Skip to main content
 

45 CFR 160.410 - Affirmative defenses.

There is 1 rule appearing in the Federal Register for 45 CFR 160. Select the tab below to view, or View eCFR (GPOAccess)
§ 160.410
Affirmative defenses.
(a) For violations occurring prior to February 18, 2009, the Secretary may not impose a civil money penalty on a covered entity for a violation if the covered entity establishes that an affirmative defense exists with respect to the violations, including the following:
(1) The violation is an act punishable under 42 U.S.C. 1320d-6 ;
(2) The covered entity establishes, to the satisfaction of the Secretary, that it did not have knowledge of the violation, determined in accordance with the federal common law of agency, and, by exercising reasonable diligence, would not have known that the violation occurred; or
(3) The violation is—
(i) Due to reasonable cause and not willful neglect; and
(ii) Corrected during either:
(A) The 30-day period beginning on the first date the covered entity liable for the penalty knew, or by exercising reasonable diligence would have known, that the violation occurred; or
(B) Such additional period as the Secretary determines to be appropriate based on the nature and extent of the failure to comply.
(b) For violations occurring on or after February 18, 2009, the Secretary may not impose a civil money penalty on a covered entity for a violation if the covered entity establishes that an affirmative defense exists with respect to the violations, including the following:
(1) The violation is an act punishable under 42 U.S.C. 1320d-6; or
(2) The covered entity establishes to the satisfaction of the Secretary that the violation is—
(i) Not due to willful neglect; and
(ii) Corrected during either:
(A) The 30-day period beginning on the first date the covered entity liable for the penalty knew, or, by exercising reasonable diligence, would have known that the violation occurred; or
(B) Such additional period as the Secretary determines to be appropriate based on the nature and extent of the failure to comply.
[74 FR 56131, Oct. 30, 2009]

Title 45 published on 2012-10-01

The following are only the Rules published in the Federal Register after the published date of Title 45.

For a complete list of all Rules, Proposed Rules, and Notices view the Rulemaking tab.

  • 2013-01-25; vol. 78 # 17 - Friday, January 25, 2013
    1. 78 FR 5566 - Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules
      GPO FDSys XML | Text
      DEPARTMENT OF HEALTH AND HUMAN SERVICES, Office of the Secretary
      Final rule.
      Effective date: This final rule is effective on March 26, 2013. Compliance date: Covered entities and business associates must comply with the applicable requirements of this final rule by September 23, 2013.
      45 CFR Parts 160 and 164

This is a list of United States Code sections, Statutes at Large, Public Laws, and Presidential Documents, which provide rulemaking authority for this CFR Part.

This list is taken from the Parallel Table of Authorities and Rules provided by GPO [Government Printing Office].

It is not guaranteed to be accurate or up-to-date, though we do refresh the database weekly. More limitations on accuracy are described at the GPO site.


United States Code
USC : Title 5 - GOVERNMENT ORGANIZATION AND EMPLOYEES

§ 552 - Public information; agency rules, opinions, orders, records, and proceedings

U.S.C. : Title 42 - THE PUBLIC HEALTH AND WELFARE

§ 1302 - Rules and regulations; impact analyses of Medicare and Medicaid rules and regulations on small rural hospitals

§ 1320d - Definitions

42 USC § 1320d–1 - General requirements for adoption of standards

42 USC § 1320d–2 - Standards for information transactions and data elements

42 USC § 1320d–3 - Timetables for adoption of standards

42 USC § 1320d–4 - Requirements

42 USC § 1320d–5 - General penalty for failure to comply with requirements and standards

42 USC § 1320d–6 - Wrongful disclosure of individually identifiable health information

42 USC § 1320d–7 - Effect on State law

42 USC § 1320d–8 - Processing payment transactions by financial institutions

Title 45 published on 2012-10-01

The following are ALL rules, proposed rules, and notices (chronologically) published in the Federal Register relating to 45 CFR 160 after this date.

  • 2013-04-23; vol. 78 # 78 - Tuesday, April 23, 2013
    1. 78 FR 23872 - HIPAA Privacy Rule and the National Instant Criminal Background Check System (NICS)
      GPO FDSys XML | Text
      DEPARTMENT OF HEALTH AND HUMAN SERVICES, Office of the Secretary
      Advance notice of proposed rulemaking.
      Submit comments on or before June 7, 2013.
      45 CFR Parts 160 and 164