According to an anonymous official, CMS will require hospitals to implement basic digital security defenses in order to receive federal funding. These requirements include using multifactor authentication and having a program dedicated to fixing software vulnerabilities.
These requirements will take effect before the end of the year, according to the official.
This comes after the HHS released a concept paper Dec. 6 detailing a new cybersecurity strategy aimed at enhancing the security of the healthcare sector.
The four actions the HHS outlined in the paper were publishing voluntary healthcare and public health sector cybersecurity performance goals; providing resources to incentivize and implement cybersecurity practices; implementing an HHS-wide strategy to support greater enforcement and accountability; and expanding and maturing the one-stop shop within HHS for healthcare sector cybersecurity.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.