Does the NPRM alter the definition of protected health information in any way?
Yes, the definition would be modified to make clear that the Privacy and Security Rules “do not protect the individually identifiable health information of persons who have been deceased for more than 50 years,” so those who have been deceased since at least 1960 (assuming the final Rule becomes effective this year). Proposed Modifications to the HIPAA Security Rule As discussed above, the proposed modifications would add references to business associates in the Security Rule to make clear that, consistent with the requirements of the HITECH Act, business associates are now directly responsible for complying with the Security Rule. • Is a covered entity required to obtain by contract assurances regarding security of ePHI from subcontractors acting as business associates under the new definition? No. That is the responsibility of the business associate. The proposed modifications would “clarify that covered entities are not required to obtain satisfactory assurances in the form of a con