On April 6, 2022, HHS Office for Civil Rights (OCR) issued a Request for Information (RFI) to solicit public comment on the implementation of the newly-enacted “safe harbor” under the Health Insurance Portability and Accountability Act (HIPAA). The safe harbor, enacted in January 2021 at 42 U.S.C. § 17941, requires HHS, when making determinations regarding fines, audits, and remedies to resolve potential violations of the HIPAA Security Rule, to consider “recognized security practices” that HIPAA covered entities and business associates “adequately demonstrate” were in place for the preceding 12 months. The RFI solicits comments on how covered entities and business associates understand and are implementing recognized security practices, how they anticipate adequately demonstrating security practices are in place, and other implementation issues they are considering or would like OCR to clarify for the public. OCR notes that it expects “adequate demonstration” to include the implementation and not merely adoption of the practices. A copy of the RFI is available here.