Skip to content

HIPAA and Emerging Issues

 

Learn about HIPAA attestation, proposed 2025 HIPAA Security Rule, Information Blocking, FTC Health Breach Notification Rule, and  more, through the Frequently Asked Questions (FAQs) below. Please schedule a free consultation, if you are looking for experienced professionals to help you comply with HIPAA, conduct a HIPAA Security Analysis, and for other customized services.

Table of Contents

What is HIPAA attestation? 

 

HIPAA attestation has three distinct meanings in practice, but the most significant, a formal attestation requirement for reproductive health care disclosures, was largely vacated by a federal court in June 2025. The term most commonly referred to a requirement introduced by HHS’s April 2024 Final Rule on Reproductive Health Care Privacy, which added 45 CFR 164.509 to require covered entities and business associates to obtain a signed attestation , certifying that a requested use or disclosure was not for a prohibited purpose , before releasing PHI potentially related to reproductive health care under four permissible disclosure pathways: health oversight activities, judicial and administrative proceedings, law enforcement requests, and disclosures to coroners or medical examiners. HHS published a model attestation form in June 2024. 

However, on June 18, 2025, a federal district court in the Northern District of Texas (Purl v. HHS) vacated most of that Final Rule, including the attestation requirement at 45 CFR 164.509. Covered entities and business associates are currently not required to obtain reproductive health care attestations. Certain Notice of Privacy Practices updates from that same rulemaking do survive the court order and carried a compliance deadline of February 16, 2026. 

Separately, “attestation” arises in two other HIPAA-adjacent contexts. Under MIPS, eligible clinicians must annually attest to completing their Security Risk Analysis and satisfying Promoting Interoperability requirements in order to earn performance points. And as a general best practice, not explicitly required by HIPAA’s text, many organizations have workforce members sign annual attestations confirming they have completed HIPAA training and reviewed the organization’s privacy and security policies, creating documentary evidence for OCR investigations.

 

What changes does the proposed 2025 HIPAA Security Rule update introduce? 

 

HHS has proposed the first major Security Rule overhaul since 2013, introducing requirements such as mandatory multi-factor authentication, encryption at rest and in transit, and annual penetration testing, but as of March 2026 the rule has not been finalized, and the existing Security Rule remains fully in effect. The Notice of Proposed Rulemaking (NPRM) was published in the Federal Register on January 6, 2025, received more than 4,600 public comments before the March 7, 2025, deadline, and remains under review by the current administration. 

If finalized in its proposed form, the rule would introduce sweeping changes, including: eliminating the distinction between required and addressable implementation specifications, making all specifications uniformly required; mandating a written technology asset inventory and network map updated at least annually and after significant operational changes; requiring annual penetration testing and vulnerability scanning; mandating multi-factor authentication for all access to systems containing ePHI; requiring written documentation of all Security Rule policies, procedures, plans, and analyses; establishing a 72-hour reporting requirement for certain security incidents to HHS; and requiring encryption of ePHI at rest and in transit in all but narrowly defined circumstances. HHS estimated first-year compliance costs at approximately $9 billion. A coalition of industry associations has petitioned for the rule’s withdrawal; whether it advances, is revised, or is shelved depends on the current administration’s regulatory priorities.

 

What are the 42 CFR Part 2 regulations and how do they relate to HIPAA? 

 

42 CFR Part 2 is a separate federal regulation governing the confidentiality of substance use disorder (SUD) treatment records, historically far stricter than HIPAA and, following 2024 rulemaking, substantially aligned with it. Part 2 applies to federally assisted programs that provide treatment, counseling, or assessment for alcohol or drug use disorders. Historically, Part 2 required written patient consent for nearly every disclosure. In 2024, HHS finalized a rule aligning Part 2 more closely with HIPAA, allowing SUD records to be shared for treatment, payment, and healthcare operations under HIPAA-like conditions, and permitting disclosures with a single general consent rather than disclosure-by-disclosure authorization. OCR took on direct Part 2 enforcement responsibility beginning February 16, 2026, also the deadline by which covered entities maintaining Part 2-protected records must have updated their Notices of Privacy Practices to reflect these changes. Part 2 violations carry a separate penalty structure using the original 2009 HITECH Act penalty amounts as a starting point rather than inflation-adjusted HIPAA figures, resulting in lower per-violation amounts. Organizations treating substance use disorders must comply with both frameworks simultaneously, following the more stringent requirement where they overlap. 

 

What is Information Blocking under the 21st Century Cures Act, and how is it different from HIPAA? 

 

Information blocking is a separate federal prohibition, established by the 21st Century Cures Act of 2016 and enforceable since April 2021, that bars certain actors from interfering with the access, exchange, or use of electronic health information (EHI), and it applies to a broader set of actors than HIPAA covers. An organization can be fully HIPAA-compliant and still commit information blocking, and vice versa. 

The actors subject to information blocking include certified health IT developers, health information networks and exchanges, and healthcare providers as defined under the Cures Act, which includes most hospitals, physician practices, clinics, pharmacies, and laboratories. Unlike HIPAA, information blocking rules apply to EHI broadly, including data formats not necessarily protected by HIPAA. 

Enforcement is handled by two agencies separate from OCR. The HHS Office of Inspector General (OIG) enforces information blocking against health IT developers, health information networks, and exchanges, with civil monetary penalties of up to $1 million per violation. Healthcare providers who commit information blocking are referred by the OIG to the HHS Office of the National Coordinator for Health IT (ONC) for disincentives, which under rules finalized in 2024 can include exclusion from Medicare and Medicaid programs and financial penalties. 

Eight exceptions define permissible reasons to limit information sharing: the Privacy Exception (when sharing would violate applicable law, including HIPAA); the Security Exception; the Infeasibility Exception; the Health IT Performance Exception; the Content and Manner Exception; the Fees Exception; the Licensing Exception; and the Preventing Harm Exception. Practices outside all eight exceptions that are likely to interfere with EHI access can be investigated and penalized regardless of HIPAA compliance. Complaints may be submitted to the ONC at healthit.gov.

 

What is the FTC Health Breach Notification Rule, and who does it apply to? 

 

The FTC Health Breach Notification Rule is a separate, non-HIPAA federal regulation requiring certain health technology companies outside HIPAA’s scope to notify affected individuals, the FTC, and in some cases the media when a breach of unsecured personal health information occurs, and the 2024 update significantly expanded its reach.  

Originally issued in 2009 and substantially updated in 2024, the rule applies to three categories of non-HIPAA entities: vendors of personal health records (PHRs) , online applications individuals use to maintain their own health information, such as fitness apps and consumer wellness portals; PHR-related entities , third-party applications that connect to or interact with a PHR platform; and service providers of PHR vendors or PHR-related entities that access, maintain, or transmit unsecured personal health record information. Traditional covered entities and business associates subject to HIPAA are exempt. 

The 2024 updates broadened the definition of a health breach to include unauthorized access, not just unauthorized acquisition, meaning a breach can occur even if no data was actually taken. The rule also clarified that personal health record information includes data drawn from multiple sources, including apps that infer health status from behavioral or location data. Violations are treated as unfair or deceptive acts under Section 5 of the FTC Act, with civil penalties of up to $51,744 per violation per day as of 2024, adjusted for inflation. The FTC has pursued active enforcement against health app developers and wellness platforms under both this rule and its broader Section 5 authority, making it an expanding area of regulatory risk for any organization operating consumer health technology outside the HIPAA framework.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties