HIPAA Claims Attachments: The Standard to Support
See the primary source.
The Health and Human Services Department adopted standards for health care claims attachments transactions, and a standard for electronic signatures to be used with those transactions, in a final rule cited as 91 FR 14350. The rule is effective May 26, 2026 and amends 45 CFR Part 160 and 45 CFR Part 162. The duty falls on HIPAA covered entities and their business associates, not on every vendor in the chain.
This page is taken from a sealed index of 1086 U.S. federal rules published September 1, 2023 – September 1, 2026 by 11 agencies that govern the industries covered here. It is a snapshot.
Source: Federal Register / eCFR.
What is in force now?
The final rule is already effective. HHS published it on March 24, 2026 at 91 FR 14350, RIN 0938-AT38. The dates text states that the final rule is effective on May 26, 2026, and that the incorporation by reference of certain material listed in the rule is approved by the Director of the Federal Register as of May 26, 2026.
Effective date and compliance date are not the same thing. The Federal Register notice states that compliance with these regulations is required by a date the sealed abstract does not restate here, and that HHS is finalizing a compliance date of 24 months after the effective date of this final rule by which all covered entities must comply. A billing manager who treats May 26, 2026 as the day the practice must already be sending the adopted attachment standard in production is reading the effective date as a production-cutover date. The notice separates those two dates.
The obligation that applies today is therefore live in a specific way: the standards are adopted, the incorporation by reference is approved, and a covered entity has a dated compliance deadline. A practice that is still treating claims attachments as an unregulated side channel is not tracking the rule that is already on the books.
The rule does not say a clearinghouse, a practice-management vendor, or an electronic-health-record vendor is the covered entity. The duty lands on covered entities and their business associates. A vendor may implement the standard because a covered entity contracted for that work; the notice does not recast every vendor in the chain as the party the Administrative Simplification subtitle binds.
What does the rule require?
The final rule implements requirements of the Administrative Simplification subtitle of HIPAA and of the Affordable Care Act. Specifically, it adopts standards for health care claims attachments transactions, which will support health care claims transactions, and a standard for electronic signatures to be used in conjunction with health care claims attachments transactions.
HHS is adding a new Subpart T to 45 CFR Part 162 for health care claims attachments. In that subpart, the notice finalizes the definition of the "health care claims attachments transaction" and adopts standards in the applicable section(a) through (d) for those transactions, and standards for electronic signatures, to be used in conjunction with those transactions, in the applicable section(e).
The notice states that HHS is adopting X12N standards and Health Level 7 (HL7) implementation guides for use by covered entities in health care claims attachments transactions. For the provider-to-plan transmission of attachment information to support a health care claims or equivalent encounter information transaction, the notice adopts the X12N the claims-attachment transaction — Additional Information to Support a Health Care Claim or Encounter (006020X314) as the standard a health care provider must use to electronically transmit that attachment information.
The notice also finalizes, with modification, a definition of "attachment information" in the applicable section as documentation that enables the health plan to make a decision about health care that is not included in a health care claims or equivalent encounter information transaction, as described in the applicable section.
The rule does not, in the sealed display values used for this page, name a commercial e-signature product. The controlling description is the abstract's "standard for electronic signatures to be used in conjunction with health care claims attachments transactions," implemented at the applicable section(e). A practice that needs the incorporated-by-reference title of that signature standard should read the Federal Register list of incorporated material rather than a vendor datasheet.
The notice is a claims-attachment rule. It does not, on this page, get restated as a prior-authorization attachment mandate. Later HHS documents have described the 2026 attachments final rule as not finalizing a prior-authorization attachment standard that had been proposed; this brief stays inside the claims-attachment and electronic-signature adoption the 91 FR 14350 abstract names.
| Adopted item | Where the notice places it | Who the duty lands on |
|---|---|---|
| Health care claims attachments transaction | New Subpart T, 45 CFR Part 162, including the applicable section(a) through (d) | Covered entities; business associates as the contract assigns the work |
| X12N the claims-attachment transaction (006020X314) | Standard a health care provider must use to electronically transmit attachment information to a health plan to support a claim or encounter | The covered provider sending the attachment |
| HL7 implementation guides | Adopted with the X12N standards for claims attachments transactions | Covered entities using those guides as the notice adopts them |
| Electronic signature standard | the applicable section(e), used in conjunction with claims attachments | Covered entities; not every vendor in the chain |
| Attachment information definition | the applicable section | The party assembling documentation that is not already in the claim transaction |
| Effective date | May 26, 2026 | Incorporation by reference approved the same date |
| Compliance date | a date the sealed abstract does not restate here (24 months after the effective date), as the notice states | All covered entities |
That table is the differentiator. The named standard, the compliance date, and the party each duty lands on sit on one row. A billing office that only calendars May 26, 2026 has the effective date and is missing the compliance date. A billing office that tells a clearinghouse "you are the covered entity now" has the vendor and is missing the party the Administrative Simplification subtitle binds.
