2013 Omnibus Final Rule
The 2013 Omnibus Final Rule is a set of updates to the HIPAA rules published by the U.S. Department of Health and Human Services (HHS) that put into effect several provisions of the HITECH Act. It was designed to strengthen the privacy and security protections for people's health information. Among other changes, it broadened who is directly responsible for protecting health data and updated how breaches are defined and handled.
The 2013 Omnibus Final Rule, published in the Federal Register on January 25, 2013 (Vol. 78, No. 17), is a consolidated rulemaking comprised of four final rules that modify the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules, implementing a number of provisions of the HITECH Act. Notably, it expanded the definition of 'business associate' to include entities that create, receive, maintain, or transmit PHI on behalf of a covered entity, extending direct compliance obligations to such parties (and, by extension, subcontractors) rather than limiting them to covered entities alone. It also revised the breach standard, generally treating an unauthorized acquisition, access, use, or disclosure of unsecured PHI as a breach subject to the Breach Notification Rule's analysis, and made other modifications such as those affecting disclosure of student immunization records. Practitioners should note that the specific regulatory text, effective and compliance dates, and CFR provisions should be verified against the current codified regulations, and that state law or other frameworks may impose additional requirements beyond those in this rule.
Why it matters
The 2013 Omnibus Final Rule represents one of the most significant modifications to the HIPAA regulatory framework since the original rules took effect, because it put into force provisions of the HITECH Act and reshaped who bears direct legal responsibility for protecting health information. Before these changes, direct compliance obligations rested primarily with covered entities, and the many vendors handling protected health information were largely reached only through contractual arrangements. By expanding the definition of business associate to include entities that create, receive, maintain, or transmit PHI on behalf of a covered entity, and extending obligations to their subcontractors, the rule brought a much broader set of organizations under direct regulatory reach.
For compliance, privacy, and security professionals, the rule matters because it altered day-to-day risk exposure. Business associates and their subcontractors became directly accountable for certain HIPAA requirements rather than only contractually liable to a covered entity, which changed how organizations negotiate business associate agreements and how they assess vendor risk. The rule also revised the breach standard, generally treating an unauthorized acquisition, access, use, or disclosure of unsecured PHI as a breach subject to the Breach Notification Rule's analysis, which affected how organizations evaluate and respond to potential incidents.
Because the rule implemented HITECH Act provisions and consolidated changes across the Privacy, Security, Breach Notification, and Enforcement Rules, its effects are foundational to how HIPAA compliance is practiced today. Readers should note that specific effective and compliance dates, penalty tiers, and codified provisions are adjusted over time and should be confirmed against the current regulatory text, and that state law or other frameworks may impose additional requirements beyond this rule.
Who it's relevant to
Inside 2013 Omnibus Final Rule
Common questions
Answers to the questions practitioners most commonly ask about 2013 Omnibus Final Rule.