Skip to main content
Category: Regulatory Framework

2013 Omnibus Final Rule

Also known as: HIPAA Omnibus Rule, Omnibus HIPAA Rulemaking, Omnibus Final Rule, HIPAA Omnibus Final Rule of 2013
Simply put

The 2013 Omnibus Final Rule is a set of updates to the HIPAA rules published by the U.S. Department of Health and Human Services (HHS) that put into effect several provisions of the HITECH Act. It was designed to strengthen the privacy and security protections for people's health information. Among other changes, it broadened who is directly responsible for protecting health data and updated how breaches are defined and handled.

Formal definition

The 2013 Omnibus Final Rule, published in the Federal Register on January 25, 2013 (Vol. 78, No. 17), is a consolidated rulemaking comprised of four final rules that modify the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules, implementing a number of provisions of the HITECH Act. Notably, it expanded the definition of 'business associate' to include entities that create, receive, maintain, or transmit PHI on behalf of a covered entity, extending direct compliance obligations to such parties (and, by extension, subcontractors) rather than limiting them to covered entities alone. It also revised the breach standard, generally treating an unauthorized acquisition, access, use, or disclosure of unsecured PHI as a breach subject to the Breach Notification Rule's analysis, and made other modifications such as those affecting disclosure of student immunization records. Practitioners should note that the specific regulatory text, effective and compliance dates, and CFR provisions should be verified against the current codified regulations, and that state law or other frameworks may impose additional requirements beyond those in this rule.

Why it matters

The 2013 Omnibus Final Rule represents one of the most significant modifications to the HIPAA regulatory framework since the original rules took effect, because it put into force provisions of the HITECH Act and reshaped who bears direct legal responsibility for protecting health information. Before these changes, direct compliance obligations rested primarily with covered entities, and the many vendors handling protected health information were largely reached only through contractual arrangements. By expanding the definition of business associate to include entities that create, receive, maintain, or transmit PHI on behalf of a covered entity, and extending obligations to their subcontractors, the rule brought a much broader set of organizations under direct regulatory reach.

For compliance, privacy, and security professionals, the rule matters because it altered day-to-day risk exposure. Business associates and their subcontractors became directly accountable for certain HIPAA requirements rather than only contractually liable to a covered entity, which changed how organizations negotiate business associate agreements and how they assess vendor risk. The rule also revised the breach standard, generally treating an unauthorized acquisition, access, use, or disclosure of unsecured PHI as a breach subject to the Breach Notification Rule's analysis, which affected how organizations evaluate and respond to potential incidents.

Because the rule implemented HITECH Act provisions and consolidated changes across the Privacy, Security, Breach Notification, and Enforcement Rules, its effects are foundational to how HIPAA compliance is practiced today. Readers should note that specific effective and compliance dates, penalty tiers, and codified provisions are adjusted over time and should be confirmed against the current regulatory text, and that state law or other frameworks may impose additional requirements beyond this rule.

Who it's relevant to

Business Associates and Subcontractors
The rule's expanded definition of business associate is most directly consequential for vendors and their subcontractors that create, receive, maintain, or transmit PHI on behalf of a covered entity. These organizations became subject to certain direct HIPAA compliance obligations rather than being reached only through contract with a covered entity. Such parties should review their business associate agreements and understand which Security Rule and Breach Notification obligations now attach to them directly.
Covered Entities
Healthcare providers, health plans, and healthcare clearinghouses affected by the rule need to understand how the broadened business associate definition and revised breach standard change their vendor management, contracting, and incident response practices. Covered entities remain responsible for their own compliance while relying on business associate agreements to allocate responsibilities to vendors.
Privacy and Security Officers
Those responsible for HIPAA compliance programs must account for the rule's revised breach standard, under which an unauthorized acquisition, access, use, or disclosure of unsecured PHI is generally treated as a breach subject to the Breach Notification Rule's analysis, when designing incident evaluation and notification procedures. They should confirm current compliance dates and codified requirements against the applicable regulatory text.
Legal and Compliance Counsel
Attorneys and compliance professionals advising healthcare organizations rely on the rule's implementation of HITECH Act provisions to shape contracts, risk assessments, and enforcement exposure analysis. They should note that the rule works by amending existing HIPAA rules and that penalty tiers and specific provisions are adjusted over time, and that state law or other frameworks may impose additional requirements beyond this rule.

Inside 2013 Omnibus Final Rule

Direct Liability for Business Associates
The Omnibus Rule extended certain HIPAA obligations directly to business associates, making them directly liable for compliance with applicable provisions of the Security Rule and specified portions of the Privacy Rule, rather than only being bound through business associate agreements. Practitioners should confirm the precise scope of direct obligations against the current regulatory text.
Subcontractor Coverage
The rule clarified that subcontractors who create, receive, maintain, or transmit protected health information on behalf of a business associate are themselves treated as business associates, extending obligations down the chain of relationships. This means BAA-type flow-down requirements generally apply beyond the first-tier vendor.
Modifications Implementing the HITECH Act
The Omnibus Rule implemented statutory changes from the HITECH Act, incorporating enhancements to privacy, security, and enforcement provisions into the HIPAA regulatory framework. Readers should verify the specific HITECH provisions and their effective dates against current guidance.
Revised Breach Notification Standard
The rule modified the standard for assessing whether an impermissible use or disclosure of PHI constitutes a reportable breach, moving toward a risk-assessment-based approach. Breach determination and notification obligations are enforced by HHS OCR under the Breach Notification Rule; specific thresholds and factors should be confirmed against current regulation.
Strengthened Enforcement Provisions
The rule incorporated changes to the Enforcement Rule, including a tiered penalty structure tied to culpability. Penalty tiers and dollar figures are adjusted over time and should be confirmed against current HHS OCR guidance rather than assumed to be fixed.
Expanded Individual Rights
The rule adjusted certain individual rights under the Privacy Rule, such as provisions relating to access to PHI and restrictions on certain disclosures. The precise scope of these rights should be verified against the applicable regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about 2013 Omnibus Final Rule.

