<?xml version="1.0" encoding="UTF-8"?><mods xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" version="3.3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd" ID="id-2013-01073">
    <name type="corporate">
        <namePart>United States Government Publishing Office</namePart>
        <role>
            <roleTerm authority="marcrelator" type="text">publisher</roleTerm>
            <roleTerm authority="marcrelator" type="code">pbl</roleTerm>
        </role>
        <role>
            <roleTerm authority="marcrelator" type="text">distributor</roleTerm>
            <roleTerm authority="marcrelator" type="code">dst</roleTerm>
        </role>
    </name>
    <name type="corporate">
        <namePart>United States</namePart>
        <namePart>National Archives and Records Administration</namePart>
        <namePart>Office of the Federal Register</namePart>
        <role>
            <roleTerm authority="marcrelator" type="text">author</roleTerm>
            <roleTerm authority="marcrelator" type="code">aut</roleTerm>
        </role>
        <description>Government Organization</description>
    </name>
    <typeOfResource>text</typeOfResource>
    <genre authority="marcgt">government publication</genre>
    <language>
        <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
    </language>
    <extension>
        <collectionCode>FR</collectionCode>
        <category>Regulatory Information</category>
        <waisDatabaseName>2013_register</waisDatabaseName>
        <branch>executive</branch>
        <dateIngested>2013-01-25</dateIngested>
    </extension>
    <genre authority="marcgt">article</genre>
    <titleInfo>
        <title>Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules</title>
        <partNumber>Part II</partNumber>
        <partName>Rules and Regulations</partName>
    </titleInfo>
    <relatedItem type="otherFormat" xlink:href="https://www.govinfo.gov/content/pkg/FR-2013-01-25/html/2013-01073.htm">
        <identifier type="FDsys Unique ID">D09002ee1c7fbeed3</identifier>
    </relatedItem>
    <relatedItem type="otherFormat" xlink:href="https://www.govinfo.gov/content/pkg/FR-2013-01-25/pdf/2013-01073.pdf">
        <identifier type="FDsys Unique ID">D09002ee1c7fbf020</identifier>
    </relatedItem>
    <name type="corporate">
        <namePart>United States</namePart>
        <namePart>Department of Health and Human Services</namePart>
        <role>
            <roleTerm authority="marcrelator" type="text">originator</roleTerm>
            <roleTerm authority="marcrelator" type="code">org</roleTerm>
        </role>
        <description>United States Government Agency or Subagency</description>
    </name>
    <name type="corporate">
        <namePart>United States</namePart>
        <namePart>Office of the Secretary</namePart>
        <role>
            <roleTerm authority="marcrelator" type="text">originator</roleTerm>
            <roleTerm authority="marcrelator" type="code">org</roleTerm>
        </role>
        <description>United States Government Agency or Subagency</description>
    </name>
    <abstract>The Department of Health and Human Services (HHS or "the Department") is issuing this final rule to: Modify the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Enforcement Rules to implement statutory amendments under the Health Information Technology for Economic and Clinical Health Act ("the HITECH Act" or "the Act") to strengthen the privacy and security protection for individuals' health information; modify the rule for Breach Notification for Unsecured Protected Health Information (Breach Notification Rule) under the HITECH Act to address public comment received on the interim final rule; modify the HIPAA Privacy Rule to strengthen the privacy protections for genetic information by implementing section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008 (GINA); and make certain other modifications to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (the HIPAA Rules) to improve their workability and effectiveness and to increase flexibility for and decrease burden on the regulated entities.</abstract>
    <identifier type="FR citation">78 FR 5566</identifier>
    <identifier type="uri">https://www.govinfo.gov/app/details/FR-2013-01-25/2013-01073</identifier>
    <identifier type="FR Doc No.">2013-01073</identifier>
