Bindinglaw

US · guidance

CMS Pub. 100-04, ch. 24, § 20.3

HIPAA and ARRA on Security and Privacy

activein force · 2026-08-25 – presentas-observed

Two aspects of the HIPAA and ARRA legislation are pertinent to this chapter:

1. Ensuring the security of electronic data transmitted between covered entities, and

2. Ensuring the privacy of individuals who are the subject of electronic information

being transmitted between covered entities.

The ARRA legislation states the following in reference to actions to be taken by a

covered entity or their business associate in case of a breach of protected health

information:

H.R. 1 -146, Subtitle D, Part 1, Section 13402 states that “a [covered entity or a]

business associate of a covered entity that accesses, maintains, retains, modifies, records,

stores, destroys, or otherwise holds, uses, or discloses unsecured protected health

information shall, following the discovery of a breach of such information, notify the

covered entity of such breach. Such notice shall include the identification of each

individual whose unsecured protected health information has been, or is reasonably

believed by the business associate to have been, accessed, acquired, or disclosed during

such breach.” See section 40.1.2.2 for a description of Medicare security and privacy

requirements.

History

(Rev. 2803, Issued: 10-28-13, Effective: 09-17-13, Implementation: 09-17-13)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
455c259a4e5e731750b8aa4cb537c5d0d48a434da47d828d2e298b9771695876
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.