HIPAA Omnibus Rule Changes Explained: Key Updates for Covered Entities and Business Associates

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Omnibus Rule Changes Explained: Key Updates for Covered Entities and Business Associates

Kevin Henry

HIPAA

April 26, 2026

7 minutes read
Share this article
HIPAA Omnibus Rule Changes Explained: Key Updates for Covered Entities and Business Associates

HIPAA Omnibus Rule Overview

The HIPAA Omnibus Rule consolidated and finalized HITECH Act provisions to strengthen privacy safeguards for electronic protected health information (ePHI), expand individual rights, and increase accountability across the healthcare ecosystem. It updates the Privacy, Security, Breach Notification, and Enforcement Rules to close gaps revealed by evolving technology and outsourcing.

For you as a covered entity or business associate, the Rule elevates expectations for covered entity compliance, clarifies business associate liability, and standardizes how you assess and report incidents involving unsecured PHI. The outcome is a more consistent, risk-based framework that emphasizes prevention, transparency, and patient empowerment.

Who is affected

  • Covered entities: health plans, healthcare providers, and healthcare clearinghouses.
  • Business associates: vendors and contractors that create, receive, maintain, or transmit PHI on your behalf, plus their subcontractors.

Privacy Rule Changes

The Omnibus Rule expands patient control and tightens rules around marketing, fundraising, and the sale of PHI, while updating notices and permissions to reflect modern data flows.

  • Expanded right of access: Patients can obtain an electronic copy of their PHI in the form and format requested if readily producible and may direct a copy to a designated third party. Reasonable, cost-based fees apply.
  • Right to restrict disclosures: If a patient pays out-of-pocket in full, you must honor a request to restrict disclosure of that item or service to a health plan, unless another law requires disclosure.
  • Marketing and sale of PHI: Most paid marketing communications require prior authorization, and the sale of PHI generally requires explicit authorization.
  • Fundraising: You may use limited data elements for fundraising, but you must provide a clear, simple opt-out that you honor.
  • Notices of Privacy Practices (NPPs): NPPs must be updated to describe new rights and uses, including breach notification, restrictions, fundraising opt-outs, and any marketing/sale practices.
  • GINA and underwriting: Health plans (with limited exceptions) may not use genetic information for underwriting purposes.
  • Targeted permissions: Disclosures of student immunization records to schools are permitted with parental agreement; disclosures to family and others involved in care are clarified; PHI of decedents is protected for 50 years.

Security Rule Enhancements

The Omnibus Rule makes the Security Rule directly applicable to business associates and their subcontractors, aligning obligations across all entities that touch ePHI. You must implement administrative, physical, and technical privacy safeguards proportionate to your risks.

Core expectations for ePHI

  • Risk analysis and management: Identify where ePHI is created, received, maintained, or transmitted; evaluate threats and vulnerabilities; and implement controls to reduce risks to a reasonable and appropriate level.
  • Administrative safeguards: Policies, workforce training, access management, and contingency planning.
  • Physical safeguards: Facility security, device/media controls, and secure disposal or re-use.
  • Technical safeguards: Access controls, audit controls, integrity protections, transmission security, and strong authentication. Encryption is strongly recommended as a best practice and breach “safe harbor.”

Business Associate Responsibilities

Business associates are now directly liable for Security Rule compliance and for certain Privacy Rule violations. The definition of a business associate includes any vendor or subcontractor that creates, receives, maintains, or transmits PHI on your behalf—expanding the reach of business associate liability throughout the vendor chain.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What you must do

  • Update business associate agreements (BAAs): Include required privacy and security assurances, flow down obligations to subcontractors, and define breach reporting timelines and processes.
  • Implement a documented security program: Conduct risk analysis and management, adopt safeguards, and monitor vendor performance.
  • Apply the minimum necessary standard: Limit PHI access and disclosures to what is needed for the task.
  • Report incidents: Promptly notify the covered entity of suspected or confirmed breaches of unsecured PHI and cooperate in investigations and mitigation.

Breach Notification Requirements

The Omnibus Rule replaced the prior “harm” test with a presumption of breach, establishing a clearer breach notification threshold. A breach is presumed unless you can demonstrate a low probability that PHI has been compromised based on a documented, four-factor risk assessment.

The four required factors

  • Nature and extent of PHI involved, including sensitivity and likelihood of re-identification.
  • Unauthorized person who used the PHI or to whom the disclosure was made.
  • Whether the PHI was actually acquired or viewed.
  • Extent to which the risk has been mitigated (for example, through timely retrieval or secure destruction).

Notification mechanics

  • Timeliness: Notify affected individuals without unreasonable delay and no later than 60 days after discovery.
  • Content: Describe what happened, the types of information involved, steps individuals should take, what you are doing to investigate and mitigate, and how to contact you.
  • Scale: For breaches affecting 500 or more residents of a state or jurisdiction, notify prominent media and report to HHS contemporaneously; smaller breaches are logged and reported to HHS annually.
  • Vendors: Business associates must notify their covered entities, supplying details needed for individual notices.
  • Safe harbor: Properly encrypted or destroyed PHI is not considered “unsecured,” so notification is typically not required.

Enforcement and Penalties

Enforcement is strengthened through a tiered civil monetary penalty structure, increased investigative expectations for willful neglect, and broader authority to require corrective action plans. Penalties can reach millions of dollars per year, per violation category, and inflation adjustments apply. Robust documentation of risk analysis, policies, training, and incident response demonstrates diligence and can meaningfully affect outcomes.

Audits and investigations look for repeat issues, insufficient oversight of vendors, and failure to implement reasonable safeguards. Demonstrable, risk-based controls—and timely mitigation when incidents occur—are central to compliance and to limiting enforcement exposure.

Patient Rights Expansion

The Omnibus Rule expands patient autonomy and transparency. Patients can obtain electronic copies of ePHI, direct a copy to a third party, and expect clearer Notices of Privacy Practices that explain uses, disclosures, and their choices. If a patient pays in full out-of-pocket, you must restrict related disclosures to a health plan upon request.

Patients gain stronger control over communications, more visibility into fundraising uses of their information, and protections against the use of genetic information for underwriting. These measures collectively reinforce trust while aligning clinical operations with modern data practices.

Conclusion

The HIPAA Omnibus Rule modernizes privacy safeguards, clarifies business associate liability, and standardizes breach response so you can protect ePHI with a risk-based, lifecycle approach. By tightening BAAs, performing rigorous risk analysis and management, updating policies and NPPs, and honing incident response, you meet covered entity compliance expectations and strengthen patient trust.

FAQs

What are the main changes introduced by the HIPAA Omnibus Rule?

The Rule implements HITECH Act provisions across the Privacy, Security, Breach Notification, and Enforcement Rules. It expands individual rights (such as electronic access and restrictions on disclosures), tightens controls on marketing, fundraising, and sale of PHI, presumes a breach unless a low probability of compromise is shown, and makes business associates and their subcontractors directly liable for compliance.

How do the changes affect business associates?

Business associates—and any subcontractors that handle PHI—are now directly subject to the Security Rule and certain Privacy Rule provisions. They must execute compliant BAAs, perform risk analysis and management, implement appropriate safeguards, limit uses and disclosures to the minimum necessary, and promptly report breaches of unsecured PHI. Failure to comply can trigger enforcement actions and monetary penalties.

What are the new breach notification requirements?

There is a presumption of breach unless you document, via a four-factor assessment, a low probability that PHI was compromised. If notification is required, you must inform affected individuals without unreasonable delay and within 60 days, include specified content in the notice, and report large incidents to HHS and the media as required. Proper encryption or destruction provides a safe harbor from notification duties.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles