HHS proposes HIPAA updates: 6 notes

HHS plans to modify HIPAA to better safeguard the healthcare industry from hackers.

Advertisement

The agency issued a proposed rule Dec. 27 with plans to publish more details and open it up to public comments Jan. 6.

In 2023, over 167 million individuals were affected by large healthcare data breaches, a number that is expected to increase in 2024 after the February ransomware attack on claims processor Change Healthcare, the largest healthcare hack in history.

Here are six things the proposed changes to HIPAA would require of healthcare providers:

1. Encrypt electronic protected health information “with limited exceptions.”

2. Implement multifactor authentication “with limited exceptions.”

3. Deploy antimalware software.

4. Establish written procedures to restore EHR systems and data within 72 hours of a cyberattack.

5. Notify certain regulators within 24 hours when an employee’s electronic access to EHR data or systems is changed or terminated.

6. Develop and revise an inventory and network map that illustrates the movement of EHR data through the organization’s systems at least once every 12 months.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

  • Hospitals are increasingly paying for artificial intelligence by the token, turning a once-obscure technical term into a line item finance…

  • Hospital leaders often measure cybersecurity readiness by asking whether their own environment is protected. Are systems patched? Is multifactor authentication…

Advertisement

Comments are closed.