Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Recognized Security Practices

Understanding HIPAA Recognized Security Practices

Recognized Security Practices (RSPs) are defined as “the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15, the approaches promulgated under section 1533(d) of title 6, and other programs and processes that address cybersecurity that are developed or recognized through regulations under other statutory authorities. Such practices shall be determined by the Covered Entity or Business Associate, consistent with the HIPAA Security rule ( part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title).”

TL;DR – HIPAA Recognized Security Practices:

  • RSPs: Standards, guidelines, and best practices from NIST, HHS 405(d), and others
  • OCR considers RSPs when evaluating HIPAA Security Rule violations
  • Implementing RSPs can mitigate penalties after a breach
  • OCR reviews RSP usage in the year preceding a violation
  • RSPs introduced in 2021, now critical due to increased cyber attacks
  • Can reduce liability if you demonstrate RSP implementation during a breach

How RSPs Can Reduce HIPAA Penalties

HHS OCR considers RSPs when evaluating potential HIPAA Security Rule violations, and implementing them can mitigate penalties. RSPs include standards, guidelines, and best practices from sources like NIST, HHS 405(d), and other programs that address cybersecurity; OCR will consider whether an entity used RSPs in the year preceding a violation. The RSPs are not new – they were presented in 2021. The importance of revisiting these now is due to the increase in cyber attacks. Should your organization go through a breach with OCR, you may be able to reduce your liability on violations if you are able to show that you had put in place some or all of the RSPs.

OCR’s Guidance on Recognized Security Practices

HHS OCR’s Senior Advisor on Cybersecurity Nicholas Heesters explains in a video created by OCR how the RSPs can assist Covered Entities and Business Associates:

OCR Recognized Security Practices Video Presentation

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.