HHS Issues Cybersecurity Rule
The U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), issued a proposed rule to improve cybersecurity and better protect the healthcare system from cyberattacks.
The proposed rule modifies the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. It requires health plans, healthcare clearinghouses, most healthcare providers, and most business associates, to strengthen cybersecurity protections against external and internal threats. It requires updates to existing cybersecurity safeguards, using modern best practices, to reflect advances in technology and cybersecurity. It provides greater detail on what covered entities and business associates need to do to protect the security of electronic protected health information (PHI). Policies and procedures would have to be in writing, reviewed, tested, and updated on a regular basis.
Specifically, HHS says the rule reacts to:
- Changes in the environment in which healthcare is provided.
- Significant increases in breaches and cyberattacks.
- Common deficiencies OCR has observed in investigations into Security Rule compliance by covered entities and their business associates.
- Other cybersecurity guidelines, best practices, methodologies, procedures, and processes.
- Court decisions that affect enforcement of the Security Rule.
The rule is in response to growing cybersecurity incidents, including the Change Healthcare attack earlier this year that made much of healthcare come to a standstill.
Th fact sheet is well written and explains many of the details of the rule. I am surprisingly impressed with the proposal and its details. I think it is a good start to protecting the nation from emerging cyberattacks. The problem, though is the readiness of health plans and providers, especially many who have limited expertise and knowledge. They do not have the dollars or know-how to implement protections. As such, I think we need a true national cyber plan with a strong budget and implementation strategy. The rule is a start but is not enough.
Rule at Federal Register: https://www.federalregister.gov/public-inspection/2024-30983/health-insurance-portability-and-accountability-act-security-rule-to-strengthen-the-cybersecurity-of .
Fact Sheet: https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet .
#cybersecurity #healthplans #providers #cms #hhs
