The U.S. Department of Health and Human Services has adopted a new rule concerning privacy and security for health information, to take into account changes that have occurred in health care since enactment of the Health Insurance Portability and Accountability Act (HIPAA) of 1996. Some of the key features in the 563-page final rule are outlined below.
Privacy notices given by covered entities, such as health-care providers and health plans, must now include a statement about a patient’s right to restrict the disclosure of his or her health information when paying out of pocket for the service.