We just want to provide a friendly reminder that, before key staff depart for the holidays, HIPAA covered entities and business associates should finalize their compliance with the 2024 HIPAA amendments related to reproductive health care by the December 23, 2024, compliance deadline.

This will include implementing the prohibition on using or disclosing any protected health information (PHI) for purposes of investigating or imposing liability on the mere act of seeking, obtaining, providing, or facilitating lawful reproductive health care, and obtaining attestations for uses and disclosures of PHI potentially related to reproductive health care for purposes of health oversight, law enforcement, judicial or administrative proceedings, coroners, and medical examiners. HIPAA covered entities have until February 16, 2026 to change their notices of privacy practices. You can view our more in-depth blog post about the 2024 amendments here or listen to our webinar here.

The future of the amendments is uncertain after the change of administration and in light of litigation challenging the amendments. In the meantime, however, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) recently has entered into a settlement agreement with a health care provider for disclosing reproductive health information to a patient's employer when doing so was outside the scope of the patient's authorization, and OCR has sent a notice to its listserv subscribers reminding them of the December 23rd compliance deadline. Accordingly, whatever the future may bring, the current OCR leadership expects regulated entities to come into compliance with new protections for the privacy of reproductive health care by the upcoming deadline.

Please do not hesitate to reach out to DWT if we can assist you in your compliance efforts.

+++

For more helpful information on privacy and security laws, check out our State General Privacy Law Tracker and our Summary of State Data Breach Notification Statutes. If you need assistance with a breach, we are available 24/7 at 844-GoToDWT (844-468-6398).