top of page

HIPAA Privacy Rule Changes 2026: What Covered Entities Need to Know About the Coordinated Care Update

  • Writer: Author: Venus Caruso
    Author: Venus Caruso
  • 11 minutes ago
  • 4 min read

As of August 17, 2026, the long-awaited final rule modifying the HIPAA Privacy Rule to support coordinated care and individual engagement (RIN 0945-AA00) remains in the Final Rule Stage. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has targeted August 2026 for final action. Agency timeline estimates are not binding, and the final rule has not yet been published in the Federal Register.

Originally proposed in January 2021, these modifications aim to strengthen individuals’ rights to access their protected health information (PHI), improve care coordination and case management, facilitate greater family and caregiver involvement, and reduce certain administrative burdens while continuing to protect patient privacy.

Below is a summary of the key proposed changes based on the 2021 Notice of Proposed Rulemaking.

Key Proposed Changes to the HIPAA Individual Right of Access

The HIPAA Privacy Rule proposed changes for 2026 would modernize and expand the right of access under 45 CFR 164.524 by:

  • Strengthening the right to inspect PHI in person (including the right to take notes or use personal devices to capture images).

  • Shortening the required response time from 30 days to 15 calendar days (with one possible 15-day extension).

  • Clarifying what constitutes a “readily producible” form and format, including electronic transmission via secure, standards-based APIs to an individual’s personal health application when the covered entity has the technical capability.

  • Prohibiting unreasonable identity verification measures that create unnecessary barriers.

  • Limiting the right to direct PHI to a third party to electronic copies of PHI maintained in an electronic health record (EHR).

  • Requiring fee transparency, including posting of estimated fee schedules and providing individualized estimates upon request.

New and Amended Definitions

The proposal would add definitions for:

  • Electronic Health Record (EHR): an electronic record of health-related information created, gathered, managed, and consulted by authorized health care clinicians and staff.

  • Personal Health Application: a consumer-facing electronic application used by an individual to access their health information, where the information is managed, shared, and controlled primarily by or for the individual (and generally not subject to HIPAA).

It would also amend the definition of “health care operations” to clarify that individual-level (as well as population-based) care coordination and case management are included.

Facilitating Care Coordination and Information Sharing

Several changes are designed to reduce barriers to beneficial information sharing, including:

  • Creating an exception to the minimum necessary standard for individual-level care coordination and case management uses, disclosures, and requests by health plans and covered health care providers.

  • Expressly permitting disclosures of PHI to social services agencies, community-based organizations, home and community-based services (HCBS) providers, and similar third parties that provide health-related services, when needed for individual-level care coordination or case management.

  • Replacing the “professional judgment” standard with a more flexible “good faith belief” standard (with a presumption of good faith) for certain disclosures to family members and caregivers, particularly in situations involving incapacity, substance use disorder, serious mental illness, or health emergencies.

  • Expanding the standard for disclosures to prevent or lessen a threat to health or safety from “serious and imminent” to “serious and reasonably foreseeable.”

Notice of Privacy Practices (NPP) Changes

The 2021 NPRM proposed several modifications to the Notice of Privacy Practices requirements under 45 CFR 164.520.

Elimination of the Written Acknowledgment Requirement 

Under the current rule, covered health care providers with a direct treatment relationship must make a good faith effort to obtain a written acknowledgment of receipt of the NPP and, if unable to obtain it, document their efforts and the reason the acknowledgment was not obtained. They must also retain that documentation for six years.

The NPRM proposed to eliminate this requirement entirely, along with the related documentation and six-year retention obligations. In its place, the proposal would create an explicit individual right to discuss the NPP with a person designated by the covered entity. The required content of the NPP (including an expanded header) would be updated to inform individuals of this right and provide the designated person’s contact information.

Other NPP Content Updates 

The proposal would also expand the required header and content of the NPP to more clearly explain:

  • How an individual’s health information may be used and disclosed

  • The individual’s rights with respect to that information

  • How to obtain copies of records (at limited cost or free of charge in some cases)

  • How to file a HIPAA complaint

  • The right to receive a copy of the Notice and discuss it with a designated contact person

Closing Remarks  

Until a final rule is published and becomes effective, covered entities and business associates must continue to comply with the current HIPAA Privacy Rule.

HIPAA regulated entities should, however, review current policies and procedures related to individual access, care coordination disclosures, family/caregiver involvement, and Notices of Privacy Practices so they can implement required changes promptly once the compliance date is known.

Once the final rule is published, HIPAA regulated entities should expect a typical compliance timeline of 60 days after publication for the effective date, followed by a 180-day compliance period (approximately eight months from publication).

If you would like to explore how Venus Caruso can assist you with your HIPAA compliance needs, reach out to schedule a complimentary consultation using the contact form or by emailing venus@carusolawoffice.com.

This post provides general information only and is not, and should not be, construed as legal advice or opinion for any individual matter or circumstance. Laws and regulations can change, and specific situations may require different approaches. Always consult a qualified attorney for advice tailored to your specific circumstances.

Back to Top

BACK TO TOP

The information contained on this website is provided for informational purposes only. Nothing stated in or contained on this website should be taken as legal advice or a legal opinion for any individual matter. Your use of this website, review of information on this website, sending or receiving mail from carusolawoffice.com, or contacting the firm via the website's contact form or by email does not create an attorney-client relationship with Caruso Law PLLC or Venus Caruso. 

Hiring a lawyer is an important decision and should not be solely based on advertisements. 

CARUSO LAW PLLC

1645 Palm Beach Lakes Blvd.

West Palm Beach, FL 33401

Available by Appointment

E: contact@carusolawoffice.com
T: (561) 437-2972

Caruso Law Favicon White+Blue _edited.pn
Gold colored badge logo with black text saying "Florida Trend's Florida Legal Elite"
  • X
  • LinkedIn

© 2023-2026 Caruso Law PLLC

bottom of page