US · guidance
CMS Pub. 100-04, ch. 24, § 20.3
HIPAA and ARRA on Security and Privacy
Two aspects of the HIPAA and ARRA legislation are pertinent to this chapter:
1. Ensuring the security of electronic data transmitted between covered entities, and
2. Ensuring the privacy of individuals who are the subject of electronic information
being transmitted between covered entities.
The ARRA legislation states the following in reference to actions to be taken by a
covered entity or their business associate in case of a breach of protected health
information:
H.R. 1 -146, Subtitle D, Part 1, Section 13402 states that “a [covered entity or a]
business associate of a covered entity that accesses, maintains, retains, modifies, records,
stores, destroys, or otherwise holds, uses, or discloses unsecured protected health
information shall, following the discovery of a breach of such information, notify the
covered entity of such breach. Such notice shall include the identification of each
individual whose unsecured protected health information has been, or is reasonably
believed by the business associate to have been, accessed, acquired, or disclosed during
such breach.” See section 40.1.2.2 for a description of Medicare security and privacy
requirements.
History
(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
455c259a4e5e731750b8aa4cb537c5d0d48a434da47d828d2e298b9771695876
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.