{"id":6785,"date":"2025-01-02T15:30:43","date_gmt":"2025-01-02T21:30:43","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/proposed-hipaa-amendments-close-healthcare-security-gaps"},"modified":"2025-01-02T15:30:43","modified_gmt":"2025-01-02T21:30:43","slug":"proposed-hipaa-amendments-will-close-healthcare-security-gaps","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/02\/proposed-hipaa-amendments-will-close-healthcare-security-gaps\/","title":{"rendered":"Proposed HIPAA Amendments Will Close Healthcare Security Gaps"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt5868cc71f87c2128\/666c477fc76eb183ea0f6c71\/Privacy%281800%29_Zoonar_GmbH_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The U.S. Department of Health and Human Services is planning a massive overhaul of the Health Insurance Portability and Accountability Act security rule to strengthen baseline cybersecurity requirements for protecting electronic protected health information (PHI). The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/public-inspection.federalregister.gov\/2024-30983.pdf\">proposed amendments<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which will be published in the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Federal Register<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on Jan. 6, would require healthcare organizations and other covered entities to implement security controls such as multi-factor authentication and enhanced encryption requirements.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The proposal describes the most substantive changes to HIPAA to date. The security rule was last revised in 2013. The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/healthcare-cyber-prognosis-security-booster\">threat landscape<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is different now than it was over a decade ago, and breaches against healthcare organizations have increased by 102% between 2018 and 2023, the HHS Office &nbsp;for Civil Rights said in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.hhs.gov\/about\/news\/2024\/12\/27\/hhs-office-civil-rights-proposes-measures-strengthen-cybersecurity-health-care-under-hipaa.html\">statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In 2023, over 167 million people had their health information compromised, a 1,002% increase from 2018.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Proposed Changes to HIPAA\">Proposed Changes to HIPAA<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The amendments will apply to health plans, healthcare clearinghouses, health providers, healthcare facilities, insurance companies, and business associates.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Everything in Writing:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> All policies, procedures, plans, and analyses will need to be in writing. This also applies to developing stronger incident response procedures, such as having written <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/incident-response-playbooks-prepared\">incident response plans<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and testing plans, as well as written procedures to be able to restore information systems and data within 72 hours.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Asset Inventory<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">: Healthcare organizations will need to develop and regular maintain an up-to-date technology asset inventory and network map to track the movement of protected health information (PHI) through the various systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Risk Analysis:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Healthcare organizations are not all that good at security risk analysis. The proposed changes include more specifics on how to conduct security risk analysis, such as written assessments that include a review of the technology asset inventory and network map, identify all potential threats to PHI, and assess the risk level for each threat and vulnerability.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Implement Security Controls:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> Healthcare organizations will be required to employ multifactor authentication and network segmentation to make it harder for healthcare systems to be compromised or data breaches. All PHI will need to be encrypted both during rest and in transit, reflecting the consensus that encryption is no longer optional. For systems that process PHI, security teams will need to scan for vulnerabilities every six months, run penetration tests at least once a year, deploy antimalware defenses, and remove extraneous software from systems. These requirements show how these are moving from recommended activities to minimum security baseline every entity must meet.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations will need to conduct a compliance audit at least once every 12 months to ensure these technical controls are in place, and prove the safeguards have been implemented at least once every 12 months via a written certification.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Anne Neuberger, deputy national security adviser for cyber and emerging technology, said during a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.whitehouse.gov\/briefing-room\/press-briefings\/2024\/12\/27\/on-the-record-press-gaggle-by-white-house-national-security-communications-advisor-john-kirby-38\/\">Dec. 27 press briefing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that the changes to the security rule will cost approximately $9 billion in the first year, and $6 billion for years two to five. \u201cThe cost of not acting is not only high, it also endangers critical infrastructure and patient safety, and it carries other harmful consequences,\u201d Neuberger said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stakeholders have 60 days after the nearly 400-page proposal is published to submit comments (early March 2025). HHS will issue the final version of the rule afterwards, although a specific date has not yet been set followed by a compliance date of 180 days. It is also not clear if the work on the changes to the security rule will continue under the new presidential administration. Even so, healthcare organizations should review proposed requirements and evaluate their existing security programs to prepare for potential changes.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/proposed-hipaa-amendments-close-healthcare-security-gaps\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The U.S. Department of Health and Human Services is planning<\/p>\n","protected":false},"author":12,"featured_media":6786,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=1813%2C1023&ssl=1",1813,1023,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=640%2C361&ssl=1",640,361,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=640%2C361&ssl=1",640,361,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=1536%2C867&ssl=1",1536,867,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=1813%2C1023&ssl=1",1813,1023,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=1024%2C578&ssl=1",1024,578,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/proposed-hipaa-amendments-will-close-healthcare-security-gaps.jpg?fit=1813%2C1023&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6785"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6786"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}