A rule in the Affordable Care Act (ACA) requiring reporting within one hour of all breaches of protected health information (PHI) during Health Insurance Marketplace activities has been dropped in the final regulations, to be published today in the Federal Register.

"Because the one-hour incident response timeline has been included in all the data sharing agreements required under the Affordable Care Act, we have deleted the timing for incident reporting from regulation … and expect it to be addressed through separate agreement," the 3000-page document states.

The Centers of Medicare and Medicaid Services (CMS) will now commit only to a "strict" enforcement of the ACA breach notification standard.

The marketplaces are to open Oct. 1 and begin taking insurance applications that day.