Skip to main content

Ohio Healthcare Compliance Requirements

State-specific breach notification rules, medical records retention periods, PDMP requirements, and mandatory reporting obligations for medical practices operating in Ohio.

60-day HIPAA deadline7-year retentionOARRS

Ohio's breach statute carries a hard day count — R.C. §1349.19 requires notification within 45 days of discovery — but it does not reach a medical practice: §1349.19(F)(2) provides that the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a HIPAA-covered practice is exempt from the Ohio statute entirely and HIPAA's 60-day outer limit is the clock that governs. Two corollaries matter operationally. Ohio requires no Attorney General breach notification at all — there is no state-AG track running alongside the federal one — and §1349.19's only third-party trigger is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected, which falls away with the rest of the section for a covered entity. Ohio's pharmacy practice is governed by the Ohio Board of Pharmacy, which operates OARRS (the Ohio Automated Rx Reporting System) as one of the most EHR-integrated PMPs in the country: OARRS queries are embedded in most major Ohio EHR platforms via the state's gateway, and the Board has built pattern-detection tooling that flags dispensing outliers for licensing review. Cleveland, Columbus, and Cincinnati-area health systems coordinate routinely with the Ohio Department of Health on communicable-disease reporting and with the Ohio Department of Job and Family Services on Children's Protective Services and Adult Protective Services mandatory reports. OARRS's deep integration, the Board of Pharmacy's pattern-detection posture, and Ohio's mandatory-reporting web make Ohio one of the more operationally rigorous Midwest jurisdictions — the breach clock is simply not where that rigor lives.

Breach Notification Rules

Notification deadline

60 calendar days (HIPAA)

Ohio law states 45 days, but that figure does not bind a HIPAA covered practice — see below.

Notification must be made no later than 45 days following discovery — Ohio Rev. Code §1349.19. Ohio requires NO Attorney General notification; the only third-party trigger is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected. Decisively for this audience: §1349.19(F)(2) states the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a HIPAA-covered medical practice is exempt from the Ohio statute entirely and HIPAA's timeline governs.

AG notification threshold (as the statute reads)

Not explicitly required

Harm analysis required

Yes — breach presumed unless risk assessment shows low probability of compromise

Penalty range

Enforceable by AG under Consumer Sales Practices Act; court may award damages

Comparable to federal HIPAA
View statute

Enforcement Posture

The Ohio Attorney General's office is one of the more active state AGs on consumer-protection enforcement under the Consumer Sales Practices Act, which is the vehicle §1349.19 is enforced through — but §1349.19(F)(2) puts HIPAA covered entities outside the section, so a medical practice's breach exposure runs through HIPAA and OCR rather than a state clock. There is no Ohio AG breach filing to prepare and no state resident threshold to monitor, and the "without unreasonable delay" versus fixed-day-count question never reaches you. The Ohio Board of Pharmacy's posture on OARRS is independently rigorous: dispensing-pattern outliers flagged by OARRS are a routine trigger for licensing-board review and pain-management practice scrutiny in the wake of the opioid-crisis litigation. Document your HIPAA breach timeline, your harm analysis, and your OARRS query log carefully.

Medical Records Retention

Record typeRetention periodMeasured from
General medical7 yearsLast treatment
Pediatric7 yearsPatient turns 18

Controlled-Substance Prescription Monitoring (OARRS)

OARRS — the Ohio Automated Rx Reporting System — requires a query before issuing any controlled-substance prescription. OARRS is among the most deeply EHR-integrated PMPs in the country: most Ohio EHR platforms surface OARRS data directly in the prescribing workflow via the state's gateway. Delegation to licensed pharmacists, NP/PAs, and RN designees is permitted. Registration at ohiopmp.gov is mandatory for all DEA registrants prescribing in Ohio. Exemptions cover hospice, cancer treatment, ≤3-day ER supplies, inpatient and nursing-facility administration, and medication-assisted treatment.

Check required

Every prescription

Check frequency

Every prescription

Delegation allowed

Yes — licensed staff may query under prescriber oversight

Penalty range

Licensing board discipline; civil penalties up to $10,000; possible felony charges for pattern noncompliance

Exemptions

Hospice patients, cancer treatment, ≤3 day supply in ER, inpatient hospital or nursing facility, medication-assisted treatment

How Ohio Rules Hit by Specialty

Pain management

Ohio pain-management practices operate under one of the country's most aggressive post-opioid-crisis regulatory regimes. OARRS query patterns and prescribing volumes are reviewed actively by the Ohio Board of Pharmacy and the State Medical Board of Ohio; document your dose, duration, and morphine-milligram-equivalent (MME) reasoning in the chart at every visit.