Did the 2013 Omnibus Final Rule make business associates directly liable under HIPAA for the first time?
The Omnibus Rule extended direct liability for compliance with certain HIPAA requirements to business associates, rather than leaving their obligations solely a matter of contract with covered entities. Before this change, business associate obligations generally flowed only through business associate agreements (BAAs). After the rule, business associates became directly subject to specified provisions of the Security Rule and certain Privacy Rule requirements, and can be subject to enforcement by HHS OCR. The rule also clarified that subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves treated as business associates. Note that direct liability applies to defined categories of obligations, not to every provision of HIPAA; readers should verify the specific requirements against the current regulatory text.
Does the 2013 Omnibus Final Rule mean any breach of unsecured PHI must automatically be reported?
Not automatically. The Omnibus Rule modified the breach notification standard by replacing the earlier 'significant risk of harm' analysis with a presumption that an impermissible use or disclosure of unsecured PHI is a breach unless the covered entity or business associate demonstrates a low probability that the PHI has been compromised, based on a risk assessment. This shifts the analytical framework toward a documented risk assessment rather than eliminating it. The obligation to notify attaches under the Breach Notification Rule and is enforced by HHS OCR. Specific notification timelines, thresholds, and content should be confirmed against the current regulation, and state law or the HITECH Act may impose additional requirements.
How should we update our business associate agreements in light of the Omnibus Rule?
In most cases, organizations should review existing BAAs to confirm they reflect the expanded obligations the Omnibus Rule addressed, including provisions requiring business associates to comply with applicable Security Rule requirements, to report breaches, and to ensure that subcontractors agree to comparable restrictions. Because subcontractors are treated as business associates, agreements should flow relevant obligations down the chain. The rule provided transition considerations for agreements in place at the time, so organizations should verify current compliance dates and any grandfathering provisions against the applicable regulatory text rather than assuming they still apply.
What practical steps should a covered entity take to align its breach response process with the revised standard?
Covered entities generally should document a repeatable risk assessment methodology consistent with the Omnibus Rule's four-factor approach, which typically considers the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which risk has been mitigated. Organizations should train staff to recognize potential impermissible uses or disclosures, log incidents, and retain documentation supporting any determination that a breach did not occur. Because notification obligations and timelines are set by the Breach Notification Rule and may interact with state law, confirm the current requirements against the applicable regulation.
Do the Omnibus changes affect how we handle patient authorizations and marketing communications?
The Omnibus Rule addressed several Privacy Rule provisions, including limitations on the use and disclosure of PHI for certain marketing and fundraising activities and restrictions on the sale of PHI, generally requiring authorization in defined circumstances. Practically, organizations should review authorization forms, marketing and fundraising practices, and opt-out mechanisms to confirm alignment. Because these are Privacy Rule matters, they apply to PHI in all forms, not only electronic PHI. The precise scope of what requires authorization should be verified against the current regulatory text.
How does the Omnibus Rule interact with a HITRUST CSF certification effort?
The Omnibus Rule is part of the HIPAA regulatory framework enforced by HHS OCR, whereas the HITRUST CSF is a certifiable control framework maintained by HITRUST, a private organization. A HITRUST certification may help an organization structure and demonstrate controls that map to HIPAA requirements, but certification is not a legal requirement and does not by itself establish HIPAA compliance with the Omnibus Rule's provisions. Organizations pursuing certification should treat it as complementary to, not a substitute for, a HIPAA compliance program, and confirm control mappings against the current HITRUST CSF version and the current regulatory text.

Common misconceptions

The Omnibus Rule made business associates fully liable for all HIPAA requirements, just like covered entities.
The rule created direct liability for business associates only for specified provisions, generally the Security Rule and certain Privacy Rule requirements. It did not impose the full set of covered entity obligations on business associates. Practitioners should confirm the exact scope against the current regulatory text.
Because subcontractors are now covered, HIPAA directly regulates every vendor that touches healthcare data.
Obligations attach through defined relationships, not to any vendor that touches data. A subcontractor is treated as a business associate only when it creates, receives, maintains, or transmits PHI on behalf of a business associate, and obligations flow down through the applicable agreements.
The revised breach notification standard eliminated the need to assess whether an incident is reportable.
The rule shifted toward a risk-assessment-based approach rather than removing the assessment. An impermissible use or disclosure is not automatically a reportable breach; determination follows the applicable factors, and the specifics should be confirmed against the current Breach Notification Rule.

Best practices

Review and update business associate agreements to reflect direct liability provisions and to ensure flow-down obligations extend to subcontractors that handle PHI.
Map your vendor relationships to determine which parties qualify as business associates or subcontractors, since obligations attach through defined relationships rather than mere data access.
Align breach response procedures with the risk-assessment-based standard, and verify current breach determination factors and notification requirements against HHS OCR guidance.
Confirm current enforcement penalty tiers and figures against current HHS OCR guidance rather than relying on prior amounts, since these are adjusted over time.
Verify the specific HITECH-derived provisions, effective dates, and CFR citations against the current regulatory text before relying on them operationally.
Assess and document individual rights processes to reflect any changes to access and restriction provisions, and check whether state law or other frameworks impose additional requirements beyond HIPAA.