The Department of Health and Human Services has issued a final rule amending HIPAA privacy, security, enforcement, and breach notification rules to enhance protections for health information in response to the HITECH Act and the Genetic Information Nondiscrimination Act. Key provisions include making business associates directly liable for HIPAA compliance, expanding individuals' rights regarding their health information, and streamlining breach notification processes. The rule, effective March 26, 2013, is estimated to incur costs between $114 million and $225.4 million in the first year, with ongoing annual costs thereafter.