Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: NIST Special Publication 800-39

Essential Risk Management Framework for Healthcare Organizations

Welcome to this week’s HIPAA Tip Tuesday! While healthcare organizations aren’t required to follow NIST standards, they offer some of the best tools to counteract cyber threats and data breaches. In this guide, Dawn Meglino highlights NIST Special Publication 800-39 and why its approach to ongoing risk management remains essential for healthcare security.

TL;DR – NIST SP 800-39 Key Points:

  • NIST provides cybersecurity guidance (not mandatory for healthcare, but highly recommended)
  • SP 800-39 offers integrated, organization-wide risk management framework
  • Published in 2011 but remains applicable and relevant today
  • Emphasizes ongoing risk assessment, not annual one-time reviews
  • Monitor information systems continuously, including user activity and privileges

What is NIST and Why It Matters for Healthcare

National Institute of Standards and Technology or NIST, a non-regulatory agency within the U.S. Department of Commerce, provides guidance, standards, and technology to the U.S. government, particularly in the areas of cybersecurity and risk management, which is mandated for federal agencies and contractors through legislation.

Healthcare organizations are not required to follow NIST standards; however, NIST offers some of the best tools to counteract cyber threats, ransomware attacks and data breaches.

NIST Special Publication 800-39

NIST Special Publication (SP) 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

This Special Publication was from a while ago but is no less applicable today than when it was published in 2011. The purpose of SP 800-39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, reputation), organizational assets and individuals. It provides a flexible approach for managing information security risk that is intentionally broad based with specific details of assessing, responding to and monitoring risks on an ongoing basis.

The Critical Takeaway: Ongoing Risk Management

Keywords: risk management, information systems, and on an ongoing basis. Do not conduct a Risk Analysis and file the report away until its time to update the following year: continue review of risks and how they are being addressed, monitor all information systems to include user activity, auditing and privileges. Ensure changes and updates to systems and applications are documented with up-to-date information.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.