Skip to main content
Category: Regulatory Framework

Title II

Also known as: ADA Title II, Title II of the ADA
Simply put

Title II is the part of the Americans with Disabilities Act (ADA) that requires state and local government entities to make their services, programs, and activities accessible to people with disabilities. In practice, this means public entities must avoid disability-based discrimination and, under recent rulemaking, meet web content accessibility standards. Note that this term refers to the ADA and is distinct from other laws that share similar section numbering, including the HIPAA administrative simplification provisions commonly discussed in healthcare compliance.

Formal definition

As used in the evidence provided, Title II refers to Title II of the Americans with Disabilities Act (ADA), which addresses accessibility obligations for state and local government entities and prohibits disability-based discrimination in the services, programs, or activities of those public entities. A U.S. Department of Justice rule extends these obligations to require that state and local governments ensure their web content and mobile applications meet specified web accessibility standards. Practitioners should note that the evidence packet addresses only the ADA meaning of Title II; the phrase 'Title II' is also used in other statutory contexts (for example, HIPAA's Administrative Simplification provisions are contained in Title II of HIPAA), and those meanings are not documented in the provided sources. Specific effective dates, compliance deadlines, and technical standards should be verified against the current DOJ rule and the applicable regulatory text.

Why it matters

For healthcare compliance professionals, the most important thing to understand about ADA Title II is that it is a different legal framework from the HIPAA provisions often discussed under the label 'Title II.' The phrase 'Title II' appears in multiple statutes, and HIPAA's Administrative Simplification provisions are themselves contained in Title II of HIPAA. Conflating these can lead to serious analytical errors, because ADA Title II governs disability-based accessibility obligations for state and local government entities, while HIPAA governs the privacy and security of protected health information. Practitioners should confirm which 'Title II' is being referenced before applying any obligations.

ADA Title II matters because it establishes that state and local government entities must make their services, programs, and activities accessible to people with disabilities and must avoid disability-based discrimination. For public healthcare organizations, such as state-run hospitals, county health departments, and public university medical centers, this can mean that accessibility obligations under the ADA operate alongside, and independently of, their HIPAA responsibilities. A single public entity may therefore need to satisfy both accessibility requirements and healthcare privacy requirements, drawn from entirely separate legal authorities.

A U.S. Department of Justice rule has extended Title II obligations to require that state and local governments ensure their web content and mobile applications meet specified web accessibility standards. Because effective dates, compliance deadlines, and the exact technical standards involved are set by that rulemaking and may change, readers should verify current requirements against the DOJ rule and the applicable regulatory text rather than relying on general summaries.

Who it's relevant to

Public healthcare organizations (state and local government entities)
State-run hospitals, county health departments, and public university medical centers are state or local government entities and therefore may fall within ADA Title II's scope. These organizations may need to ensure that their services, programs, and activities, including web content and mobile applications, under the DOJ rule, are accessible to people with disabilities, independent of any HIPAA obligations they also carry.
Compliance and privacy officers
Compliance and privacy officers should be able to distinguish ADA Title II from HIPAA's Title II Administrative Simplification provisions. The shared 'Title II' terminology can cause confusion; officers should confirm which framework applies before assigning obligations, and recognize that ADA accessibility requirements are separate from HIPAA privacy and security requirements.
Legal and regulatory teams
Legal teams advising public entities should verify current ADA Title II web accessibility requirements against the applicable DOJ rule and regulatory text, including any effective dates, deadlines, and technical standards, which are not fully documented in the sources here and may be subject to change.
Digital accessibility and IT teams
IT and web teams at covered state and local government entities may need to bring web content and mobile applications into conformance with the specified web accessibility standards referenced in the DOJ rule. The exact standards and timelines should be confirmed against the current rule.

Inside Title II

Administrative Simplification
The portion of HIPAA Title II most relevant to healthcare compliance professionals. It directed the adoption of national standards for electronic healthcare transactions and, through subsequent rulemaking by HHS, gave rise to the Privacy Rule, Security Rule, Breach Notification Rule (added via the HITECH Act), and Enforcement Rule. Readers should verify specific provisions against the current regulatory text.
Privacy Rule
A rule arising under Title II that governs protected health information (PHI) in all forms, including oral, paper, and electronic. It sets standards for the use and disclosure of PHI by covered entities and, through business associate agreements, their business associates.
Security Rule
A rule arising under Title II that applies specifically to electronic protected health information (ePHI). It establishes administrative, physical, and technical safeguards, with implementation specifications designated as either required or addressable.
Breach Notification Rule
Added to the HIPAA framework via the HITECH Act, this rule generally establishes obligations to notify affected individuals, HHS, and in certain cases the media following a breach of unsecured PHI. Specific thresholds and timeframes should be confirmed against current guidance.
Enforcement Rule
The rule addressing investigations, penalties, and procedures for HIPAA violations, enforced by HHS OCR. Penalty tiers and figures are adjusted over time and should be confirmed against current guidance.
Regulated relationships (covered entities and business associates)
Title II obligations attach through defined relationships. Covered entities are directly regulated, while business associates and subcontractors take on obligations through business associate agreements rather than because HIPAA directly regulates every vendor that touches data.

