45 CFR 155.260
Also known as: 45 CFR 155.260, Exchange privacy and security standards, ACA Exchange PII
Privacy and security of personally identifiable information (45 CFR 155.260) — US Department of Health and Human Services (CMS)
The clause that carries health-insurance Exchange privacy down the contracting chain. An Exchange may only create, collect, use or disclose personally identifiable information where that is strictly necessary to run its statutory functions, and it must bind every non-Exchange entity it works with — issuers, navigators, agents, contractors — to the same standards by agreement, with monitoring and a written breach duty. Operators read it as the Marketplace counterpart of the HIPAA Security Rule.
Subscribe to 45 CFR 155.260 (RSS)
Timeline
No changes recorded yet — we are watching, and nothing has been published.
Monitoring
Watched by 1 official source. Watching since 20 September 2026.