    <identifier type="former granule identifier">fr25ja13-14</identifier>
    <identifier type="Regulation ID Number">RIN 0945-AA03</identifier>
    <identifier type="billing code">4153-01-P</identifier>
    <location>
        <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/FR-2013-01-25/2013-01073</url>
        <url access="raw object" displayLabel="HTML rendition">https://www.govinfo.gov/content/pkg/FR-2013-01-25/html/2013-01073.htm</url>
        <url access="raw object" displayLabel="PDF rendition">https://www.govinfo.gov/content/pkg/FR-2013-01-25/pdf/2013-01073.pdf</url>
    </location>
    <subject>
        <topic>Administrative Practice and Procedure</topic>
        <topic>Computer Technology</topic>
        <topic>Electronic Information System</topic>
        <topic>Electronic Transactions</topic>
        <topic>Employer Benefit Plan</topic>
        <topic>Health</topic>
        <topic>Health Care</topic>
        <topic>Health Facilities</topic>
        <topic>Health Insurance</topic>
        <topic>Health Records</topic>
        <topic>Hospitals</topic>
        <topic>Investigations</topic>
        <topic>Medicaid</topic>
        <topic>Medical Research</topic>
        <topic>Medicare</topic>
        <topic>Penalties</topic>
        <topic>Privacy</topic>
        <topic>Reporting and Record Keeping Requirements</topic>
        <topic>Security</topic>
    </subject>
    <physicalDescription>
        <extent>137 p.</extent>
    </physicalDescription>
    <part type="Part II">
        <extent unit="pages">
            <start>5566</start>
            <end>5702</end>
        </extent>
    </part>
    <identifier type="preferred citation">78 FR 5566</identifier>
    <relatedItem type="isReferencedBy">
        <titleInfo>
            <title>Code of Federal Regulations</title>
            <partNumber>Title 45 Part 160</partNumber>
        </titleInfo>
        <identifier type="CFR citation">45 CFR Part  160</identifier>
    </relatedItem>
    <relatedItem type="isReferencedBy">
        <titleInfo>
            <title>Code of Federal Regulations</title>
            <partNumber>Title 45 Part 164</partNumber>
        </titleInfo>
        <identifier type="CFR citation">45 CFR Part  164</identifier>
    </relatedItem>
    <relatedItem type="isReferencedBy">
        <titleInfo>
            <title>Regulation Identification Number 0945-AA03</title>
        </titleInfo>
        <identifier type="regulation ID number">RIN 0945-AA03</identifier>
    </relatedItem>
    <extension>
        <searchTitle>Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules; Federal Register Vol. 78, Issue </searchTitle>
        <granuleClass>RULE</granuleClass>
        <accessId>2013-01073</accessId>
        <partNumber>II</partNumber>
        <agency order="1">DEPARTMENT OF HEALTH AND HUMAN SERVICES</agency>
        <agency order="2">Office of the Secretary</agency>
        <effectiveDate>2013-03-26</effectiveDate>
        <rin number="0945-AA03"/>
        <billingCode>4153-01-P</billingCode>
        <frDocNumber>2013-01073</frDocNumber>
        <action>Final rule.</action>
        <summary>The Department of Health and Human Services (HHS or "the Department") is issuing this final rule to: Modify the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Enforcement Rules to implement statutory amendments under the Health Information Technology for Economic and Clinical Health Act ("the HITECH Act" or "the Act") to strengthen the privacy and security protection for individuals' health information; modify the rule for Breach Notification for Unsecured Protected Health Information (Breach Notification Rule) under the HITECH Act to address public comment received on the interim final rule; modify the HIPAA Privacy Rule to strengthen the privacy protections for genetic information by implementing section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008 (GINA); and make certain other modifications to the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules (the HIPAA Rules) to improve their workability and effectiveness and to increase flexibility for and decrease burden on the regulated entities.</summary>
        <dates>Effective date: This final rule is effective on March 26, 2013.</dates>
        <contact>Andra Wicks 202-205-2292.</contact>
        <cfr title="45">
                                    
