Pull your vendor list. Count the rows with a signed business associate agreement executed after September 23, 2013. If that number is smaller than the number of vendors who touch protected health information, the HIPAA Omnibus Rule is sitting in your file as an open finding — and it has been for over a decade.

This article is for the person who signs those contracts. It walks through what the Omnibus Rule obligates a covered entity to do, who inside your practice owns each task, what the documented evidence looks like when OCR asks, and which downstream rules have shifted since 2013. No patient-facing language, no theory.

The Rule Took Effect in 2013 and Nobody Sunset It

HHS published the Omnibus Final Rule on January 25, 2013. It became effective March 26, 2013, with a general compliance date of September 23, 2013. Agreements already in place before January 25, 2013 got a grandfathering window that closed on September 22, 2014.

That last date matters more than people remember. Every BAA transition deadline expired eleven years ago. There is no remaining safe harbor for a pre-Omnibus contract. If your laboratory courier agreement or your answering service contract still uses 2010 language, it is non-compliant on its face, and it is the first thing a reviewer will notice because contract dates are easy to check.

The consolidated regulatory text — Privacy, Security, Breach Notification, and Enforcement Rules as amended by Omnibus — is published by HHS at the combined regulation text page. Keep a copy in your policy binder rather than relying on secondhand summaries.

What Did the HIPAA Omnibus Rule Change?

The HIPAA Omnibus Rule made six structural changes that still drive practice-level obligations:

  1. Direct liability for business associates. Vendors are now regulated entities under the Security Rule and parts of the Privacy Rule, enforceable by OCR without going through you.
  2. Subcontractor coverage. A business associate's subcontractor that creates, receives, maintains, or transmits PHI is itself a business associate and must sign a downstream agreement.
  3. A presumption of breach. The old "significant risk of harm" test was replaced with a presumption that any impermissible use or disclosure is a reportable breach unless a four-factor assessment shows a low probability that PHI was compromised.
  4. Mandatory Notice of Privacy Practices content. New required statements on authorization-triggering uses, fundraising opt-out, the cash-pay restriction, and the duty to notify after a breach.
  5. Marketing and sale-of-PHI restrictions. Communications funded by a third party whose product is described generally require authorization, and any sale of PHI requires authorization disclosing the remuneration.
  6. Tiered civil monetary penalties keyed to culpability, with the top tier reserved for uncorrected willful neglect.

Everything below is the operational version of those six items.

Business Associate Liability Runs in Both Directions

Before 2013, your vendor's compliance was your contract problem. After Omnibus, it is also the vendor's legal problem — OCR can pursue a business associate directly for a Security Rule failure. That did not reduce your exposure. It added a second enforceable party while leaving your obligation to have a compliant agreement fully intact.

The practical consequence: a missing BAA is now a standalone violation on your side and theirs, and OCR resolution agreements have repeatedly cited the absence of an executed agreement as a distinct finding separate from whatever caused the underlying disclosure.

What a Post-Omnibus BAA Must Actually Say

At minimum, your agreement must obligate the business associate to:

  • Comply with the Security Rule's administrative, physical, and technical safeguards with respect to ePHI
  • Report security incidents and breaches of unsecured PHI to you, with a defined timeline
  • Obtain written assurances from any subcontractor that receives PHI
  • Make PHI available to satisfy your access, amendment, and accounting-of-disclosures obligations
  • Make internal practices and records available to HHS for compliance review
  • Return or destroy PHI at termination, or explain why return is infeasible

The Omnibus regulation sets a 60-day outer limit for breach notification, but 60 days from your vendor leaves you almost no runway to meet your own 60-day clock. Negotiate a contractual reporting window of five to ten business days for suspected incidents. Write it in. HHS publishes sample business associate agreement provisions, but those samples are deliberately minimal — they satisfy the regulation and nothing more.

The Vendor Inventory Test

Run this quarterly. Export your accounts-payable vendor list for the last twelve months. For each line, ask one question: does this vendor create, receive, maintain, or transmit PHI on our behalf?

The answers people miss are the boring ones. Shredding companies. Off-site storage. IT contractors with remote access. Transcription. Answering services and after-hours call centers. Billing and collections. Cloud file storage where a staff member parked a scanned intake packet. Marketing agencies with access to a patient email list. Interpreters under contract. Data-analytics or quality-reporting vendors.

Conduit exceptions are narrow — the postal service and an ISP moving encrypted traffic qualify; a cloud storage provider holding your records does not, even if it never looks at the data.

When the inventory turns up a vendor with no agreement on file, you need an executable document, not a project. Practices without in-house counsel can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription — which is usually faster than waiting three weeks for the vendor's own template to arrive from their legal department.

The Breach Presumption: Four Factors, 60 Days, and a Written Record

This is where the Omnibus Rule changed daily operations most. Any acquisition, access, use, or disclosure of PHI not permitted by the Privacy Rule is presumed to be a breach. The burden sits with you to demonstrate otherwise, in writing.

