HIPAA Tip: HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information
On December 27, 2024, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule to strengthen cybersecurity protections for electronic protected health information (ePHI). OCR administers and enforces the Security Rule, which establishes national standards for the protection of individuals’ ePHI by Covered Entities (health plans, health care clearinghouses, and most health care providers), and their Business Associates (together, regulated entities). The proposed rule seeks to strengthen cybersecurity by updating the Security Rule’s standards to better address ever-increasing cybersecurity threats to the health care sector.
The proposed rulemaking is one of many actions taken by HHS in support of President Biden’s commitment to improving the cybersecurity of critical infrastructure. In 2023, the Biden-Harris Administration released the National Cybersecurity Strategy and its plan for implementing the strategy; version 2 was released in May of 2024. Also in 2023, HHS released its Healthcare Sector Cybersecurity concept paper outlining the Department’s path forward to advance cybersecurity enhancements for the health care sector. These plans included the publication of voluntary cybersecurity best practices and a strategy for greater cybersecurity enforcement and accountability, which included updating the HIPAA Security Rule with new cybersecurity requirements.
Now more than ever is the time for the healthcare industry to step up its game with cybersecurity training for all staff, multiple layers of security (2FA, MFA), and enhanced security monitoring including Endpoint Detection Response (EDR) solutions and Remote Monitoring and Management (RMM).
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP