2019-21031. Agency Information Collection Request. 30-Day Public Comment Request  

  • Start Preamble

    AGENCY:

    Office of the Secretary, HHS.

    ACTION:

    Notice.

    SUMMARY:

    In compliance with the requirement of the Paperwork Reduction Act of 1995, the Office of the Secretary (OS), Department of Health and Human Services, is publishing the following summary of a proposed collection for public comment.

    DATES:

    Comments on the Information Collection Request (ICR) must be received on or before October 30, 2019.

    ADDRESSES:

    Submit your comments to OIRA_submission@omb.eop.gov or via facsimile to (202) 395-5806.

    Start Further Info

    FOR FURTHER INFORMATION CONTACT:

    Sherrette Funn, Sherrette.Funn@hhs.gov or (202) 795-7714. When submitting comments or requesting information, please include the document identifier 0945-0003-New-30D and project title for reference.

    End Further Info End Preamble Start Supplemental Information

    SUPPLEMENTARY INFORMATION:

    Interested persons are invited to send comments regarding this burden estimate or any other aspect of this collection of information, including any of the following subjects: (1) The necessity and utility of the proposed information collection for the proper performance of the agency's functions; (2) the accuracy of the estimated burden; (3) ways to enhance the quality, utility, and clarity of the information to be collected; and (4) the use of automated collection techniques or other forms of information technology to minimize the information collection burden.

    Title of the Collection: HIPAA Privacy, Security, and Breach Notification Rules, and Supporting Regulations Contained in 45 CFR parts 160 and 164.

    Type of Collection: Extension.

    OMB No. 0945-0003: Office for Civil Rights (OCR)—Health Information Privacy Division.

    Abstract: Office for Civil Rights (OCR) requests approval to extend this existing, approved collection without changing any collection requirements while OCR obtains public comment through a Notice of Proposed Rulemaking (NPRM) proposing modifications to the HIPAA Rules that will affect the hourly burdens associated with the Rules. This notice does, however, make the following revisions to estimates provided in the 60-day public comment request, which do not change the collection requirements: (1) Lower the estimated number of individuals who call an entity's toll-free number for information after being affected by a breach requiring substitute notice to reflect a more realistic estimate of the proportion of individuals who choose to call; and (2) correct an error from the 2016 ICR notice that underestimated the average number of individuals affected per breach because it relied on older breach data. This notice also incorporates data from the 60-day public comment request which recognizes for the first time the burdens resulting from the pre-existing, ongoing requirements for business associates to report breaches of PHI to their covered entities.

    We did not receive public comment on the 60-day public comment request published on July 19, 2019. We expect to receive robust public comment on existing burdens associated with compliance with the HIPAA Rules and on changes in burden that could result from the modifications proposed in the NPRM. OCR will update this ICR to reflect the input we receive.

    Likely Respondents: HIPAA covered entities, business associates, individuals, and professional and trade associations of covered entities and business associates.Start Printed Page 51605

