Skip to main content
HHSARAgency supplement

Department of Health & Human Services

HHS's procurement supplement — important wherever contracts touch health data.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The HHS Acquisition Regulation (HHSAR) does not add a general CUI cybersecurity-safeguarding clause like DFARS or HSAR. Its security-relevant rules center on health and privacy data:

HHSAR Subpart 324.70 — Health Insurance Portability and Accountability Act (HIPAA). Where a contract involves protected health information, the contractor acts as a business associate and must meet HIPAA Privacy and Security Rule safeguards (including a Business Associate Agreement).

HHSAR clause 352.224-70 — Privacy Act. Applies Privacy Act obligations to contractors operating systems of records.

HHSAR clause 352.224-71 — Confidential Information. Restricts use and disclosure of confidential information obtained in performance.

In plain terms

HHS doesn't impose a single broad cyber-safeguarding clause; instead, its security duties flow through health-data law. If your work touches protected health information, HIPAA's Security Rule and a Business Associate Agreement govern how you protect it, and the Privacy Act and confidentiality clauses cover other personal data.

Who it applies to

Contractors and subcontractors that handle HHS health data, protected health information, or Privacy Act records.

What it requires

Follow the FAR baseline, then: meet HIPAA Privacy/Security Rule safeguards and sign a Business Associate Agreement where PHI is involved, and comply with Privacy Act and confidentiality obligations. General cybersecurity controls otherwise come from the FAR baseline.

Why it matters

HHS contracts frequently involve health data, where HIPAA — not a procurement cyber clause — sets the binding security standard, with its own penalties.

Citation

HHS Acquisition Regulation (HHSAR), codified at 48 C.F.R. Chapter 3.