            <part number="160"/>
                                    
            <subject>Administrative Practice and Procedure</subject>
                                    
            <subject>Computer Technology</subject>
                                    
            <subject>Electronic Information System</subject>
                                    
            <subject>Electronic Transactions</subject>
                                    
            <subject>Employer Benefit Plan</subject>
                                    
            <subject>Health</subject>
                                    
            <subject>Health Care</subject>
                                    
            <subject>Health Facilities</subject>
                                    
            <subject>Health Insurance</subject>
                                    
            <subject>Health Records</subject>
                                    
            <subject>Hospitals</subject>
                                    
            <subject>Investigations</subject>
                                    
            <subject>Medicaid</subject>
                                    
            <subject>Medical Research</subject>
                                    
            <subject>Medicare</subject>
                                    
            <subject>Penalties</subject>
                                    
            <subject>Privacy</subject>
                                    
            <subject>Reporting and Record Keeping Requirements</subject>
                                    
            <subject>Security</subject>
                                
        </cfr>
        <cfr title="45">
                                    
            <part number="164"/>
                                
        </cfr>
        <tocDoc>HIPAA Privacy, Security, Enforcement, and Breach Notification Rules
, </tocDoc>
        <urlRef>http://csrc.nist.gov/publications/nistir/ir7298-rev1/nistir-7298-revision1.pdf</urlRef>
        <urlRef>http://ncvhs.hhs.gov/050111mn.htm</urlRef>
        <urlRef>http://www.bls.gov/oes/current/naics3_541000.htm#23-0000</urlRef>
        <urlRef>http://www.bls.gov/oes/current/oes_nat.htm</urlRef>
        <urlRef>http://www.cms.gov/manuals/Downloads/bp102c15.pdf</urlRef>
        <urlRef>http://www.datalossdb.org</urlRef>
        <urlRef>http://www.dol.gov/ebsa/faqs/faq-GINA.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/civilrights/</urlRef>
        <urlRef>http://www.hhs.gov/ocr/enforcement/</urlRef>
        <urlRef>http://www.hhs.gov/ocr/office/about/rgn-hqaddresses.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/brinstruction.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/faq/business_associates/236.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/faq/business_associates/239.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/faq/protected_health_information/354.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/faq/providers/business/245.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/faq/right_to_request_a_restriction/512.html</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/hipaaferpajointguide.pdf</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/provider_ffg.pdf</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/understanding/special/healthit/eaccess.pdf</urlRef>
        <urlRef>http://www.hhs.gov/ocr/privacy/hipaa/understanding/special/research/index.html</urlRef>
        <urlRef>http://www.hhs.gov/ohrp/sachrp/hipaalettertosecy090104.html</urlRef>
        <urlRef>http://www.nacds.org/wmspage.cfm?parm1=507</urlRef>
        <urlRef>http://www.ncvhs.hhs.gov/04061712.html</urlRef>
        <urlRef>http://www.ncvhs.hhs.gov/040902lt1.htm</urlRef>
        <urlRef>http://www.regulations.gov</urlRef>
        <urlRef>http://www.sba.gov/advo/research/data.html</urlRef>
        <urlRef>http://www.sba.gov/content/small-business-size-standards</urlRef>
        <urlRef>www.bls.gov/oes/current/oes_nat.htm</urlRef>
    </extension>
    <relatedItem type="host" ID="P0b002ee183b5199f" xlink:href="https://www.govinfo.gov/metadata/pkg/FR-2013-01-25/mods.xml">
        <titleInfo>
            <title>Federal Register</title>
            <partNumber>Vol. 78, no. 17</partNumber>
        </titleInfo>
        <originInfo>
            <publisher>Office of the Federal Register, National Archives and Records Administration</publisher>
            <dateIssued encoding="w3cdtf">2013-01-25</dateIssued>
            <issuance>continuing</issuance>
            <frequency>daily</frequency>
        </originInfo>
        <physicalDescription>
            <note type="source content type">deposited</note>
            <digitalOrigin>born digital</digitalOrigin>
            <extent>465 p.</extent>
        </physicalDescription>
        <tableOfContents xlink:href="https://www.govinfo.gov/app/frtoc/2013-01-25">    
		  Table of Contents: 
		</tableOfContents>
        <classification authority="sudocs">AE 2.7:</classification>
        <classification authority="sudocs">GS 4.107:</classification>
        <classification authority="sudocs">AE 2.106:</classification>
        <classification authority="lcc">KF70.A2</classification>
        <identifier type="uri">https://www.govinfo.gov/app/details/FR-2013-01-25</identifier>
        <identifier type="local">P0b002ee183b5199f</identifier>
        <identifier type="issn">0097-6326</identifier>
        <identifier type="issn">0042-1219</identifier>
        <identifier type="issn">0364-1406</identifier>
        <identifier type="stock number">769-004-00000-9</identifier>
        <identifier type="ILS system id">000582072</identifier>
        <identifier type="former identifier">f:fr25ja13</identifier>
        <location>
            <url displayLabel="Content Detail" access="object in context">https://www.govinfo.gov/app/details/FR-2013-01-25</url>
            <url displayLabel="PDF rendition" access="raw object">https://www.govinfo.gov/content/pkg/FR-2013-01-25/pdf/FR-2013-01-25.pdf</url>
            <url displayLabel="XML rendition" access="raw object">https://www.govinfo.gov/content/pkg/FR-2013-01-25/xml/FR-2013-01-25.xml</url>
        </location>
        <accessCondition type="GPO scope determination">fdlp</accessCondition>
        <part type="issue">
            <extent unit="pages">
                <start>5253</start>
                <end>5705</end>
            </extent>
        </part>
        <recordInfo>
            <recordContentSource authority="marcorg">DGPO</recordContentSource>
            <recordCreationDate encoding="w3cdtf">2013-01-25</recordCreationDate>
            <recordChangeDate encoding="w3cdtf">2024-06-03</recordChangeDate>
            <recordIdentifier source="DGPO">FR-2013-01-25</recordIdentifier>
            <recordOrigin>machine generated</recordOrigin>
            <languageOfCataloging>
                <languageTerm type="code" authority="iso639-2b">eng</languageTerm>
            </languageOfCataloging>
        </recordInfo>
        <extension>
            <docClass>FR</docClass>
            <accessId>FR-2013-01-25</accessId>
            <volume>78</volume>
            <issue>17</issue>
        </extension>
    </relatedItem>
</mods>
