Cyber security in healthcare

1 minute read

Published:

Cyber security in healthcare

Cyber security in healthcare

On January 6, 2025, the U.S. Department of Health and Human Services (HHS) issued a notice of proposed rule making (NPRM), stating significant updates to the HIPAA Security Rule. To strengthen protections for electronically protected health information (ePHI), this revision focuses on improving cyber security practices for better protecting the U.S. health care system, as there has been an increase in cases involving cyber-attacks.
The proposed rule addresses common non-compliance areas with the Security Rule, identified by thorough investigations from the Office of Civil Rights (OCR's). The rule also incorporates recommendations from the National Committee on Vital Health Statistics (NCVHS), and aligns with guidelines from agencies like Cyber Security and Infrastructure Security Agency (CISA) and National Institute of Standards and Technology (NIST). This joint effort aims to strengthen the security of health information across the healthcare sector in the United States of America.
The proposed updates are also open to comments until March 7, 2025, using the RIN Number 0945-AA22. The comments should be submitted either through the Federal eRulemaking Portal or by Mail