In general— The Secretary of Health and Human Services, in consultation with the Federal Trade Commission, shall promulgate regulations setting privacy, security, and breach notifications standards for the processing of applicable health information by regulated entities and their service providers. Such standards shall provide protections that are at least commensurate with, and wherever feasible and appropriate harmonize with, the protections provided through the privacy, security, and breach notification rules promulgated under section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (
42 U.S.C. 1320d–2 note) and section 13402 of the HITECH Act (
42 U.S.C. 17932) that apply to covered entities and business associates with respect to protected health information under such rules. Such regulations promulgated under this section shall include the following:
(1)
Privacy requirements, including the following:
(A)
Permitted uses and disclosures of applicable health information without an individual’s written authorization that are consistent with the individual’s reasonable expectations.
(B)
Other permitted uses and disclosures of applicable health information without an individual’s written authorization for certain public policy purposes, such as public health, health oversight, law enforcement, judicial and administrative proceedings, and any conditions for such uses and disclosures.
(C)
Uses and disclosures of applicable health information that require the individual’s written authorization and the requirements related to such written authorizations.
(D)
Prohibited uses and disclosures of applicable health information.
(E)
Minimum necessary requirements for the request, use, and disclosure of applicable health information and any exceptions.
(F)
Standards and requirements related to legal representatives of the individual.
(G)
Standards and requirements related to service providers.
(H)
Individual rights with respect to applicable health information, including the right of the individual to receive a privacy notice from the regulated entity, access to applicable health information, amendment of applicable health information, deletion of applicable health information, and portability of applicable health information, and any exceptions to such rights (such as with respect to applicable health information collected for research purposes), any conditions on such rights, and any other requirements related to such rights, including timeframes for responding to requests.
(I)
Administrative safeguards, including designation of a privacy officer, policies and procedures, training of workforce members, non-retaliation, documentation, and mitigation.