Related Experiment Video
Updated: May 11, 2026

Safety Precautions and Operating Procedures in an (A)BSL-4 Laboratory: 4. Medical Imaging Procedures
Published on: October 3, 2016
New HIPAA rules: a guide for radiology providers
Adrienne Dresevic1, Clinton Mikel
1The Health Law Partners, PC. adresevic@thehlp.com
Abstract:
The Office for Civil Rights issued its long awaited final regulations modifying the HIPAA privacy, security, enforcement, and breach notification rules--the HIPAA Megarule. The new HIPAA rules will require revisions to Notice of Privacy Practices, changes to business associate agreements, revisions to HIPAA privacy and security policies and procedures, and an overall assessment of HIPAA compliance. The HIPAA Megarule formalizes the HITECH Act requirements, and makes it clear that the OCRs ramp up of HIPAA enforcement is not merely a passing trend. The new rules underscore that both covered entities and business associates must reassess and strengthen HIPAA compliance.
Insights
The final HIPAA Omnibus Rule (Health Insurance Portability and Accountability Act) mandates significant compliance updates for healthcare organizations. Entities must revise privacy notices, business associate agreements, and security protocols to meet new federal standards.
Area of Science:
- Healthcare Law
- Information Security
- Regulatory Compliance
Background:
- The Health Insurance Portability and Accountability Act (HIPAA) established national standards for protecting sensitive patient health information.
- Previous regulations required adherence to privacy, security, and breach notification rules.
- The HITECH Act introduced further requirements and enforcement mechanisms for HIPAA compliance.
Purpose of the Study:
- To analyze the implications of the final HIPAA Omnibus Rule (HIPAA Megarule) on healthcare entities and business associates.
- To highlight the mandatory revisions required for HIPAA compliance under the new regulations.
- To emphasize the Office for Civil Rights' (OCR) increased focus on HIPAA enforcement.
Main Methods:
- Review of the final HIPAA Omnibus Rule published by the Office for Civil Rights.
- Analysis of the regulatory changes impacting covered entities and business associates.
- Identification of necessary updates to compliance policies, procedures, and agreements.
Main Results:
- The HIPAA Megarule necessitates revisions to Notice of Privacy Practices.
- Changes are required for business associate agreements and HIPAA privacy/security policies.
- A comprehensive assessment of overall HIPAA compliance is mandated.
Conclusions:
- The HIPAA Megarule formalizes HITECH Act requirements and signals intensified OCR enforcement.
- Covered entities and business associates must proactively reassess and strengthen their HIPAA compliance measures.
- Failure to adapt to the new HIPAA rules poses significant compliance risks.
More Related Videos
Related Concept Videos
Legal Guidelines for Documentation
Standards of Care II
Radiological Investigation I: X-ray and CT
Radiological Investigation III: Pulmonary Angiogram and PET Scan
Pulmonary Angiogram
A Pulmonary Angiogram is an invasive procedure involving injecting a contrast medium through a catheter threaded into the pulmonary artery or the right side of the heart to visualize the pulmonary vasculature. Computed Tomography (CT) scans have mainly replaced this...
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security:
Imaging Studies for Cardiovascular System III: X-Ray
Definition and Purpose
An X-ray, or radiograph, is a non-invasive method that uses ionizing radiation to take images of internal structures. It is mainly used in cardiac imaging to examine the heart, lungs, and major blood vessels, aiming to identify abnormalities in the heart's size, shape, and position, such as heart failure, congenital defects, and vascular...

