Skip to main content
Category: OCR Enforcement and Penalties

Notice of Enforcement Discretion

Also known as: NOED, Notification of Enforcement Discretion, Enforcement Discretion Notice, HIPAA Enforcement Discretion
Simply put

A Notice of Enforcement Discretion is an announcement from a federal agency stating that, for a defined situation, it will use its discretion to relax how it applies or enforces certain legal requirements, often temporarily. In the HIPAA context, the Department of Health and Human Services (HHS) has issued such notices to signal it will not impose penalties for specified violations during certain circumstances. It does not repeal or change the underlying rules; it reflects how the agency chooses to enforce them at a given time.

Formal definition

In the HIPAA context, a Notice (or Notification) of Enforcement Discretion is a public statement by HHS, typically issued through its Office for Civil Rights, that it is exercising its discretion in how it applies the HIPAA Rules and, in some cases, will not impose civil money penalties for specified categories of noncompliance under defined conditions or time periods. Examples include the April 2019 notification regarding HIPAA civil money penalty tiers and the April 2020 notification concerning community-based COVID-19 testing sites. Such notices generally alter enforcement posture rather than the substantive regulatory obligations themselves, are commonly time-limited or tied to specific circumstances, and do not amend the underlying Privacy, Security, Breach Notification, or Enforcement Rules. Practitioners should note that the term is used across multiple federal agencies (for example, EPA and NRC) with agency-specific meanings, so the scope, conditions, and duration of any given notice must be verified against the specific issuing document and confirmed against current HHS guidance, as such discretion may be modified or withdrawn over time.

Why it matters

A Notice of Enforcement Discretion directly shapes the real-world risk calculus for HIPAA-regulated organizations because it signals when HHS, typically through its Office for Civil Rights, will refrain from imposing civil money penalties for specified categories of noncompliance. For compliance officers and legal teams, understanding these notices is essential to distinguishing between what the underlying HIPAA Rules require and how the agency is choosing to enforce them at a given moment. Because a NOED changes enforcement posture rather than the substantive obligations themselves, an organization that relies on one still remains subject to the Privacy, Security, Breach Notification, and Enforcement Rules as written.

Who it's relevant to

Privacy and Compliance Officers
These professionals must track active Notices of Enforcement Discretion to understand where HHS has signaled it will not impose penalties, while recognizing that the underlying HIPAA obligations remain unchanged. They should document the specific scope, conditions, and duration of any notice their organization relies upon and monitor for updates or withdrawal.
Legal and Regulatory Counsel
Attorneys advising covered entities and business associates need to read the precise text of each HHS notice to assess whether a client's activities fall within its defined scope. They should also caution clients that discretion notices from other agencies, such as the EPA or NRC, carry agency-specific meanings and do not affect HIPAA obligations.
Security and IT Leadership
Where a notice touches on activities involving ePHI or specific operational circumstances, security leaders should confirm exactly which requirements the discretion addresses and continue meeting all obligations not covered. A NOED does not relax the Security Rule's administrative, physical, or technical safeguards outside its stated scope.
Organizations Operating Under Emergency or Special Circumstances
Entities that stood up services under situations addressed by an HHS notice, such as the April 2020 notification concerning community-based COVID-19 testing sites, should track whether the applicable discretion remains in effect and prepare for a return to standard enforcement once a notice is modified or ends.

Inside NOED

Enforcement Discretion
A statement in which HHS OCR announces that, for a defined period or set of circumstances, it will not impose penalties or will exercise discretion in enforcing certain HIPAA requirements. It reflects a temporary policy choice by the enforcing authority rather than a change to the underlying regulatory text.
Scope and Applicability
The specific provisions, entities, activities, or timeframes to which the discretion applies. A notice typically identifies which HIPAA rules or requirements (for example, aspects of the Privacy Rule or Security Rule) are affected and which covered entities or business associates may rely on it.
Conditions and Limitations
Any qualifying conditions that must be met for the discretion to apply, such as acting in good faith or using the flexibility only for a stated purpose. The notice generally spells out what remains out of scope and continues to be fully enforceable.
Effective Period
The duration for which the discretion is in effect. Such notices are often tied to specific circumstances (for example, a public health emergency) and may be time-limited or subject to termination, so practitioners should confirm the current status against OCR guidance.
Issuing Authority
HHS OCR, the office responsible for enforcing HIPAA. Enforcement discretion is an exercise of that authority's prosecutorial or penalty judgment and does not alter obligations arising under other laws or from other authorities.

Common questions

Answers to the questions practitioners most commonly ask about NOED.