The rule does not say a penalty dollar this page may copy. The closed fact set does not include one.
Who has to comply?
HIPAA Administrative Simplification duties land on covered entities — health plans, health care clearinghouses, and health care providers who transmit health information in electronic form in connection with a covered transaction — and on business associates as the underlying HIPAA rules already assign them. The notice adopts standards for use by covered entities. The limitation this page must carry is that the duty does not automatically fall on every vendor in the chain.
The reader this brief is written for is a billing manager at a small practice, or the clearinghouse liaison who owns the the claim transaction workflow. That person already sends claims electronically. Claims attachments are the extra documentation a plan asks for when the claim transaction itself does not contain enough information to pay or deny. The rule is the national standard for sending that extra documentation electronically, plus a signature standard used with it.
A clearinghouse or a revenue-cycle vendor may be a business associate. The rule does not say the practice can point at the vendor and treat the covered-entity duty as moved. The contract can assign implementation work; it cannot, on this page, be treated as a transfer of the HIPAA party.
Adjacent healthcare compliance reading that is already live, and that this page does not restate, includes the Medicare program healthcare brief, the Medicaid program healthcare brief, and the hospital price transparency standard-charges brief.
Where do healthcare practices commonly fall short?
The shortfalls below are process patterns. The rule does not publish an enforcement count, and this page does not invent one.
The first pattern is treating attachments as a fax and portal problem with no calendar. The notice adopts a transaction standard and a compliance date. A practice that has no owner for Subpart T will still be sending charts through the old side channel when the compliance date arrives.
The second pattern is calendaring only the effective date. May 26, 2026 is when the rule is effective and the incorporation by reference is approved. a date the sealed abstract does not restate here is when the notice requires compliance. Mixing those two dates produces either a false emergency or a two-year nap.
The third pattern is assuming the the claim transaction claim already carries the attachment. The notice defines attachment information as documentation that is not included in the claims or encounter transaction. The the claims-attachment transaction is additional information to support the claim. A practice that "already files 837s" has not, on that fact alone, adopted the attachment standard.
The fourth pattern is leaving electronic signatures out of the attachment build. The abstract adopts a signature standard to be used in conjunction with claims attachments. A build that maps the the claims-attachment transaction and ignores the applicable section(e) is half a build.
The fifth pattern is telling the clearinghouse it is now the covered entity. The duty falls on covered entities and their business associates, not on every vendor in the chain. A business-associate agreement can assign implementation; it does not, on this page, move the HIPAA party.
The sixth pattern is waiting for a payer to "turn on attachments" before the practice maps its own workflow. The notice is a covered-entity compliance date, not a payer courtesy window. Payer readiness still matters operationally; it is not a substitute for the dated duty.
What self-audit can a billing team run now?
A practice can run this checklist against its the claim transaction workflow without waiting for the compliance date. The rule is already effective.
Name the covered-entity owner for claims attachments. If the only named person is "the clearinghouse," the owner row is empty.
List every current path used to send medical records, operative notes, or other claim-supporting documents that are not in the the claim transaction: fax, payer portal, mail, email, proprietary upload.
Map each path to whether it will become an X12N the claims-attachment transaction (006020X314) transmission, an HL7-guided transmission as the notice adopts those guides, or a path that will be retired.
Confirm the electronic-signature standard at the applicable section(e) has an owner and a place in the attachment build, not a sticky note that says "later."
Calendar both dates: effective May 26, 2026, compliance a date the sealed abstract does not restate here.
Open the business-associate agreements with the clearinghouse and the revenue-cycle vendor and write down who implements the standard and who remains the covered entity.
