HHS proposes updated HIPAA security rule
HHS unveils proposed updates to the HIPAA security rule, introducing modern safeguards to combat rising cyber threats in healthcare.
2 min read
Farah Amod
January 2, 2025
On December 27, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) proposed updates to the HIPAA Security Rule to improve cybersecurity protections in the U.S. healthcare system. It marked the first revision of the Security Rule since 2013. The updates aim to address the increasing frequency and sophistication of cyberattacks which have jeopardized patient safety.
The recent notice of proposed rulemaking (NPRM) by the Department of Health and Human Services (HHS) seeks to modify the HIPAA Security Rule to improve the cybersecurity of electronic protected health information (ePHI). The initiative arises from the increasing frequency and severity of cyberattacks on healthcare systems.
The proposed changes aim to address the growing number of breaches impacting large populations and the deficiencies observed in compliance investigations conducted by the Office for Civil Rights (OCR). The updates would introduce more in depth requirements for risk management, including regular vulnerability assessments and adherence to best practices in cybersecurity.
One of the most impactful aspects of the NPRM is the removal of the “addressable” specification category which means all security measures will now be mandatory. Organizations are compelled to adopt comprehensive cybersecurity practices without exception. The shift places a greater responsibility on healthcare providers to implement security measures like mandatory encryption which may require an increased investment in technology and training.
The NPRM also discusses the need for thorough risk assessments, including maintaining a detailed inventory of technology assets and mapping how ePHI flows in their systems. For smaller healthcare providers, particularly those in rural areas with limited resources, these changes could present challenges. The HHS has indicated that it will provide tailored guidance to help these entities comply effectively.
Related: HIPAA Compliant Email: The Definitive Guide
Healthcare organizations approach addressable requirements by evaluating each specification's relevance to their specific circumstances.
After the publication, there is a period for public comment after which the NPRM is available submitted for comments. Once these steps have been completed, the final rule is issued and implemented.
HHS unveils proposed updates to the HIPAA security rule, introducing modern safeguards to combat rising cyber threats in healthcare.
On December 27, 2024, the U.S. Department of Health and Human Services (HHS) released a Notice of Proposed Rulemaking (NPRM) introducing potential...
Regulators are enforcing patient access and security expectations more aggressively, even as long-awaited rule updates remain unresolved.
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.