Common questions

Answers to the questions practitioners most commonly ask about Title II.

Does HIPAA Title II directly regulate every vendor or company that handles health data?
No. HIPAA does not attach obligations to every entity that touches health data simply because data passes through its systems. Under Title II's administrative simplification provisions, obligations flow through defined relationships: covered entities are directly regulated, and business associates and their subcontractors become subject to certain requirements through business associate agreements and the applicable regulatory text. An organization that does not meet the definition of a covered entity, business associate, or subcontractor is generally not regulated by HIPAA on that basis alone, though state law or other frameworks may impose separate requirements. Readers should verify status against the current regulatory definitions.
Is Title II the same thing as 'the HIPAA rules' most compliance professionals work with day to day?
Title II is broader than the privacy and security rules alone. Its administrative simplification provisions provided the statutory basis from which HHS developed the regulations most professionals reference, including the Privacy Rule, the Security Rule, the Breach Notification Rule, and the Enforcement Rule, as well as transaction and code set standards and identifier requirements. It is more precise to say that the rules practitioners apply day to day were promulgated under the authority of Title II rather than to treat Title II and those specific rules as identical. The distinct scopes of each rule should be kept separate.
Which HIPAA rules were developed under the authority of Title II's administrative simplification provisions?
The administrative simplification provisions of Title II provided the statutory basis for the regulations HHS later issued, which generally include the Privacy Rule (covering PHI in all forms, including oral, paper, and electronic), the Security Rule (covering electronic protected health information only), the Breach Notification Rule, the Enforcement Rule, and standards for electronic transactions, code sets, and identifiers. Each of these rules has a distinct scope and set of obligations. For specific citations and current requirements, readers should consult the applicable regulatory text.
How do Title II obligations reach a business associate or subcontractor?
Obligations reach business associates and subcontractors through defined relationships rather than automatically. A covered entity generally enters into a business associate agreement with a business associate, and a business associate similarly contracts with its subcontractors. These agreements, together with the applicable regulatory requirements, establish the obligations that flow down. Not every requirement that applies to a covered entity applies identically to a business associate, so organizations should map their specific role and confirm the corresponding obligations against the current regulation.
Does complying with Title II's administrative simplification requirements mean an organization is fully compliant with all applicable law?
Not necessarily. Meeting the requirements developed under Title II addresses the federal HIPAA framework enforced by HHS OCR, but it does not by itself establish compliance with every applicable requirement. State privacy and security laws, the HITECH Act, and other frameworks may impose additional or stricter obligations. Separately, obtaining a certification such as HITRUST CSF certification is not a legal requirement and does not by itself establish HIPAA compliance. Organizations should assess the full set of laws and frameworks that apply to their operations.
Who enforces the requirements arising under Title II, and how should penalty information be treated?
The HIPAA rules developed under Title II are generally enforced by HHS OCR, primarily through the Enforcement Rule. Penalty structures are organized into tiers, but the specific dollar figures are adjusted over time and should not be treated as fixed. Because penalty amounts and thresholds change, organizations should confirm current figures against the applicable regulatory text and current HHS guidance rather than relying on previously published numbers.

Common misconceptions

Title II's Security Rule protects all forms of protected health information.
The Security Rule applies only to electronic protected health information (ePHI). PHI in oral and paper form is addressed by the Privacy Rule, not the Security Rule.
Addressable implementation specifications under the Security Rule are optional.
Addressable does not mean optional. An addressable specification must generally be implemented, or an entity must document why it is not reasonable and appropriate and implement an equivalent alternative where reasonable.
Achieving HITRUST CSF certification satisfies HIPAA Title II requirements.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA compliance, though it may support an organization's compliance efforts.

Best practices

Map your obligations to the correct rule: treat Privacy Rule requirements as covering PHI in all forms and Security Rule requirements as covering ePHI only, so safeguards are scoped correctly.
Document the required versus addressable status of each Security Rule implementation specification, and where a specification is addressed with an alternative, retain written rationale rather than treating it as optional.
Identify and formalize regulated relationships through business associate agreements, confirming that obligations flow appropriately to business associates and their subcontractors.
Verify penalty tiers, breach notification thresholds, and specific timeframes against current HHS OCR guidance rather than relying on figures that may have changed over time.
If pursuing HITRUST CSF certification, treat it as a supporting control framework and confirm it against the current CSF version, while separately validating that HIPAA Title II obligations are met.
Check for additional requirements that may apply beyond HIPAA, including state law and HITECH Act provisions, since these can impose obligations stricter than the federal baseline.