Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
May 13, 2025
No Result
View All Result
Concur News

Home » HIPAA rule faces legal pushback from states

HIPAA rule faces legal pushback from states

April 24, 2025
in America, News, Privacy, United States
Reading Time: 5 mins read
HIPAA rule faces legal pushback from states

HIPAA rule faces legal pushback from states

Share on LinkedinShare on Whatsapp

In April 2024, the Biden administration finalized a rule under HIPAA to protect the privacy of reproductive healthcare information. This came nearly two years after the Supreme Court overturned Roe v. Wade, a decision that triggered new abortion laws in many states. This rule took effect in June 2024.

This rule stops covered entities from sharing protected health information (PHI) if it could be used to impose criminal, civil, or administrative penalties on anyone seeking or providing legal reproductive healthcare. Officials from the Department of Health and Human Services (HHS) hoped it would help ease fears and legal confusion around data privacy in reproductive care.

What Does the Rule Change?

Before this rule, HIPAA-covered entities couldn’t share PHI without the patient’s permission, except in limited cases—like court orders, law enforcement, or health oversight.

Consent Foundation

Roger Cohen, a healthcare law partner at Goodwin, explained:

“And after the Dobbs decision overturning Roe v. Wade, there were laws passed outlawing abortion or limiting abortion in a number of states. There was concern about the ability of law enforcement authorities to access reproductive health information and use it to prosecute women who had abortions, healthcare providers who provided abortions.”

Now, the rule strictly prohibits sharing PHI for investigating or prosecuting someone who legally accessed or provided reproductive care. It also requires a signed attestation for requests involving reproductive health information, confirming that the request isn’t for a prohibited purpose. Covered entities must also update their Notice of Privacy Practices to reflect the new protections for reproductive health data.

Legal Challenges Create Uncertainty

Not everyone agrees with the rule. In September 2024, Texas Attorney General Ken Paxton sued the HHS, claiming the rule interferes with states’ rights to investigate crimes. Paxton said,

“This new rule actively undermines Congress’s clear statutory meaning when HIPAA was passed, and it reflects the Biden Administration’s disrespect for the law. The federal government is attempting to undermine Texas’s law enforcement capabilities, and I will not allow this to happen.”

His lawsuit argues that the rule conflicts with existing HIPAA provisions and the Administrative Procedure Act, which governs how federal agencies make rules.

In January 2025, 15 more states joined in, just before President Trump took office. These states said the rule could interfere with investigations into Medicaid fraud, abuse, or insurance crimes.

Their filing claimed:

“That result flouts HIPAA, which specifically preserves States’ longstanding authority to investigate healthcare-related issues.”

Roger Cohen added context around the rule’s future:

“One other interesting factor here is that agencies, prior to the overturning of Chevron — or, changing of the law around the deference that agencies get in rulemaking — an agency would get deference in how it interpreted what public health means. But that’s no longer the law. So really, a court gets to decide what Congress intended when it said the law shouldn’t interfere with public oversight of public health.”

It’s now up to the courts to decide if the rule aligns with HIPAA’s intent—or if the rule will be changed or revoked by the new administration.

What Covered Entities Can Do Now

Despite legal uncertainty, covered entities must comply with the rule while it’s in effect. Experts suggest that now is a good time for organizations to revisit and improve their privacy practices. Healthcare lawyer Roger Cohen shared,

“One low-hanging fruit or box to check is to update your notice of privacy practices and distribute the updated notice to patients. The regulations are still in effect, and so regulated entities should comply with them.”

He also advised:

“If you get a request for reproductive health information, consult with your counsel on the request to ensure you’re complying with the regulations.”

Covered entities should know that PHI disclosures for reproductive care are restricted in some cases but allowed in others. For example:

  • If someone travels to another state for legal reproductive care, their provider doesn’t need to disclose that.
  • But a provider can disclose PHI to defend themselves in a legal case about misconduct or negligence.

Keep Watching the Rule’s Status

With lawsuits ongoing and a new administration in office, the future of this rule remains unclear. Still, HIPAA compliance is an ongoing responsibility, and organizations should continue to:

  • Consult legal counsel when handling reproductive health PHI
  • Update privacy notices to reflect the current law
  • Monitor legal developments around the rule

The privacy landscape is changing fast—but protecting patient data should always remain a top priority.

Also Read: DataKrypto Launches FHEnom for AI to Secure Models and Data with Fast Homomorphic Encryption

Tags: Data privacyPrivacy

Related Posts

EasemyTrip
India

EaseMyTrip Founder Warns of Security Risks from China-Linked Travel Apps

May 12, 2025
Michigan
LAW

Michigan Attorney General Sues Roku for Alleged COPPA Violations

May 10, 2025
EIB
Europe

EDPS Blocks EIB’s Data Transfer to India Over Privacy Law Concerns

May 10, 2025
Pearson
Europe

Pearson Confirms Cyberattack, Customer Data and Source Code Stolen

May 10, 2025

RECOMMENDED NEWS

skyward

Skyward Specialty Data Breach Exposes Sensitive Documents on Dark Web

4 weeks ago
Vahan and Sarathi Data Sharing: Government Earns Rs 100 Crores

Vahan and Sarathi Data Sharing: Government Earns Rs 100 Crores

1 month ago
Are Gurugram's Gate Apps Compromising Your Privacy?

Are Gurugram’s Gate Apps Compromising Your Privacy?

3 weeks ago
DeepSeek Shared User Data with Chinese Server Without Consent, Says South Korea

DeepSeek Shared User Data with Chinese Server Without Consent, Says South Korea

3 weeks ago

BROWSE BY TOPICS

AI AI Governance AI Privacy Children privacy Compliance Consent Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy Data Protection Data Safeguard Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines Fraud GDPR Generative AI Hack Hacked Industry Interview Investigation Law penalty Personal data PHI PII Press Release Privacy RBI RTI Act Startek Tech giants Technology Training Trending

Trimtab Innovation Pvt. Ltd 701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
error: Content is protected !!
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager