First Potential Update To HIPAA Rules Since 2013 Focuses On Strengthening Health System Cybersecurity
On January 6, 2025, the federal Department of Health and Human Services (HHS) Office for Civil Rights (OCR) released a proposal to strengthen security requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The provisions address the increasing risk of cyberattacks targeting the U.S. health care system. As proposed, the rule would modify the HIPAA Security Rule to require health plans, health care clearinghouses that facilitate data exchange between provider organizations and payers, and most health care provider organizations and their business associates to strengthen cybersecurity protections for individuals’ protected health information against both . . .