Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA Privacy Rule Updates

The 2024 updates to the HIPAA Privacy Rules include:

  • Allowing patients to inspect PHI in person and take notes or photographs of their PHI.
  • Changing the maximum time to provide access to PHI from 30 days to 15 days.
  • Restricting the right of individuals to transfer ePHI to a third party to only ePHI that is maintained in an EHR.
  • Confirming that an individual is permitted to direct a covered entity to send their ePHI to a personal health application if requested by the individual.
  • Stating when individuals should be provided with ePHI without charge as well as Covered Entities posting estimated fee schedules for PHI access on their websites.
  • PHI can be disclosed by Covered Entities to prevent threats to health or safety. PHI can also be disclosed for the individual’s best interest.
  • Covered Entities will not be required to obtain a written acknowledgement from an individual that they received a Notice of Privacy Practices.
  • The addition of a minimum necessary standard exception for individual-level care coordination and case management uses and disclosures, regardless of whether the activities constitute treatment or health care operations.

Ensure all staff are educated in these changes and understand the necessity to follow the HIPAA Rule(s) requirements.


Author: Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP