OCR Updates Guidance on HIPAA Tracking Technologies

Posted by BAS - 09 May, 2024

header-picture

The U.S. Department of Health and Human Services (HHS) recently revised its guidance on the use of online tracking technologies by Health Insurance Portability and Accountability Act (HIPAA) covered entities and business associates. The Office for Civil Rights (OCR) within HHS administers and enforces the HIPAA Rules, ensuring compliance and investigating breaches or complaints.

Tracking technologies, like cookies and web beacons, gather data on user interactions with websites or mobile apps. If this data includes protected health information (PHI), HIPAA rules apply. Regulated entities must avoid disclosing PHI to tracking technology vendors without authorization, as it can lead to identity theft, discrimination, or other serious consequences.

The guidance emphasizes the need for regulated entities to ensure PHI is disclosed only as permitted by HIPAA. User-authenticated webpages, requiring logins, and unauthenticated webpages, without logins, have different implications for PHI disclosure. Mobile apps offered by regulated entities also fall under HIPAA rules if they collect PHI.

Regulated entities must adhere to various HIPAA requirements when using tracking technologies, including:

  • Only disclosing PHI to vendors with whom they have a business associate agreement (BAA).
  • Ensuring proper safeguards for ePHI, including encryption and access controls.
  • Notifying affected individuals, the Secretary, and the media of any breaches.

OCR prioritizes compliance with the HIPAA Security Rule, aiming to mitigate risks associated with online tracking technologies. Investigations into noncompliance are fact-specific and may involve technical assessments of tracking technology usage.

The guidance underscores the importance of safeguarding PHI in an era of widespread online tracking. Regulated entities must carefully navigate the use of tracking technologies to protect individuals' privacy and comply with HIPAA regulations.


Benefit Allocation Systems (BAS) provides best-in-class, online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.

MyEnroll360 can Integrate with any insurance carrier for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and many others), and integrate with any payroll system for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and many others).

Topics: MyEnroll360 Security, MyEnroll360, MyEnroll360 News, Cybersecurity


Recent Posts

Question of the Week - Domestic Partners and COBRA

read more

Security During Natural Disasters

read more

MyEnroll Library Repository

read more