§1320d–5. General penalty for failure to comply with requirements and standards — Inbound Citations
42 U.S.C. § 1320d–5
Cited by 10 provisions in release 119-102.
Citations to 42 U.S.C. § 1320d–5 as a whole
-
(f) The provisions of sections 1176 and 1177 of the Social Security Act [42 U.S.C. 1320d–5, 1320d–6] shall apply to a violation of this section to the extent and in the same manner as such provisions apply to a violation of part C of title XI of such Act [42 U.S.C. 1320d et seq.]. In applying the previous sentence—(1) the reference to “this subsection” in subsection (a)(2) of such section 1176 shall be treated as a reference to “this subsection (including as applied pursuant to section 290dd–2(f) of this title)”; and(2) in subsection (b) of such section 1176—(A) each reference to “a penalty imposed under subsection (a)” shall be treated as a reference to “a penalty imposed under subsection (a) (including as applied pursuant to section 290dd–2(f) of this title)”; and(B) each reference to “no damages obtained under subsection (d)” shall be treated as a reference to “no damages obtained under subsection (d) (including as applied pursuant to section 290dd–2(f) of this title)”.
-
(3) except as provided in subsection (i), to alter or affect the implementation of any provision of the HIPAA confidentiality regulations or section 1320d–5 of this title (or regulations promulgated under such section);
-
(d) In addition to any other sanctions or remedies that may be available under law, a covered entity that is a group health plan, health insurance issuer, or issuer of a medicare supplemental policy and that violates the HIPAA privacy regulation (as revised under subsection (a) or otherwise) with respect to the use or disclosure of genetic information shall be subject to the penalties described in sections 1320d–5 and 1320d–6 of this title in the same manner and to the same extent that such penalties apply to violations of this part.
-
(b) In the case of a business associate that violates any security provision specified in subsection (a), sections 1320d–5 and 1320d–6 of this title shall apply to the business associate with respect to such violation in the same manner such sections apply to a covered entity that violates such security provision.
-
(c) In the case of a business associate that violates any provision of subsection (a) or (b), the provisions of sections 1176 and 1177 of the Social Security Act (42 U.S.C. 1320d–5, 1320d–6) shall apply to the business associate with respect to such violation in the same manner as such provisions apply to a person who violates a provision of part C of title XI of such Act [42 U.S.C. 1320d et seq.].
-
(2) Any violation by a covered entity under thus1 subchapter is subject to enforcement and penalties under section2 1176 and 1177 of the Social Security Act [42 U.S.C. 1320d–5, 1320d–6].
-
(1) Subject to the regulation promulgated pursuant to paragraph (3), any civil monetary penalty or monetary settlement collected with respect to an offense punishable under this subchapter or section 1176 of the Social Security Act (42 U.S.C. 1320d–5) insofar as such section relates to privacy or security shall be transferred to the Office for Civil Rights of the Department of Health and Human Services to be used for purposes of enforcing the provisions of this subchapter and subparts C and E of part 164 of title 45, Code of Federal Regulations, as such provisions are in effect as of February 17, 2009.
-
(a) Consistent with the authority of the Secretary under sections 1320d–5 and 1320d–6 of this title, when making determinations relating to fines under such section 1320d–5 (as amended by section 13410 of Pub. L. 111–5) or such section 1320d–6, decreasing the length and extent of an audit under section 17940 of this title, or remedies otherwise agreed to by the Secretary, the Secretary shall consider whether the covered entity or business associate has adequately demonstrated that it had, for not less than the previous 12 months, recognized security practices in place that may—(1) mitigate fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5);(2) result in the early, favorable termination of an audit under section 17940 of this title; and(3) mitigate the remedies that would otherwise be agreed to in any agreement with respect to resolving potential violations of the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title) between the covered entity or business associate and the Department of Health and Human Services.
-
(1) mitigate fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5);
-
(2) Nothing in this section shall be construed as providing the Secretary authority to increase fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5), or the length, extent or quantity of audits under section 17940 of this title, due to a lack of compliance with the recognized security practices.