45 CFR 155.260

Also known as: 45 CFR 155.260, Exchange privacy and security standards, ACA Exchange PII

Privacy and security of personally identifiable information (45 CFR 155.260) — US Department of Health and Human Services (CMS)

The clause that carries health-insurance Exchange privacy down the contracting chain. An Exchange may only create, collect, use or disclose personally identifiable information where that is strictly necessary to run its statutory functions, and it must bind every non-Exchange entity it works with — issuers, navigators, agents, contractors — to the same standards by agreement, with monitoring and a written breach duty. Operators read it as the Marketplace counterpart of the HIPAA Security Rule.

Subscribe to 45 CFR 155.260 (RSS)

Timeline

No changes recorded yet — we are watching, and nothing has been published.

Monitoring

Watched by 1 official source. Watching since 20 September 2026.