2024 HIPAA Final Rule: The New Attestation Requirement
Published for On the Civil Side on July 01, 2024.
This post is written by my colleague, Kirsten Leloudis, who works in the area of public health. Her contact information is below.
On June 25, 2024, changes to the HIPAA Privacy Rule aimed at supporting reproductive health care privacy went into effect. Last week, I published a blog post about these changes, including the creation of three new types of prohibited uses and disclosures of protected health information (PHI). This post addresses another major change to the law: a new attestation requirement that applies to four types of uses and disclosures when the PHI at issue is “potentially related” to reproductive health care. It’s not just covered entities and business associates that need to understand this new requirement- judicial officials, law enforcement, health oversight agencies, and medical examiners who frequently request PHI to carry out their official duties will likely encounter situations that require them to comply with the new attestation requirement, too.
Background
Numerous changes to the HIPAA Privacy Rule, including the new attestation requirement, are the result of a Final Rule that was published by the U.S. Department of Health and Human Services (HHS) on April 26, 2024. For more information about what prompted promulgation of the Final Rule, a summary of key changes, and an in-depth look at the Final Rule’s creation of new prohibited uses and disclosures of PHI, please see this blog post.
Important Dates
The changes initiated by the Final Rule went into effect on June 25, 2024. Entities that must abide by HIPAA (covered entities and business associates) must come into compliance with these new requirements- including the attestation requirement- no later than December 23, 2024.
There is one exception: the required updates to covered entities’ notices of privacy practices (NPPs), which are addressed in 45 CFR 164.520, do not have to be implemented until February 16, 2026.
The Attestation Requirement
The attestation requirement can be found at the new 45 CFR 164.509. Under this provision of the HIPAA Privacy Rule, covered entities and business associates are required to obtain a valid attestation from a party requesting PHI when both of the following are true:
- The requestor is seeking the PHI for one of four types of uses/disclosures of PHI that already exist under the Privacy Rule (health oversight activities, judicial and administrative proceedings, certain law enforcement uses, and certain coroner/medical examiner uses); and
- The PHI requested is “potentially related” to reproductive health care.
- Health oversight activities (45 CFR 164.512(d)). This includes, for example, a health oversight agency auditing patient records to confirm that the covered entity or business associate is complying with the law.
- Judicial and administrative proceedings (45 CFR 164.512(e)). This includes requests for PHI that come in the form of a subpoena or a court order so that the PHI may be used in an administrative, criminal, or civil case.
- Law enforcement uses (45 CFR 164.512(f)). This includes disclosing PHI to law enforcement to assist with identifying a fugitive or suspect, providing information about a crime victim, etc.
- Coroner and medical examiner uses (45 CFR 164.512(g)(1)). This would include disclosure of a decedent’s PHI to a coroner or medical examiner for the purpose of determining cause of death.
- A statement that the purpose for which the PHI is requested is not one of the new prohibited uses or disclosures described at 45 CFR 164.502(a)(5)(iii).
- A statement that the party requesting the PHI could be subject to criminal penalties under 42 USC 1320d-6 if that person knowingly and in violation of HIPAA obtains someone’s individually identifiable health information (IIHI) (of which PHI is a subset) or discloses IIHI to another person.