The four factors you must assess and document:

  1. The nature and extent of the PHI involved, including identifier types and the likelihood of re-identification
  2. The unauthorized person who used the PHI or to whom the disclosure was made
  3. Whether the PHI was actually acquired or viewed
  4. The extent to which the risk to the PHI has been mitigated

A Worked Example

Your front desk faxes a five-page consult note to the wrong specialist's office. The receiving practice calls within the hour, confirms it shredded the pages, and sends a written attestation.

Factor one: clinical note with name, DOB, and diagnosis — high sensitivity. Factor two: another HIPAA-covered entity bound by the same rules — favorable. Factor three: pages were viewed at least in part — unfavorable. Factor four: written attestation of destruction — strong mitigation. The privacy officer concludes low probability of compromise, no notification required.

What makes that defensible is not the conclusion. It is the dated memo, signed by the privacy officer, that walks all four factors and attaches the attestation. A conclusion with no memo is indistinguishable from never having looked. Keep it for six years.

The Clocks You Are Running

Individual notice goes out without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals in a state or jurisdiction require contemporaneous notice to HHS and to prominent media in that area. Breaches under 500 go on an internal log submitted to HHS within 60 days after the end of the calendar year — meaning your 2025 log is due by March 1, 2026.

Discovery means the first day the incident is known, or reasonably should have been known, to any workforce member other than the person who caused it. Not the day it reached your desk. Train supervisors to timestamp the report. Submission portals and the public breach list are maintained at the HHS Breach Notification Rule page.

Notice of Privacy Practices Paragraphs You Cannot Omit

Omnibus made specific NPP content mandatory. Your current notice must state that uses and disclosures for marketing, sales of PHI, and most uses of psychotherapy notes require written authorization; that individuals may opt out of fundraising communications; that individuals have the right to restrict disclosure to a health plan for services paid out of pocket in full; and that you are obligated to notify affected individuals after a breach of unsecured PHI.

Practices that updated the notice in 2013 and never touched it again are the common failure. Check three things today: the revision date on the posted notice, whether the version on your website matches the version at the front desk, and whether new patients receive the current version. Material revisions require you to post the updated notice and make it available on request — a paper reprint alone is not enough if you maintain a website.

The Cash-Pay Restriction Your Front Desk Was Never Trained On

Under 45 CFR 164.522(a)(1)(vi), a patient who pays in full out of pocket for a specific item or service can require you to withhold that information from their health plan. You must agree. This is not discretionary the way other restriction requests are.

Operationally that means three things: your scheduling and billing staff need a script and an intake form for the request, your practice management system needs a flag that suppresses that encounter from claims submission, and someone must handle the downstream problem of a bundled claim that would inadvertently reveal the restricted service. Assign an owner. Document the request, the date, and the technical steps taken. This obligation shows up in complaints far more often than practices expect.

Penalty Tiers and Why "Willful Neglect" Is the Word That Matters

Omnibus locked in four culpability tiers: lack of knowledge; reasonable cause; willful neglect corrected within 30 days; and willful neglect not corrected. Per-violation and annual amounts are adjusted for inflation and published by HHS each year, so verify current figures rather than quoting a number from an old training deck.

The operational lesson is the 30-day correction window. A gap you identify and fix, with dated evidence, lands in a materially lower tier than the same gap discovered by an investigator. That is the entire argument for running your own internal audits and writing down what you found — including the failures. A remediation log showing a missing BAA identified in March and executed in April is a defense. Silence is not.

What Has Shifted Since 2013

The Omnibus framework is intact, but three developments belong on your 2026 calendar.

Part 2 alignment. The February 2024 final rule aligning 42 CFR Part 2 substance use disorder records with HIPAA carries a compliance date of February 16, 2026. If your practice creates or receives Part 2 records, your NPP and consent workflows need revision before that date.

Security Rule modernization. OCR published a proposed overhaul of the Security Rule in January 2025 that would tighten technical safeguards and reduce the flexibility of "addressable" implementation specifications. It remains a proposal. Do not rebuild your program around it, but do not assume the current baseline is permanent either.

Reproductive health privacy. The 2024 rule adding heightened protections was largely vacated by a federal district court in June 2025. The Part 2-related NPP requirements were not disturbed. Confirm which version of the notice your vendor or template provider is shipping.

Your Evidence File, Item by Item

When a reviewer asks how you comply with the HIPAA Omnibus Rule, these are the artifacts that answer the question:

  • A current vendor inventory with a BAA status column and a date for each executed agreement
  • Executed BAAs with post-2013 language, plus documentation that subcontractor assurances exist
  • A four-factor breach risk assessment template, and completed assessments for every incident — including those you concluded were not reportable
  • Your annual small-breach log and proof of submission
  • The current NPP, with revision date, posted on the website and available at intake
  • A written procedure for cash-pay restriction requests, with a named owner
  • Dated workforce training records covering breach reporting and restriction requests
  • Your most recent Security Rule risk analysis and the remediation log that flows from it

Most practices have four or five of these. The gaps cluster around the risk analysis and the vendor inventory, because both require sustained attention rather than a one-time document.

Start with the vendor list this week — it is the fastest finding to close. Generate the business associate agreements you are missing and get them countersigned, then work outward to the risk analysis and policy set that the rest of your file depends on. A documented gap you are actively fixing is a different conversation than a gap you never looked for.