010 and 2012 alone—frequently exposing security gaps among third-party business associates who lacked direct statutory liability at the time.

 

Closing Pre-2013 Regulatory Gaps and Enforcement Weaknesses

Before the Omnibus Rule, Business Associate Agreements (BAAs) were the primary mechanism for controlling third-party PHI risk. But BAAs were not standardized. Many contained weak privacy provisions. HHS could not directly fine a business associate that violated HIPAA—it could only pursue the covered entity that had hired them.

This rule closed that gap. Business associates now bear direct responsibility for HIPAA compliance, regardless of what their BAA says or does not say.

What Major Changes Did the Omnibus Rule Introduce?




Direct Liability Shift for Business Associates and Subcontractors

Business associates became directly liable for HIPAA Privacy and Security Rule compliance after the Omnibus Rule took effect. The OCR can now investigate and penalize business associates independently. Subcontractors—entities that work for business associates—also became subject to the same obligations.

 

Stronger Patient Privacy Rights — Access to EHRs and Out-of-Pocket Restrictions

The HIPAA Omnibus Rule expanded individual rights in two significant ways. First, patients gained the right to receive an electronic copy of their health records when a covered entity maintains EHRs. Second, patients who pay out-of-pocket in full for a service can instruct their provider not to share that information with their health plan. These rights must be documented in each organization's Notice of Privacy Practices (NPP) and must be honored operationally.

 

New Restrictions on Marketing and Sale of PHI

Covered Entities can no longer use PHI for marketing communications involving financial remuneration from a third party without explicit patient authorization. Fundraising communications must include an easy opt-out mechanism. The sale of PHI without patient authorization is explicitly prohibited.

 

Genetic Information Under GINA

The Omnibus Rule classified genetic information as a category of PHI by implementing provisions of the Genetic Information Nondiscrimination Act (GINA). Health plans are prohibited from using genetic information for underwriting purposes.

 

The Presumption-of-Breach Standard

The pre-2013 breach notification standard allowed organizations to decline notification if they determined there was no significant risk of harm. The Omnibus Rule replaced that with a presumption-of-breach standard. Any impermissible use or disclosure of PHI is now presumed to be a breach—requiring notification—unless the organization can demonstrate through a documented four-factor risk assessment that there is a low probability PHI has been compromised. The burden of proof shifted entirely to the organization.

 

The 4-Tiered Civil Penalty Enforcement System

The Omnibus Rule formalized a four-tiered civil penalty structure based on culpability. While the baseline statutory limits started at $100 to $50,000 per violation, these numbers are adjusted annually for inflation by HHS under the Federal Civil Penalties Inflation Adjustment Act.

Additionally, under the OCR's current enforcement discretion policy, the annual penalty caps for identical violations within a calendar year are tiered strictly by intent level—ranging from lower localized caps for absolute lack of knowledge up to a maximum inflation-adjusted ceiling exceeding $2.1 million per year for uncorrected willful neglect. Because multiple distinct violation types can be cited within a single data breach incident, total penalty exposure frequently compounds far beyond the single annual cap. 

What Do Regulators Actually Require Under the Rule?

The OCR at HHS is the primary enforcement body for the HIPAA Omnibus Rule. The OCR enforces the HIPAA Privacy Rule, the HIPAA Security Rule, and the Breach Notification Rule — all of which the Omnibus Rule amended.

The OCR requires every Covered Entity and Business Associate to conduct a formal Security Risk Assessment (SRA) — a documented analysis of threats, vulnerabilities, and risks to PHI. The SRA is not optional and must be updated regularly, particularly after a system change, a merger, or the onboarding of a new vendor.

The OCR also requires all Business Associate Agreements to be updated to reflect the rules of the expanded Omnibus compliance obligations. Any BAA signed before September 23, 2013 that has not been renegotiated is non-compliant.

