Menu

HIPAA Omnibus Rule: Key Changes and Compliance Impact

HIPAA Omnibus Rule: Key Changes and Compliance Impact

The HIPAA Omnibus Rule was one of the most significant updates to the U.S. Health Insurance Portability and Accountability Act (HIPAA) privacy and security framework. Issued by the U.S. Department of Health and Human Services (HHS) in 2013, the rule introduced major changes to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules and incorporated privacy protections related to genetic information.

Although the HIPAA Omnibus Final Rule was published more than a decade ago, its requirements remain important for organizations handling protected health information (PHI), particularly covered entities and business associates. This is also relevant to organizations in India that provide healthcare IT, medical billing, cloud, analytics, transcription, software, or other services to U.S. healthcare organizations. Where an Indian organization qualifies as a HIPAA business associate, applicable HIPAA obligations can extend directly to that organization.

Understanding the HIPAA Omnibus Rule requirements is therefore important for organizations that create, receive, maintain, or transmit PHI on behalf of HIPAA-regulated entities.

What Is the Omnibus Rule?

The HIPAA Omnibus Rule is a 2013 HHS rulemaking that modified several HIPAA rules to implement provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act and make other changes to HIPAA privacy and security requirements. The rule was published on January 25, 2013, became effective on March 26, 2013, and generally had a compliance date of September 23, 2013. Certain existing business associate agreements received a transition period for compliance. The rule strengthened individual privacy rights, expanded the responsibilities and direct liability of business associates, modified breach notification requirements, placed additional restrictions on marketing and the sale of PHI, and strengthened enforcement provisions.

The HIPAA Omnibus Rule introduced several significant changes to how covered entities and business associates handle PHI, with key provisions addressing the following areas: 

Patient Access and Control

The Omnibus Rule strengthened certain individual rights concerning their health information. It also addressed individuals' ability to obtain electronic copies of electronic PHI where applicable. Business associates can have direct obligations concerning access to electronic PHI when they maintain the relevant information on behalf of a covered entity.

Accountability

One of the major HIPAA Omnibus Rule changes was greater accountability for business associates. Business associates became directly liable for certain HIPAA requirements rather than being subject only to contractual obligations imposed by covered entities. This included direct liability for certain impermissible uses and disclosures of PHI, Security Rule violations, breach notification obligations, and other specified requirements.

Marketing Restrictions

The rule strengthened restrictions around the use and disclosure of PHI for marketing purposes. Certain communications involving financial remuneration require individual authorization, subject to applicable exceptions under the Privacy Rule. Organizations therefore need to distinguish legitimate healthcare communications from activities that constitute marketing under HIPAA.

Reasonable Disclosures

HIPAA permits certain uses and disclosures of PHI without individual authorization when specific regulatory conditions are met. The Omnibus Rule clarified and modified several Privacy Rule provisions governing these uses and disclosures. Organizations must still apply the applicable requirements, including minimum-necessary considerations where relevant, rather than treating all internal or third-party information sharing as automatically permissible.

Genetic Information

The Omnibus Rule incorporated provisions related to the Genetic Information Nondiscrimination Act (GINA) into the HIPAA Privacy Rule. Genetic information was incorporated into the definition of health information and certain uses and disclosures were restricted accordingly.

Sale of PHI

The rule established additional restrictions around the sale of PHI. Covered entities and business associates generally cannot receive direct or indirect remuneration in exchange for PHI without the individual's authorization, subject to specified exceptions.

Research

The rule also modified certain provisions affecting the use and disclosure of PHI for research. These changes were intended to provide greater flexibility in certain research activities while maintaining privacy protections. Organizations involved in healthcare research therefore need to evaluate both HIPAA requirements and the specific conditions applicable to research-related uses and disclosures.

Breach Notice

The Omnibus Rule modified the HIPAA Breach Notification Rule and removed the previous requirement to determine whether a breach posed a significant risk of financial, reputational, or other harm to affected individuals. Under the current framework, an impermissible use or disclosure of PHI is generally presumed to be a breach unless the covered entity or business associate demonstrates, through a risk assessment, a low probability that the PHI was compromised.

Penalties

The Omnibus Rule strengthened enforcement and incorporated the HITECH Act's tiered civil money penalty structure. This increased the importance of documenting compliance activities, responding to incidents, and maintaining appropriate safeguards rather than relying solely on contractual assurances.

Implementation

The rule became effective on March 26, 2013, with a general compliance date of September 23, 2013. Existing business associate agreements that met specified conditions could receive a transition period to September 22, 2014.

Strengthen HIPAA compliance and demonstrate your commitment to protecting health information. Connect with INTERCERT to discuss your HIPAA assessment and certification requirements.

How the Omnibus Rule Impacts Covered Entities and Business Associates?

The HIPAA Omnibus Rule provisions significantly changed the compliance responsibilities of organizations operating within the HIPAA ecosystem.

Direct Liability Provisions

Business associates became directly liable for several HIPAA requirements, including compliance with the Security Rule, certain impermissible uses and disclosures of PHI, breach notification obligations, and minimum-necessary requirements. This is particularly relevant for technology providers, cloud service providers, medical billing companies, analytics providers, and other organizations processing PHI on behalf of covered entities. For an organization in India providing these services to U.S. healthcare organizations, simply having a contract with a U.S. customer does not eliminate the need to understand whether the organization qualifies as a business associate and which HIPAA requirements apply.