Route any payer or document type whose standard mapping is unclear to the compliance owner and a qualified professional. The rule does not map a particular plan's companion guide.
| Audit item | Where to look | Pass condition | Fail condition |
|---|---|---|---|
| Covered-entity owner | Job description or compliance roster | A named practice owner | "The clearinghouse owns HIPAA" |
| Current attachment paths | Billing SOP | Fax, portal, mail, and electronic paths are listed | "We just send records" with no list |
| the claims-attachment transaction / HL7 mapping | Vendor worksheet | Each path is mapped to an adopted standard or to retirement | the claim transaction-only worksheet |
| Electronic signature | the applicable section(e) build plan | Signature standard has an owner | Signature left to a later phase with no owner |
| Dual dates | Compliance calendar | May 26, 2026 and a date the sealed abstract does not restate here both present | Only one date |
| Business-associate line | BAA | Implementation assigned; covered-entity party unchanged | Vendor treated as the covered entity |
The two products a small practice already runs for this work are Availity and Waystar. Availity is a payer-connectivity and clearinghouse network many practices use for eligibility, claims, and related administrative transactions. Waystar is a revenue-cycle platform many of the same practices use for claims, eligibility, and denial work. Neither product is the covered entity. They are the pipes a billing manager already uses to move an the claim transaction, and they are the pipes a the claims-attachment transaction will have to travel if the practice's contract puts attachment traffic there.
A third product name would turn this page into a roundup. These two are named because they are the systems a billing manager already opens on the day a claim needs supporting documents.
What can be automated is the flag that a claim still has an attachment sitting in a fax queue, a portal download, or an unsigned packet while the adopted standard is the the claims-attachment transaction path. What needs a human decision is whether a particular document is attachment information under the applicable section, whether the signature standard applies to that packet, and whether a particular payer companion guide is consistent with the adopted standard.
How does a workflow flag billing still running on the old attachment path?
Propagate the coverage and billing rule change across the practice: each affected policy, code, or workflow maps to the change it must reflect. US Tech Automations flags workflows still running on the old rule and routes the update to the compliance owner.
That is flag-and-route. A queue item that says "this claim's operative note went out by fax and is not on a the claims-attachment transaction path" is useful. A queue item that says "this practice is HIPAA-compliant" is not a determination this workflow is allowed to make.
US Tech Automations can watch the attachment paths from the seven-step checklist, attach the 91 FR 14350 citation to the task, and send the item to the named compliance owner. It cannot decide whether a document is attachment information, apply the electronic-signature standard, or file a the claims-attachment transaction in place of the practice.
A useful configuration is one practice, the current attachment-path list, both dates, and a count of claims whose supporting documents still left through a path the practice has marked for retirement. US Tech Automations should sit around Availity and Waystar claim events rather than inside the covered-entity determination. The event is evidence. The duty belongs to the practice.
Key Takeaways
The HHS final rule at 91 FR 14350, RIN 0938-AT38, is effective May 26, 2026 and amends 45 CFR Part 160 and 45 CFR Part 162.
The notice adopts standards for health care claims attachments transactions and a standard for electronic signatures used with those transactions, including the X12N the claims-attachment transaction (006020X314) for provider-to-plan attachment information supporting a claim or encounter.
Compliance is required by a date the sealed abstract does not restate here, 24 months after the effective date, as the notice states.
The duty falls on covered entities and their business associates, not on every vendor in the chain.
The rule does not, in the sealed display values, state a penalty amount this page may copy.
Frequently asked questions
Is the claims-attachment standard still only a proposal?
No. The document at 91 FR 14350 is a final rule, effective May 26, 2026.
When does a covered entity have to support the adopted standard?
The notice states that compliance with these regulations is required by a date the sealed abstract does not restate here, 24 months after the effective date.
Which standard does a provider use to send claim-supporting attachment information?
The notice adopts the X12N the claims-attachment transaction — Additional Information to Support a Health Care Claim or Encounter (006020X314) as the standard a health care provider must use to electronically transmit that attachment information to a health plan.
Does the duty fall on every vendor in the billing chain?
No. The duty falls on covered entities and their business associates. The rule does not recast every vendor as the covered entity.
Is an the claim transaction claim enough, without a separate attachment transaction?
The notice defines attachment information as documentation that is not included in the claims or encounter transaction. Sending an the claim transaction is not, on that fact alone, sending the adopted attachment standard.
Does completing the self-audit mean the practice is compliant?
No. This page is informational. It is not legal advice and does not create an attorney-client relationship. Consult a qualified professional and read the rule.
Disclaimer
This page is for informational purposes only. It is not legal or tax advice and does not create an attorney-client relationship. Consult a qualified professional about a particular practice, transaction, or vendor contract. Read the rule.
Every date, citation, RIN, CFR reference, and figure in these posts is copied verbatim from the Federal Register and eCFR as of the snapshot date. Nothing is estimated, modeled, or extrapolated. This is not legal or tax advice.
.
Last reviewed: March 24, 2026
The exception path is the agentic workflow layer.
About the Author

Helping businesses leverage automation for operational efficiency.
Related Articles
See how AI agents fit your team
US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.
View pricing & plans