According to official enforcement data published by the HHS Office for Civil Rights, the agency has levied enforcement actions resulting in financial settlements and civil monetary penalties totaling well over $185 million. Organizations found to have committed willful neglect with no corrective action face the highest penalty tiers.

 

What Are the Warning Signs of Non-Compliance?

 

Red Flags in Vendor and Subcontractor Management — Missing or Outdated BAAs

  • No centralized BAA register: Your organization cannot produce a current BAA for every active vendor or subcontractor that touches PHI within 48 hours.

  • BAAs signed before September 23, 2013: Pre-Omnibus BAAs do not reflect a business associate's direct liability, the updated breach notification standard, or subcontractor obligations.

  • Subcontractor BAAs are absent: Your primary vendor has signed a BAA with your organization but cannot confirm that its own subcontractors have signed compliant BAAs.

  • No vendor reassessment process: Vendors are onboarded with a BAA and never reviewed again, regardless of how their services or data handling practices change.

 

Operational Warning Signs — Lack of Logging and Excessive Access Privileges

  • No PHI access logging: Your EHR or data system does not generate audit logs showing who accessed which patient records, when, and from what device.

  • Excessive access privileges: Staff have access to PHI beyond what their role requires. The HIPAA Privacy Rule's minimum necessary standard is not operationally enforced.

  • No breach response plan: Your organization has a written policy but no documented, tested breach response procedure that covers business associate incidents.

  • Delayed breach reporting: Staff are uncertain about when a PHI exposure triggers notification obligations — and the four-factor risk assessment has never been conducted in practice.

 

Technical Security Weaknesses — Lack of Encryption and MFA Gaps

  • PHI transmitted unencrypted: Emails containing PHI are sent without encryption. File transfers between systems do not use Transport Layer Security (TLS).

  • No Multi-Factor Authentication (MFA) on EHR access: Staff log in to systems containing PHI with a username and password only.

  • No encryption at rest: PHI stored on laptops, portable devices, or cloud environments is not encrypted. A lost device becomes a reportable breach.

  • Outdated software with known vulnerabilities: Systems running unpatched operating systems or legacy EHR software remain exposed to the class of attacks responsible for most large breaches reported to the OCR.

From 2013 to 2026: The Evolution and Future of HIPAA Compliance

The HIPAA Omnibus Rule of 2013 established the current enforcement framework, but HIPAA compliance has continued to evolve through OCR guidance, enforcement settlements, and regulatory updates.

In December 2020, HHS proposed modifications to the HIPAA Privacy Rule focused on individual access rights and care coordination. In February 2024, HHS released updated guidance on reproductive health data privacy. The OCR continues to issue enforcement settlements that clarify how the rule applies to specific scenarios—including multi-state telehealth, cloud-hosted EHRs, and AI-assisted diagnostics.

Most notably, covered entities faced a mandatory compliance deadline on February 16, 2026, to implement comprehensive revisions to their Notice of Privacy Practices (NPP). This 2026 mandate requires organizations to update their NPP language to explicitly cover substance use disorder (SUD) patient records, aligning traditional HIPAA protections with the stricter requirements of 42 CFR Part 2. Any healthcare organization operating with an outdated NPP framework drafted prior to these unified healthcare privacy changes is actively out of compliance. 

The trajectory of HIPAA enforcement points toward stricter scrutiny of business associate relationships, greater enforcement of the security risk assessment requirement, and increased penalties for organizations that demonstrate willful neglect. The HIPAA Rule created the framework—enforcement actions since 2013 have steadily expanded how that framework is applied.

What Happens If You Fail to Comply With the Omnibus Rule?

Failure to comply with the HIPAA Omnibus Rule exposes covered entities and business associates to OCR investigation, civil monetary penalties, corrective action plans, and reputational damage.

The OCR initiates investigations from two sources: breach reports filed by organizations and complaints filed by individuals. Both pathways can result in a full compliance review that covers the Privacy Rule, Security Rule, and Breach Notification Rule — not just the specific incident that triggered the investigation.

