{"abstract":"The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to require notification of breaches of unsecured protected health information. Section 13402 of the Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the American Recovery and Reinvestment Act of 2009 (ARRA) that was enacted on February 17, 2009, requires HHS to issue interim final regulations within 180 days to require covered entities under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and their business associates to provide notification in the case of breaches of unsecured protected health information. For purposes of determining what information is \"unsecured protected health information,\" in this document HHS is also issuing an update to its guidance specifying the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals.","action":"Interim final rule with request for comments.","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Office of the Secretary"}],"body_html_url":"https://www.federalregister.gov/documents/full_text/html/2009/08/24/E9-20169.html","cfr_references":[{"chapter":null,"citation_url":null,"part":160,"title":45},{"chapter":null,"citation_url":null,"part":164,"title":45}],"citation":"74 FR 42740","comment_url":null,"comments_close_on":null,"correction_of":null,"corrections":[],"dates":"Effective Date: This interim final rule is effective September 23, 2009.","disposition_notes":null,"docket_ids":[],"dockets":[],"document_number":"E9-20169","effective_on":"2009-09-23","end_page":42770,"executive_order_notes":null,"executive_order_number":null,"full_text_xml_url":"https://www.federalregister.gov/documents/full_text/xml/2009/08/24/E9-20169.xml","html_url":"https://www.federalregister.gov/documents/2009/08/24/E9-20169/breach-notification-for-unsecured-protected-health-information","images":{},"images_metadata":{},"json_url":"https://www.federalregister.gov/api/v1/documents/E9-20169?publication_date=2009-08-24","mods_url":"https://www.govinfo.gov/metadata/granule/FR-2009-08-24/E9-20169/mods.xml","not_received_for_publication":null,"page_length":31,"page_views":{"count":7503,"last_updated":"2026-07-26 02:15:03 -0400"},"pdf_url":"https://www.govinfo.gov/content/pkg/FR-2009-08-24/pdf/E9-20169.pdf","presidential_document_number":null,"proclamation_number":null,"public_inspection_pdf_url":null,"publication_date":"2009-08-24","raw_text_url":"https://www.federalregister.gov/documents/full_text/text/2009/08/24/E9-20169.txt","regulation_id_number_info":{"0991-AB56":{"issue":"201104","html_url":"https://www.federalregister.gov/regulations/0991-AB56/breach-notification-for-unsecure-protected-health-information","title":"Breach Notification for Unsecure Protected Health Information","xml_url":"http://www.reginfo.gov/public/do/eAgendaViewRule?pubId=201104&RIN=0991-AB56&operation=OPERATION_EXPORT_XML","priority_category":"Other Significant"}},"regulation_id_numbers":["0991-AB56"],"regulations_dot_gov_info":{"checked_regulationsdotgov_at":"2011-09-13T03:50:11Z"},"regulations_dot_gov_url":null,"significant":true,"signing_date":null,"start_page":42740,"subtype":null,"title":"Breach Notification for Unsecured Protected Health Information","toc_doc":"Breach Notification for Unsecured Protected Health Information","toc_subject":null,"topics":["Administrative practice and procedure","Computer technology","Employee benefit plans","Health","Health care","Health facilities","Health insurance","Health records","Hospitals","Investigations","Medicaid","Medical research","Medicare","Penalties","Privacy","Reporting and recordkeeping requirements"],"type":"Rule","volume":74}