    Estimated Annualized Burden Table

    Forms (if necessary)Respondents (if necessary)Number of respondentsNumber of responses per respondentsAverage burden per responseTotal burden hours
    45 CFR 160.204 Process for Requesting Exception Determinations (states or persons)A state's chief elected official or designee111616
    45 CFR 164.308 Risk Analysis—DocumentationCovered entities; business associates1,700,00011017,000,000
    45 CFR 164.308 Information System Activity Review—DocumentationCovered entities; business associates1,700,000120.7515,300,000
    45 CFR 164.308 Security Reminders—Periodic UpdatesCovered entities; business associates1,700,00012120,400,000
    45 CFR 164.308 Security Incidents (other than breaches)—DocumentationCovered entities; business associates1,700,000525442,000,000
    45 CFR 164.308 Contingency Plan—Testing and RevisionCovered entities; business associates1,700,0001813,600,000
    45 CFR 164.308 Contingency Plan—Criticality AnalysisCovered entities; business associates1,700,000146,800,000
    45 CFR 164.310 Maintenance RecordsCovered entities; business associates1,700,000126122,400,000
    45 CFR 164.314 Security Incidents—Business Associate reporting of incidents (other than breach) to Covered EntitiesBusiness associates1,000,0001220240,000,000
    45 CFR 164.316 Documentation—Review and UpdateCovered entities; business associates1,700,0001610,200,000
    45 CFR 164.404 Individual Notice—Written and Email Notice (drafting)Covered entities58,48210.529,241
    45 CFR 164.404 Individual Notice—Written and Email Notice (preparing and documenting notification)Covered entities58,48210.529,241
    45 CFR 164.404 Individual Notice—Written and Email Notice (processing and sending)Covered entities58,4821,9410.008908,108
    45 CFR 164.404 Individual Notice—Substitute Notice (posting or publishing)Covered entities2,746112,746
    45 CFR 164.404 Individual Notice—Substitute Notice (staffing toll-free number)Covered entities2,74613.429,391
    45 CFR 164.404 Individual Notice—Substitute Notice (individuals' voluntary burden to call toll-free number for information)Covered entities113,26410.12514,158
    45 CFR 164.406 Media NoticeCovered entities26711.25334
    45 CFR 164.408 Notice to Secretary (notice for breaches affecting 500 or more individuals)Covered entities26711.25334
    45 CFR 164.408 Notice to Secretary (notice for breaches affecting less than 500 individuals)Covered entities58,2151158,215
    45 CFR 164.410 Business associate notice to covered entity—500 or more affected individualsBusiness Associates201501,000
    45 CFR 164.410 Business associate notice to covered entity—Less than 500 affected individualsBusiness Associates1,165189,320
    45 CFR 164.414 500 or More Affected Individuals (investigating and documenting breach)Covered entities26715013,350
    45 CFR 164.414 Less than 500 Affected Individuals (investigating and documenting breach)—affecting 10-499Covered entities2,4791819,832
    45 CFR 164.414 Less than 500 Affected Individuals (investigating and documenting breach)—affecting <10Covered entities55,73614222,944
    45 CFR 164.504 Uses and Disclosures—Organizational RequirementsCovered entities700,00010.08333333358,333
    45 CFR 164.508 Uses and Disclosures for Which Individual authorization is requiredCovered entities700,00011700,000
    45 CFR 165.512 Uses and Disclosures for Research PurposesCovered entities113,52410.0833333339,460
    Start Printed Page 51606
    45 CFR 164.520 Notice of Privacy Practices for Protected Health Information (health plans—periodic distribution of NPPs by paper mail)Covered entities—health plans100,000,00010.004166667416,667
    45 CFR 164.520 Notice of Privacy Practices for Protected Health Information (health plans—periodic distribution of NPPs by electronic mail)Covered entities—health plans100,000,00010.002783333278,333
    45 CFR 164.520 Notice of Privacy Practices for Protected Health Information (health care providers—dissemination and acknowledgement)Covered entities—health care providers613,000,00010.0530,650,000
    45 CFR 164.522 Rights to Request Privacy Protection for Protected Health InformationCovered entities—health care providers, health plans20,00010.051,000
    45 CFR 164.524 Access of Individuals to Protected Health Information (disclosures)Covered entities—health care providers, health plans, clearinghouses200,00010.0510,000
    45 CFR 164.526 Amendment of Protected Health Information (requests)Covered entities—health care providers, health plans, clearinghouses150,00010.08333333312,500
    45 CFR 164.526 Amendment of Protected Health Information (denials)Covered entities—health care providers, health plans, clearinghouses50,00010.0833333334,167
    45 CFR 164.528 Accounting for Disclosures of Protected Health InformationCovered entities—health care providers, health plans, clearinghouses5,00010.05250
    Total921,158,941
    Start Signature

    Debbie Kramer,

    HHS Information Collection Reports Clearance Officer.

    End Signature End Supplemental Information

    [FR Doc. 2019-21031 Filed 9-27-19; 8:45 am]

    BILLING CODE 4153-01-P

Document Information

Published:
09/30/2019
Department:
Health and Human Services Department
Entry Type:
Notice
Action:
Notice.
Document Number:
2019-21031
Dates:
Comments on the Information Collection Request (ICR) must be received on or before October 30, 2019.
Pages:
51604-51606 (3 pages)
Docket Numbers:
Document Identifier: OS-0945-0003
PDF File:
2019-21031.pdf