Stricter Business Associate Agreements (BAAs)

Covered entities must establish appropriate written arrangements with business associates that define permitted and required uses and disclosures of PHI and require appropriate safeguards. BAAs remain an important mechanism for establishing responsibilities between covered entities and business associates.

Expanded Privacy Obligations

The rule expanded privacy responsibilities around areas such as individual rights, marketing, the sale of PHI, and certain uses and disclosures. Organizations therefore need documented privacy processes that translate regulatory requirements into day-to-day handling of PHI.

Tightened Authorization and Consent Rules

The Omnibus Rule modified requirements surrounding individual authorizations for certain uses and disclosures, particularly marketing and the sale of PHI. Organizations need to determine when authorization is required rather than assuming that an individual's general consent permits every use of their PHI.

Stricter Enforcement and Penalties

The rule strengthened enforcement mechanisms and made certain business associates directly accountable for HIPAA violations. For organizations processing PHI, compliance therefore requires more than contractual assurances. Security controls, privacy processes, employee responsibilities, incident response, and evidence of compliance all become important.

HIPAA Breach Notification and Privacy Requirements 

Breach notification is one of the most important areas affected by the HIPAA Omnibus Rule.

Timelines and Thresholds for Breach Notification

Following a breach of unsecured PHI, covered entities generally must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. For breaches affecting 500 or more individuals, notification to the HHS Secretary is required without unreasonable delay and no later than 60 days after discovery. Breaches affecting fewer than 500 individuals can generally be reported to HHS annually. Business associates must notify the applicable covered entity following discovery of a breach and generally cannot delay notification beyond 60 calendar days.

Assessment of Harm and Changes to the "Harm Threshold"

One of the most important HIPAA Omnibus Rule changes was the modification of the breach assessment approach. Previously, organizations considered whether an incident presented a significant risk of financial, reputational, or other harm. The Omnibus Rule replaced that approach with a presumption that an impermissible use or disclosure constitutes a breach unless the organization demonstrates a low probability that the PHI was compromised. The required risk assessment considers factors including the nature and extent of PHI involved, the unauthorized recipient, whether the information was actually acquired or viewed, and the extent to which risk was mitigated. This makes documented incident assessment especially important.

Encryption and Security Measures

Encryption plays an important role in protecting PHI, particularly electronic PHI. Under HHS guidance, PHI rendered unusable, unreadable, or indecipherable to unauthorized individuals through specified technologies or methodologies can qualify as secured information for breach-notification purposes. Encryption and destruction are identified by HHS as such technologies and methodologies. However, encryption should not be viewed as a substitute for the broader HIPAA Security Rule. The Security Rule requires appropriate administrative, physical, and technical safeguards to protect electronic PHI. Organizations should therefore consider encryption alongside access controls, authentication, risk analysis, security policies, workforce controls, monitoring, incident response, and other safeguards appropriate to their environment.

HIPAA Omnibus Rule Compliance: What Organizations Should Focus On?

The HIPAA Omnibus Rule explained in practical terms is about expanding accountability across the healthcare information ecosystem. For covered entities and business associates, effective HIPAA Omnibus Rule compliance involves understanding:

  • What PHI the organization creates, receives, maintains, or transmits?
  • Which HIPAA roles and obligations apply?
  • How PHI is used and disclosed?
  • Which third parties have access to PHI?
  • Whether appropriate BAAs are in place?
  • How security risks are identified and managed?
  • How incidents and potential breaches are evaluated?
  • How individual privacy rights are addressed?
  • How workforce members are trained and held accountable?
  • What evidence demonstrates compliance?

For Indian organizations serving U.S. healthcare clients, these considerations are especially important. A company may operate physically in India while still having contractual and regulatory responsibilities arising from its role as a business associate under HIPAA.

Ready to demonstrate HIPAA compliance? Connect with INTERCERT to explore HIPAA assessment and certification options for your organization.

Move from HIPAA Compliance to Stronger Data Protection

The HIPAA Omnibus Final Rule strengthened accountability for protecting PHI through direct business associate liability, tighter privacy restrictions, updated breach notification requirements, expanded individual protections, and stronger enforcement.

Although the Omnibus Rule was finalized in 2013, HIPAA requirements have continued to evolve. HHS published a proposed rule in January 2025 to strengthen the HIPAA Security Rule's cybersecurity requirements for electronic PHI. For organizations in the USA and Indian organizations serving U.S. healthcare customers, staying current with these developments is essential. Therefore, the HIPAA Omnibus Rule reinforced the need to embed privacy, security, and accountability into everyday PHI management, not address them only after an incident occurs.

INTERCERT provides HIPAA compliance and certification services for organizations seeking to improve their healthcare information protection practices and demonstrate alignment with HIPAA requirements. With experienced auditors, independent assessments, and certification expertise across 10,000+ organizations in 28+ countries, INTERCERT delivers internationally focused assessment services for organizations handling protected health information (PHI), including healthcare providers, technology companies, and business associates.

 

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved