HIPAA Tip: Recognized Security Practices
Understanding HIPAA Recognized Security Practices
Recognized Security Practices (RSPs) are defined as “the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15, the approaches promulgated under section 1533(d) of title 6, and other programs and processes that address cybersecurity that are developed or recognized through regulations under other statutory authorities. Such practices shall be determined by the Covered Entity or Business Associate, consistent with the HIPAA Security rule ( part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title).”
- RSPs: Standards, guidelines, and best practices from NIST, HHS 405(d), and others
- OCR considers RSPs when evaluating HIPAA Security Rule violations
- Implementing RSPs can mitigate penalties after a breach
- OCR reviews RSP usage in the year preceding a violation
- RSPs introduced in 2021, now critical due to increased cyber attacks
- Can reduce liability if you demonstrate RSP implementation during a breach
How RSPs Can Reduce HIPAA Penalties
HHS OCR considers RSPs when evaluating potential HIPAA Security Rule violations, and implementing them can mitigate penalties. RSPs include standards, guidelines, and best practices from sources like NIST, HHS 405(d), and other programs that address cybersecurity; OCR will consider whether an entity used RSPs in the year preceding a violation. The RSPs are not new – they were presented in 2021. The importance of revisiting these now is due to the increase in cyber attacks. Should your organization go through a breach with OCR, you may be able to reduce your liability on violations if you are able to show that you had put in place some or all of the RSPs.
OCR’s Guidance on Recognized Security Practices
HHS OCR’s Senior Advisor on Cybersecurity Nicholas Heesters explains in a video created by OCR how the RSPs can assist Covered Entities and Business Associates:
OCR Recognized Security Practices Video Presentation
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.