The HIPAA Omnibus rule that went into affect on September 23 comes with severe financial penalties for noncompliance. In the tiered penalty structure, single violations can cost your practice as much as $50,000.
Therefore, it’s important to educate yourself thoroughly on the security rule. To assist these efforts, we’ve created a study guide that includes all of the HIPAA Omnibus basics.
Glossary
Protected health information (PHI) – Any information that can be used to identify an individual, including demographic information
Covered entity – Healthcare providers who transmit any health information in an electronic form
Business associate – Any entity that uses protected health information in some way to provide services to a covered entity
Facts You Should Know
- Although providers can charge a fee to cover the cost of copying, the provider cannot charge for searching for patients’ health information.
- Practices are no longer liable for security breaches for which a business associate is at fault.
- Providers have 30 days to respond to a patient’s written request for their protected health information.
- September 23, 2014 is the final date for getting all business associate agreements in compliance with the HIPAA Omnibus rule.
- Providers must obtain consent from patients prior to using their health information for marketing purposes.
- Patients who pay cash for treatment can request to not have the details of their treatment shared with their healthcare plan.
Resources
The following resources will provide more in-depth information on the HIPAA Omnibus rule:
- A HIPAA Omnibus primer from Power Your Practice
- The Department of Health & Human Services health information privacy page
- HHS’s official Omnibus press release
- An Omnibus summary from the American Medical Association
Don’t let the new HIPAA Omnibus rule catch you off guard. Become familiar with it now, so your practice doesn’t pay for it later if a security breach occurs.
Cloud-based health IT solutions can help keep your patients’ health information safe. Find out how by contacting us at 1-877-342-7517 or hello@carecloud.com.

Do you know what you need when setting up a new medical practice?