Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HHS OCR Announces Expiration of COVID-19 Public Health Emergency HIPAA Notifications of Enforcement Discretions

By John W. Kaveney on April 14, 2023
Email this postTweet this postLike this postShare this post on LinkedIn

The U.S. Department of Health & Human Services Office of Civil Rights (OCR) announced on April 11, 2023 that the Notifications of Enforcement Discretions issued during the COVID-19 Public Health Emergency (PHE) would be expiring at 11:59 p.m. on May 11, 2023 due to the expiration of the PHE. A copy of the notice of expiration can be found here.

Despite this expiration, OCR Director Melanie Fontes Rainer announced that OCR would be “providing a transition period for health care providers to make any changes to their operations that are needed to provide telehealth in a private and secure manner in compliance with the HIPAA Rules.”

Specifically, OCR is providing a 90-calendar day transition period until 11:59 p.m. on August 9, 2023 for health care providers to come into compliance with the HIPAA Rules with respect to their provision of telehealth. Thus, during this 90-day period, health care providers will not face penalties if they engage in the good faith provision of telehealth.

In 2020 and 2021, OCR published four Notifications of Enforcement Discretion in the Federal Register regarding how the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules would be applied to certain violations during the PHE. The following are links to each of those Notifications:

  • Enforcement Discretion Regarding COVID-19 Community-Based Testing Sites During the COVID-19 Nationwide Public Health Emergency – PDF – This Notification announced that OCR would exercise its enforcement discretion to not impose penalties for noncompliance with the HIPAA Rules by covered health care providers, including some large pharmacy chains, and their business associates, in connection with the good faith participation in the operation of COVID-19 specimen collection and testing sites.
  • Enforcement Discretion for Telehealth Remote Communications During the COVID–19 Nationwide Public Health Emergency – PDF – This Notification announced that OCR would exercise its enforcement discretion and would not impose HIPAA penalties for noncompliance with the regulatory requirements under the HIPAA Rules in connection with the good faith provision of telehealth using a non-public facing remote communication technology. This exercise of discretion applied to telehealth provided for any reason, regardless of whether the telehealth service was related to the diagnosis and treatment of health conditions related to COVID-19.
  • Enforcement Discretion Under HIPAA To Allow Uses and Disclosures of Protected Health Information by Business Associates for Public Health and Health Oversight Activities in Response to COVID-19 – PDF – This Notification announced that OCR would exercise its enforcement discretion to not impose penalties on covered health care providers or their business associates for violations of certain provisions of the HIPAA Privacy Rule for uses and disclosures of PHI by business associates for public health and health oversight activities.
  • Enforcement Discretion Regarding Online or Web-Based Scheduling Applications for the Scheduling of Individual Appointments for COVID-19 Vaccination During the COVID-19 Nationwide Public Health Emergency – PDF – This Notification announced that OCR would exercise its enforcement discretion to not impose penalties for noncompliance with the HIPAA Rules by covered health care providers, including some large pharmacy chains and public health authorities, or their business associates, in connection with the good faith use of online or web-based scheduling applications for the limited purpose of scheduling individual appointments for COVID-19 vaccinations.

Health care providers should carefully review each of these Notifications to assess whether adjustments were made to their daily operating practices during the PHE.

Action should be immediately taken to ensure resumed compliance with all applicable HIPAA Rules following the 90-day transition period expiring on August 9, 2023.

Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.

Read more about John W. KaveneyEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Healthcare Perspectives
  • Organization:
    Greenbaum, Rowe, Smith & Davis LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo