Title 42The Public Health and WelfareRelease 119-73

§17941 Recognition of security practices

Title 42 › Chapter CHAPTER 156— - HEALTH INFORMATION TECHNOLOGY › Subchapter SUBCHAPTER III— - PRIVACY › Part Part A— - Improved Privacy Provisions and Security Provisions › § 17941

Last updated Apr 6, 2026|Official source

Summary

When deciding whether to lower fines, shorten an audit, or reduce other penalties for violations of the HIPAA Security Rule, the Secretary must look at whether the covered entity or business associate had recognized security practices in place for at least the previous 12 months. If those practices are shown, they can help reduce fines, allow an audit to end sooner on good terms, or lead to smaller agreed remedies. Recognized security practices — standards, guidelines, best practices, methods, or processes for cybersecurity developed or accepted under federal programs — are chosen by the covered entity or business associate but must be consistent with the HIPAA Security Rule. The Secretary cannot raise fines or expand audits because an organization did not follow these practices, and choosing not to use them does not by itself create liability. This does not limit the Secretary’s power to enforce the HIPAA Security Rule or change an entity’s obligations under that rule.

Full Legal Text

Title 42, §17941

The Public Health and Welfare — Source: USLM XML via OLRC

(a)Consistent with the authority of the Secretary under section 1320d–5 and 1320d–6 of this title, when making determinations relating to fines under such section 1320d–5 (as amended by section 13410 of Pub. L. 111–5) or such section 1320d–6, decreasing the length and extent of an audit under section 17940 of this title, or remedies otherwise agreed to by the Secretary, the Secretary shall consider whether the covered entity or business associate has adequately demonstrated that it had, for not less than the previous 12 months, recognized security practices in place that may—
(1)mitigate fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5);
(2)result in the early, favorable termination of an audit under section 17940 of this title; and
(3)mitigate the remedies that would otherwise be agreed to in any agreement with respect to resolving potential violations of the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title) between the covered entity or business associate and the Department of Health and Human Services.
(b)(1)The term “recognized security practices” means the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15, the approaches promulgated under section 1533(d) of title 6, and other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities. Such practices shall be determined by the covered entity or business associate, consistent with the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title).
(2)Nothing in this section shall be construed as providing the Secretary authority to increase fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5), or the length, extent or quantity of audits under section 17940 of this title, due to a lack of compliance with the recognized security practices.
(3)Subject to paragraph (4), nothing in this section shall be construed to subject a covered entity or business associate to liability for electing not to engage in the recognized security practices defined by this section.
(4)Nothing in this section shall be construed to limit the Secretary’s authority to enforce the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title), or to supersede or conflict with an entity or business associate’s obligations under the HIPAA Security rule.

Reference

Citations & Metadata

Citation

42 U.S.C. § 17941

Title 42The Public Health and Welfare

Last Updated

Apr 6, 2026

Release point: 119-73