Notice of Enforcement Discretion
A Notice of Enforcement Discretion is an announcement from a federal agency stating that, for a defined situation, it will use its discretion to relax how it applies or enforces certain legal requirements, often temporarily. In the HIPAA context, the Department of Health and Human Services (HHS) has issued such notices to signal it will not impose penalties for specified violations during certain circumstances. It does not repeal or change the underlying rules; it reflects how the agency chooses to enforce them at a given time.
In the HIPAA context, a Notice (or Notification) of Enforcement Discretion is a public statement by HHS, typically issued through its Office for Civil Rights, that it is exercising its discretion in how it applies the HIPAA Rules and, in some cases, will not impose civil money penalties for specified categories of noncompliance under defined conditions or time periods. Examples include the April 2019 notification regarding HIPAA civil money penalty tiers and the April 2020 notification concerning community-based COVID-19 testing sites. Such notices generally alter enforcement posture rather than the substantive regulatory obligations themselves, are commonly time-limited or tied to specific circumstances, and do not amend the underlying Privacy, Security, Breach Notification, or Enforcement Rules. Practitioners should note that the term is used across multiple federal agencies (for example, EPA and NRC) with agency-specific meanings, so the scope, conditions, and duration of any given notice must be verified against the specific issuing document and confirmed against current HHS guidance, as such discretion may be modified or withdrawn over time.
Why it matters
A Notice of Enforcement Discretion directly shapes the real-world risk calculus for HIPAA-regulated organizations because it signals when HHS, typically through its Office for Civil Rights, will refrain from imposing civil money penalties for specified categories of noncompliance. For compliance officers and legal teams, understanding these notices is essential to distinguishing between what the underlying HIPAA Rules require and how the agency is choosing to enforce them at a given moment. Because a NOED changes enforcement posture rather than the substantive obligations themselves, an organization that relies on one still remains subject to the Privacy, Security, Breach Notification, and Enforcement Rules as written.
Who it's relevant to
Inside NOED
Common questions
Answers to the questions practitioners most commonly ask about NOED.