Index to Section-by-Section Documentation of the HIPAA Regulations

Included here is a section-by-section compilation of the documentation for the HIPAA privacy and security regulations as it appeared in the Federal Register, including the actual regulation, the HHS description and the HHS response to comments received regarding that particular section of the regulations.

The regulations included in the section-by-section compilation include:

A Listing of and Links to the Guidance Documents on HIPAA Privacy From HHS

The Section-by-Section Compilation

Introductory Material

Relationship to Other Federal Laws


Part 160 General Administrative Requirements

General Provisions
Subpart A

Definitions - Section 160.103

Compliance Dates for Implementation of New or Modified Standards and Implementation Specifications - Section 160.105

Preemption of State Law
Subpart B

Statutory Basis - Section 160.201

Definitions - Section 160.202

Compliance and Enforcement
Subpart C

Imposition of Civil Money Penalties
Subpart D

Not included in the section-by-section. The text is available here. The January 2013 HIPAA rules include some revisions to this subpart.


Part 164 Security and Privacy

General Provisions
Subpart A 

Security Standards for the Protection of Electronic Protected Health Information
Subpart C 

Notification in the Case of Breach of Unsecured Protected Health Information
Subpart D

Privacy of Individually Identifiable Health Information
Subpart E

Privacy of Individually Identifiable Health Information
Subpart E

Definitions
Section 164.501

General Rules for Uses and Disclosures of Protected Health Information
Section 164.502

Uses and Disclosures - Organizational Requirements - Component Entities, Affiliated Entities, Business Associates and Group Health Plans
Section 164.504

Uses and Disclosures to Carry Out Treatment, Payment or Health Care Operations
Section 164.506

Uses and Disclosures For Which an Authorization is Required
Section 164.508

Uses and Disclosures Requiring an Opportunity for the Individual to Agree or to Object
Section 164.510

Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object is Not Required
Section 164.512

Other Requirements Relating to Uses and Disclosures of Protected Health Information
Section 164.514

Notice of Privacy Practices for Protected Health Information
Section 164.520

Rights to Request Privacy Protection for Protected Health Information
Section 164.522

Access of Individuals to Protected Health Information
Section 164.524

Amendment of Protected Health Information
Section 164.526

Accounting of Disclosures of Protected Health Information
Section 164.528

The Administrative Requirements
Section 164.530

Transition Provisions - Section 164.532

Compliance Dates - Section 164.534


Practice Areas

Jump to Page

Necessary Cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.