The largest settlements to date emphasize this cross-enterprise risk. These include a historic $16 million settlement with Anthem Inc. in 2018 following a cyberattack affecting 78.8 million individuals and a $3.5 million settlement with Fresenius Medical Care North America in 2018 that resolved five separate breach incidents across various operating branches. Both cases involved structural failures that standard HIPAA administrative controls—such as enterprise-wide risk assessments and proactive encryption—were legally required to prevent. 

State attorneys general also have independent authority to enforce HIPAA. Texas, New York, and California have each pursued HIPAA enforcement actions independently of the OCR. Non-compliance is not solely a federal exposure.

Quick-Start Checklist for Staying Compliant

 



Conduct Regular, Documented Security Risk Assessments

Complete a new SRA at least annually, or after any significant system change, vendor addition, or facility expansion. Use the HHS Security Risk Assessment Tool or a qualified third-party assessor. Document identified risks and implement a remediation plan with assigned owners and deadlines—an SRA without a follow-up action plan does not satisfy OCR requirements.

 

Audit the BAA Chain Down to Subcontractors

Maintain a centralized BAA register listing every vendor and subcontractor with PHI access. Require primary business associates to certify in writing that their subcontractors have signed compliant BAAs. Review and renew BAAs every two years or whenever a vendor's service scope changes.

 

Enforce Technical Safeguards

Require MFA for all access to systems containing PHI. Encrypt all PHI at rest using AES-256 and in transit using TLS 1.2 or higher. A lost or stolen device with encrypted PHI is not a reportable breach.

 

Train Staff and Simulate Breach Response

Deliver role-specific HIPAA training—compliance officers, IT staff, clinical staff, and business associate employees face different obligations. Conduct a breach response simulation at least once per year. Document all training with completion records; the OCR will request this documentation in any audit or investigation.

If you are responsible for HIPAA compliance in your organization, structured training is the most reliable way to reduce enforcement risk and build staff confidence. The HIPAA Compliance Training - Executive Certification Program walks compliance professionals through real Omnibus Rule scenarios and the correct responses—in a format built for busy healthcare and digital health teams. 

Frequently Asked Questions

01 Who must comply with the HIPAA Omnibus Rule? +

The rule applies to two groups. The first group are Covered Entities—healthcare providers, health plans, and healthcare clearinghouses. The second group is business associates—any individual or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. This includes IT vendors, cloud hosting providers, billing companies, legal firms, and data analytics companies. Subcontractors of Business Associates also fall under the rule's scope. If a subcontractor handles PHI, it carries the same direct HIPAA obligations as the primary business associate, regardless of what its contract says.

02 What did the Omnibus Rule of 2013 do? +

The HIPAA Omnibus Rule of 2013 made six major changes to HIPAA. It gave the Office for Civil Rights authority to fine business associates directly. It replaced the risk-of-harm breach notification standard with a presumption-of-breach standard. It strengthened patients' rights to access electronic health records and restrict disclosures to health plans for services paid out-of-pocket. It restricted the use of PHI for marketing without patient authorization. It prohibited the sale of PHI without explicit patient consent. It also incorporated Genetic Information Nondiscrimination Act protections by classifying genetic data as a protected category under HIPAA. The effective date was September 23, 2013.

03 What is the maximum fine for a HIPAA Omnibus Rule violation? +

Adjusted for inflation under the Federal Civil Penalties Inflation Adjustment Act, the maximum civil monetary penalty cap for identical HIPAA violations within a single calendar year stands at more than $2.1 million for the highest tier of culpability. This cap applies to each violation category independently. An organization found to have committed distinct infractions simultaneously—such as failing to execute a Security Risk Assessment while simultaneously allowing an impermissible disclosure of PHI—will face separate annual caps for each category, driving potential liability exponentially higher. 

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.