Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HHS Issues Limited Waiver of HIPAA Sanctions Post-Hurricane Harvey

By Pamela Del Negro on September 8, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

The U.S. Department of Health and Human Services (HHS) has used its authority to waive certain provisions of HIPAA in response to Hurricane Harvey.  HHS previously declared a public health emergency in Texas and Louisiana related to the hurricane and its aftermath.  

Under the waiver, HHS waives sanctions against covered hospitals that do not comply with HIPAA requirements to distribute a notice of privacy practices; obtain a patient’s agreement in order to speak with family and friends; and honor a request to opt-out of a facility directory.  HHS also waived sanctions against covered hospitals that do not comply with a patient’s right to request privacy restrictions or confidential communications.

The waiver only applies to the emergency area, for the period identified in the declaration of public health emergency.  The waiver is limited to hospitals that have instituted a disaster protocol, and applies for a period of up to 72 hours from the time the protocol is implemented or, if shorter, the time when the state of emergency is lifted.

This post is also being shared on our Data Privacy +Security Insider blog. If you’re interested in getting updates on developments affecting data privacy and security, we invite you to subscribe to the blog.

Photo of Pamela Del Negro Pamela Del Negro

Pamela H. Del Negro is a member of Robinson+Cole’s Health Law Group, where she advises institutional providers, including hospitals and ambulatory surgery centers, as well as physician practice groups, community providers, and other health care entities on health care issues and general corporate…

Pamela H. Del Negro is a member of Robinson+Cole’s Health Law Group, where she advises institutional providers, including hospitals and ambulatory surgery centers, as well as physician practice groups, community providers, and other health care entities on health care issues and general corporate matters. She provides legal counsel on a full range of transactional and regulatory health law issues, including co-management arrangements; compliance plans; the acquisition and merger of medical entities; Medicare and Medicaid fraud and abuse and the Stark law; hospital affiliations; the privacy and security of personal health information; corporate governance; private placements; and contracting. She also works with clients on managed care contracting, the corporate practice of medicine issues, clinical integration and antitrust issues, and the structuring and acquisition of electronic health records technology, including the negotiation and documentation of software agreements. Read her full rc.com bio here.

Read more about Pamela Del NegroEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Health Law Diagnosis
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo