HIPAA Tip: NIST Special Publication 800-39
Essential Risk Management Framework for Healthcare Organizations
Welcome to this week’s HIPAA Tip Tuesday! While healthcare organizations aren’t required to follow NIST standards, they offer some of the best tools to counteract cyber threats and data breaches. In this guide, Dawn Meglino highlights NIST Special Publication 800-39 and why its approach to ongoing risk management remains essential for healthcare security.
- NIST provides cybersecurity guidance (not mandatory for healthcare, but highly recommended)
- SP 800-39 offers integrated, organization-wide risk management framework
- Published in 2011 but remains applicable and relevant today
- Emphasizes ongoing risk assessment, not annual one-time reviews
- Monitor information systems continuously, including user activity and privileges
What is NIST and Why It Matters for Healthcare
National Institute of Standards and Technology or NIST, a non-regulatory agency within the U.S. Department of Commerce, provides guidance, standards, and technology to the U.S. government, particularly in the areas of cybersecurity and risk management, which is mandated for federal agencies and contractors through legislation.
Healthcare organizations are not required to follow NIST standards; however, NIST offers some of the best tools to counteract cyber threats, ransomware attacks and data breaches.
NIST Special Publication 800-39
This Special Publication was from a while ago but is no less applicable today than when it was published in 2011. The purpose of SP 800-39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, reputation), organizational assets and individuals. It provides a flexible approach for managing information security risk that is intentionally broad based with specific details of assessing, responding to and monitoring risks on an ongoing basis.
The Critical Takeaway: Ongoing Risk Management
Keywords: risk management, information systems, and on an ongoing basis. Do not conduct a Risk Analysis and file the report away until its time to update the following year: continue review of risks and how they are being addressed, monitor all information systems to include user activity, auditing and privileges. Ensure changes and updates to systems and applications are documented with up-to-date information.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.