Ohio Healthcare Compliance Requirements
State-specific breach notification rules, medical records retention periods, PDMP requirements, and mandatory reporting obligations for medical practices operating in Ohio.
Ohio's breach statute carries a hard day count — R.C. §1349.19 requires notification within 45 days of discovery — but it does not reach a medical practice: §1349.19(F)(2) provides that the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a HIPAA-covered practice is exempt from the Ohio statute entirely and HIPAA's 60-day outer limit is the clock that governs. Two corollaries matter operationally. Ohio requires no Attorney General breach notification at all — there is no state-AG track running alongside the federal one — and §1349.19's only third-party trigger is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected, which falls away with the rest of the section for a covered entity. Ohio's pharmacy practice is governed by the Ohio Board of Pharmacy, which operates OARRS (the Ohio Automated Rx Reporting System) as one of the most EHR-integrated PMPs in the country: OARRS queries are embedded in most major Ohio EHR platforms via the state's gateway, and the Board has built pattern-detection tooling that flags dispensing outliers for licensing review. Cleveland, Columbus, and Cincinnati-area health systems coordinate routinely with the Ohio Department of Health on communicable-disease reporting and with the Ohio Department of Job and Family Services on Children's Protective Services and Adult Protective Services mandatory reports. OARRS's deep integration, the Board of Pharmacy's pattern-detection posture, and Ohio's mandatory-reporting web make Ohio one of the more operationally rigorous Midwest jurisdictions — the breach clock is simply not where that rigor lives.
Breach Notification Rules
Notification deadline
60 calendar days (HIPAA)
Ohio law states 45 days, but that figure does not bind a HIPAA covered practice — see below.
Notification must be made no later than 45 days following discovery — Ohio Rev. Code §1349.19. Ohio requires NO Attorney General notification; the only third-party trigger is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected. Decisively for this audience: §1349.19(F)(2) states the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a HIPAA-covered medical practice is exempt from the Ohio statute entirely and HIPAA's timeline governs.
AG notification threshold (as the statute reads)
Not explicitly required
Harm analysis required
Penalty range
Enforceable by AG under Consumer Sales Practices Act; court may award damages
Enforcement Posture
The Ohio Attorney General's office is one of the more active state AGs on consumer-protection enforcement under the Consumer Sales Practices Act, which is the vehicle §1349.19 is enforced through — but §1349.19(F)(2) puts HIPAA covered entities outside the section, so a medical practice's breach exposure runs through HIPAA and OCR rather than a state clock. There is no Ohio AG breach filing to prepare and no state resident threshold to monitor, and the "without unreasonable delay" versus fixed-day-count question never reaches you. The Ohio Board of Pharmacy's posture on OARRS is independently rigorous: dispensing-pattern outliers flagged by OARRS are a routine trigger for licensing-board review and pain-management practice scrutiny in the wake of the opioid-crisis litigation. Document your HIPAA breach timeline, your harm analysis, and your OARRS query log carefully.
Medical Records Retention
| Record type | Retention period | Measured from |
|---|---|---|
| General medical | 7 years | Last treatment |
| Pediatric | 7 years | Patient turns 18 |
Controlled-Substance Prescription Monitoring (OARRS)
OARRS — the Ohio Automated Rx Reporting System — requires a query before issuing any controlled-substance prescription. OARRS is among the most deeply EHR-integrated PMPs in the country: most Ohio EHR platforms surface OARRS data directly in the prescribing workflow via the state's gateway. Delegation to licensed pharmacists, NP/PAs, and RN designees is permitted. Registration at ohiopmp.gov is mandatory for all DEA registrants prescribing in Ohio. Exemptions cover hospice, cancer treatment, ≤3-day ER supplies, inpatient and nursing-facility administration, and medication-assisted treatment.
Check required
Every prescription
Check frequency
Every prescription
Delegation allowed
Penalty range
Licensing board discipline; civil penalties up to $10,000; possible felony charges for pattern noncompliance
Exemptions
Hospice patients, cancer treatment, ≤3 day supply in ER, inpatient hospital or nursing facility, medication-assisted treatment
How Ohio Rules Hit by Specialty
Pain management
Ohio pain-management practices operate under one of the country's most aggressive post-opioid-crisis regulatory regimes. OARRS query patterns and prescribing volumes are reviewed actively by the Ohio Board of Pharmacy and the State Medical Board of Ohio; document your dose, duration, and morphine-milligram-equivalent (MME) reasoning in the chart at every visit.
