HHS Issues NPRM to Strengthen Protections under HIPAA for Reproductive Privacy
Time 2 Minute Read
Categories: Health Privacy

On April 12, 2023, the U.S. Department of Health and Human Services (“HHS”) issued a Notice of Proposed Rulemaking (“NPRM”) to modify protections under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) to strengthen reproductive health care privacy.

The NPRM comes after President Biden in a July 2022 executive order directed HHS to consider taking actions, including under HIPAA, to better protect reproductive health care information in the wake of the Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization.

The NPRM proposes to modify the HIPAA Privacy Rule by prohibiting covered entities and their business associates from using or disclosing protected health information (“PHI”) where the PHI would be used for:

  • a criminal, civil or administrative investigation into or proceeding against any “person” (i.e., under HIPAA, a covered entity, business associate, the individual data subject, or any other person or entity) in connection with seeking, obtaining, providing or facilitating lawful reproductive health care; or
  • identifying any person for the purpose of initiating such an investigation or proceeding.

The NPRM would continue to allow the use or disclosure of PHI for purposes otherwise permitted under HIPAA where the request for PHI “is not made primarily for the purpose of investigating or imposing liability on any person for the mere act of seeking, obtaining, providing or facilitating reproductive health care that is lawful under the circumstances in which it is provided.”

To implement the prohibition, the NPRM would require a regulated entity, when it receives a request for PHI potentially related to reproductive health care, to obtain a signed attestation that the use or disclosure is not for a prohibited purpose.

Public comments on the NPRM will be due 60 days after publication of the NPRM in the Federal Register, which occurred on April 17, 2023.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page