
December 27, 2024
HHS Issues Cybersecurity Rule The U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), issued a proposed rule to improve cybersecurity and better protect the healthcare system from cyberattacks. The proposed rule modifies the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. It requires health plans, healthcare clearinghouses, most healthcare providers, and most business associates, to strengthen cybersecurity protections against external and internal threats. It requires updates to existing cybersecurity safeguards, using modern best practices, to reflect advances in technology and cybersecurity. It provides greater detail on what covered entities and business associates need to do to protect the security of electronic protected health information (PHI). Policies and procedures would have to be in writing, reviewed, tested, and updated on a regular basis. Specifically, HHS says the rule reacts to: The rule is in response to growing cybersecurity incidents, including the