Pharmacy/compounding
OARRS is embedded into most Ohio EHR platforms; the Board of Pharmacy uses OARRS data for proactive surveillance, not just complaint-driven review. Compounding pharmacies face additional state-board scrutiny on USP 795/797/800 compliance.
Hospital systems
Ohio adds no state layer to the incident-response runbook: §1349.19(F)(2) exempts covered entities and Ohio requires no AG breach notification at any resident count, so the runbook you pre-stage is the federal one — individual notice and the HHS filing on HIPAA's timeline. The §1349.19 consumer-reporting-agency notice above 1,000 affected residents only ever reaches a non-covered affiliate.
Behavioral health
Ohio behavioral health practices follow OARRS for controlled-substance prescribing (buprenorphine, benzodiazepines) and report to the Ohio Department of Mental Health and Addiction Services for substance-use treatment program licensure.
Mandatory Reporting Obligations
Mandated reporters
Physicians, dentists, nurses, psychologists, social workers, and all healthcare professionals acting in professional capacity
Report to
County children services agency or local law enforcement
Timeline
Immediately / as soon as possible
Penalty for failure
Fourth-degree misdemeanor; second-degree misdemeanor if previous conviction
Immunity provision
Good faith reporters immune from civil and criminal liability under ORC 2151.421
Mandated reporters
Physicians, nurses, social workers, and all healthcare professionals
Report to
County Department of Job and Family Services, Adult Protective Services
Timeline
Immediately / as soon as possible
Penalty for failure
Fourth-degree misdemeanor
Immunity provision
Good faith reporters immune from civil and criminal liability
Mandated reporters
Healthcare providers treating injuries from felonious assault or domestic violence
Report to
Local law enforcement
Timeline
Immediately / as soon as possible
Immunity provision
Good faith reporters immune from civil liability
Mandated reporters
Physicians, laboratories, and healthcare facility administrators
Report to
Ohio Department of Health or local board of health
Timeline
Within 24 hours
Penalty for failure
Minor misdemeanor, up to $150 fine
Immunity provision
Good faith reporters immune from civil liability
Mandated reporters
All physicians and healthcare providers treating gunshot wounds, stab wounds, or burn injuries from criminal violence
Report to
Local law enforcement
Timeline
Immediately / as soon as possible
Penalty for failure
Minor misdemeanor
Immunity provision
Good faith reporters immune from civil and criminal liability
Ohio Compliance FAQs
For a HIPAA-covered practice, none — the statute's 45-day figure never starts running against you. §1349.19(F)(2) states the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a covered medical practice is exempt from the Ohio statute entirely and HIPAA's 60-day outer limit is the deadline you work to. Ohio also requires no Attorney General notification at all.
Never. Ohio's statute contains no Attorney General notification requirement at any resident count, which makes it unusual among state breach laws. The only third-party trigger in §1349.19 is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected — and §1349.19(F)(2) exempts covered entities from the section entirely, so that trigger does not reach a medical practice either. Your notifications run to affected individuals and to HHS under the federal Breach Notification Rule.
Yes. Ohio requires an OARRS query before every controlled-substance prescription. Exemptions cover hospice, cancer treatment, ≤3-day ER supplies, inpatient or nursing-facility administration, and medication-assisted treatment. OARRS is deeply EHR-integrated, so most queries occur in the prescribing workflow without leaving the chart.
7 years from the last patient encounter under ORC §3701.741. Pediatric records: until age of majority plus 7 years. The 7-year clock starts at the last clinical encounter, not the last billed visit; document the trigger date carefully for patients who have aged out of pediatric care or been lost to follow-up.
No — it does not apply to you at all. R.C. §1349.19(F)(2) provides that the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so the statute's 45-day figure never binds a HIPAA-covered medical practice and there is no state deadline to compare against HIPAA's 60 days. Run one timeline, the federal one, and document the discovery date that starts it.
Guides & Articles
Stay audit-ready in Ohio
GuardWell tracks Ohio-specific breach deadlines, retention periods, OARRS PDMP queries, and mandatory reporting obligations automatically.
