At the end of January the Office for Civil Rights (OCR) of the Department of Health and Human Services published new regulations that dramatically extend the reach of federal health care privacy and security law to a vast array of companies that do business with the health care industry. These long-awaited final omnibus regulations (the "Final Rule") amend the privacy, security, enforcement, and breach notification rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. The Final Rule represents the most significant development in health care privacy and security law since the original HIPAA regulations were published a decade ago.

The Final Rule became effective on March 26, and compliance is generally required by September 23. HIPAA has previously regulated "covered entities," which include health plans, health care providers, and health care clearinghouses. The Final Rule extends certain HIPAA requirements to "business associates" of those covered entities, as well as to their subcontractors.