Pharmacy/compounding

OARRS is embedded into most Ohio EHR platforms; the Board of Pharmacy uses OARRS data for proactive surveillance, not just complaint-driven review. Compounding pharmacies face additional state-board scrutiny on USP 795/797/800 compliance.

Hospital systems

Ohio adds no state layer to the incident-response runbook: §1349.19(F)(2) exempts covered entities and Ohio requires no AG breach notification at any resident count, so the runbook you pre-stage is the federal one — individual notice and the HHS filing on HIPAA's timeline. The §1349.19 consumer-reporting-agency notice above 1,000 affected residents only ever reaches a non-covered affiliate.

Behavioral health

Ohio behavioral health practices follow OARRS for controlled-substance prescribing (buprenorphine, benzodiazepines) and report to the Ohio Department of Mental Health and Addiction Services for substance-use treatment program licensure.

Mandatory Reporting Obligations

Mandated reporters

Physicians, dentists, nurses, psychologists, social workers, and all healthcare professionals acting in professional capacity

Report to

County children services agency or local law enforcement

Timeline

Immediately / as soon as possible

Penalty for failure

Fourth-degree misdemeanor; second-degree misdemeanor if previous conviction

Immunity provision

Good faith reporters immune from civil and criminal liability under ORC 2151.421

Mandated reporters

Physicians, nurses, social workers, and all healthcare professionals

Report to

County Department of Job and Family Services, Adult Protective Services

Timeline

Immediately / as soon as possible

Penalty for failure

Fourth-degree misdemeanor

Immunity provision

Good faith reporters immune from civil and criminal liability

Mandated reporters

Healthcare providers treating injuries from felonious assault or domestic violence

Report to

Local law enforcement

Timeline

Immediately / as soon as possible

Immunity provision

Good faith reporters immune from civil liability

Mandated reporters

Physicians, laboratories, and healthcare facility administrators

Report to

Ohio Department of Health or local board of health

Timeline

Within 24 hours

Penalty for failure

Minor misdemeanor, up to $150 fine

Immunity provision

Good faith reporters immune from civil liability

Mandated reporters

All physicians and healthcare providers treating gunshot wounds, stab wounds, or burn injuries from criminal violence

Report to

Local law enforcement

Timeline

Immediately / as soon as possible

Penalty for failure

Minor misdemeanor

Immunity provision

Good faith reporters immune from civil and criminal liability

Ohio Compliance FAQs

For a HIPAA-covered practice, none — the statute's 45-day figure never starts running against you. §1349.19(F)(2) states the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so a covered medical practice is exempt from the Ohio statute entirely and HIPAA's 60-day outer limit is the deadline you work to. Ohio also requires no Attorney General notification at all.

Never. Ohio's statute contains no Attorney General notification requirement at any resident count, which makes it unusual among state breach laws. The only third-party trigger in §1349.19 is notice to the nationwide consumer reporting agencies when more than 1,000 Ohio residents are affected — and §1349.19(F)(2) exempts covered entities from the section entirely, so that trigger does not reach a medical practice either. Your notifications run to affected individuals and to HHS under the federal Breach Notification Rule.

Yes. Ohio requires an OARRS query before every controlled-substance prescription. Exemptions cover hospice, cancer treatment, ≤3-day ER supplies, inpatient or nursing-facility administration, and medication-assisted treatment. OARRS is deeply EHR-integrated, so most queries occur in the prescribing workflow without leaving the chart.

7 years from the last patient encounter under ORC §3701.741. Pediatric records: until age of majority plus 7 years. The 7-year clock starts at the last clinical encounter, not the last billed visit; document the trigger date carefully for patients who have aged out of pediatric care or been lost to follow-up.

No — it does not apply to you at all. R.C. §1349.19(F)(2) provides that the section does not apply to a covered entity as defined in 45 C.F.R. 160.103, so the statute's 45-day figure never binds a HIPAA-covered medical practice and there is no state deadline to compare against HIPAA's 60 days. Run one timeline, the federal one, and document the discovery date that starts it.

Stay audit-ready in Ohio

GuardWell tracks Ohio-specific breach deadlines, retention periods, OARRS PDMP queries, and mandatory reporting obligations automatically.

GuardWell

Healthcare Compliance Assistant

Hi! I'm GuardWell's AI sales assistant (automated, not a human).

I can answer questions about our healthcare compliance platform, pricing, and features. How can I help?

Powered by GuardWell AI