Does a Notice of Enforcement Discretion change or repeal the underlying HIPAA rules?
No. A Notice of Enforcement Discretion does not amend, repeal, or waive any provision of the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. The underlying regulatory requirements generally remain in effect. What the notice typically does is announce that HHS OCR will exercise its discretion not to impose penalties, or will do so in a limited way, for certain specified conduct during a defined period or set of circumstances. Because the rules themselves are unchanged, covered entities and business associates should treat the notice as a temporary or conditional enforcement posture rather than a permanent change to their legal obligations, and should verify the exact scope against the current published notice.
If OCR issues a Notice of Enforcement Discretion, does that mean I am fully compliant and protected from all liability?
Not necessarily. Enforcement discretion is generally narrow in scope, applying only to the specific conduct, entities, and time frame described in the notice, and often subject to conditions. It typically addresses HHS OCR's federal enforcement of HIPAA only. It does not by itself establish compliance, and it generally does not affect potential liability under state laws, the HITECH Act provisions, other federal authorities, contractual obligations, or private causes of action that may exist under applicable law. Readers should not assume broad immunity and should confirm the precise terms and limits against the current notice and consult counsel where liability questions arise.
How do I determine whether a specific activity falls within the scope of a given Notice of Enforcement Discretion?
Read the notice carefully to identify its stated scope, including which entities are covered, which specific conduct or rule provisions are addressed, any conditions that must be met, and the effective time period. Enforcement discretion generally applies only to activity that fits squarely within those defined parameters. Conduct outside the described scope typically remains subject to full enforcement. Because scope language can be technical and situation-specific, organizations should document their analysis and confirm interpretation against the current text of the notice and, where appropriate, seek legal review.
What should an organization document while relying on a Notice of Enforcement Discretion?
As a general practice, organizations should document the specific notice being relied upon, the date and scope, the conditions the notice imposes, and how their activities meet those conditions. Maintaining records of good-faith efforts, risk analyses, and any safeguards implemented during the period can be helpful. Because enforcement discretion is typically time-limited and conditional, documentation supports demonstrating that reliance was reasonable and within scope. Organizations should confirm documentation expectations against the current notice, as some notices specify particular conditions or good-faith requirements.
What happens to an organization's obligations when a Notice of Enforcement Discretion expires or is withdrawn?
When enforcement discretion ends, the affected conduct generally becomes subject to full HIPAA enforcement again, because the underlying rules were never suspended. Organizations should plan for the transition by identifying any temporary practices adopted under the notice that would not meet the standard requirements, and by bringing those practices into alignment before the discretion lapses. Effective dates and withdrawal timing should be verified against current HHS OCR guidance, as these can change and are sometimes tied to specific circumstances rather than fixed calendar dates.
Does a Notice of Enforcement Discretion affect obligations under state law, the HITECH Act, or frameworks like the HITRUST CSF?
Generally, a Notice of Enforcement Discretion addresses HHS OCR's federal enforcement of HIPAA and does not, by itself, alter obligations arising under state privacy or breach laws, other federal statutes, or contractual commitments. HITRUST is a private organization and the HITRUST CSF is a separate certifiable control framework; an OCR enforcement notice does not change CSF requirements, and HITRUST certification is not a legal substitute for HIPAA compliance. Organizations operating under such a notice should still assess whether state law or other frameworks impose requirements beyond the scope of the discretion, and verify specifics against current regulatory text and the current HITRUST CSF version.

Common misconceptions

A Notice of Enforcement Discretion changes or suspends the underlying HIPAA regulation.
Enforcement discretion generally reflects a decision by HHS OCR not to pursue penalties in defined circumstances; the underlying Privacy Rule, Security Rule, and Breach Notification Rule requirements typically remain in effect. Reliance beyond the notice's stated scope and conditions can still result in enforcement, and the discretion may be time-limited or terminated.
Enforcement discretion means covered entities and business associates have no compliance obligations during the covered period.
The discretion typically applies only to specified provisions under stated conditions, often requiring good-faith conduct. Requirements outside the notice's scope continue to apply, and state law or the HITECH Act may impose additional obligations that OCR's discretion does not address.
Because it comes from OCR, enforcement discretion shields organizations from all liability related to the affected activity.
A notice generally addresses only OCR's own HIPAA enforcement posture. It does not necessarily eliminate exposure under state law, contractual obligations, or other frameworks, and figures, timeframes, and conditions should be verified against the current OCR notice.

Best practices

Read the specific Notice of Enforcement Discretion in full and rely only on the provisions, entities, and activities expressly within its stated scope rather than assuming broad relief.
Confirm the current effective status and any effective period directly against HHS OCR guidance, since such notices are often time-limited and may be modified or terminated.
Document good-faith compliance efforts and how your organization meets any conditions the notice imposes, in case you must later demonstrate eligibility for the discretion.
Continue to meet all HIPAA requirements that fall outside the notice's scope, treating the discretion as a narrow, temporary exception rather than a general suspension of obligations.
Assess whether state law, the HITECH Act, contractual commitments, or other frameworks impose additional obligations that OCR's discretion does not affect.
Consult legal or compliance counsel before relying on enforcement discretion for significant decisions, and verify any dates, conditions, or figures against the current regulatory text and OCR guidance.