Author’s Note: This article discusses proposed changes to existing regulations. These changes are not in effect as of the date of this article and may themselves change significantly before inclusion in an interim or final rule. Monitor the corresponding official Web sites below for the latest information on publication specifics.
On December 27, 2024, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule (45 CFR Parts 160 and 164). HHS has issued a good Fact Sheet summarization of the proposed changes (referred to as the Proposed Rule herein), but you are going to want to read the entire NPRM carefully. HHS has shared in depth their thinking on the current state of healthcare security, patterns they have observed in healthcare cybersecurity incidents, and why they are proposing the changes described. HHS is accepting comments through March 7, 2025 on the Proposed Rule.
The Proposed Rule represents a long-needed update to the Security Rule to align it to modern cyber security threats and remove loopholes. As all compliance standards should, it represents a reasonable minimum baseline, or starting point, for cyber security. Compliance does not equal security, but is rather a subset of security, a starting point, and a tool to move organizations toward a secure state commensurate with the risk appetite of its stakeholders – including the regulatory or contractual bodies issuing the standards.
Most of the proposed changes align the Security Rule with other common cyber security frameworks, which ensures effectiveness and should make it a little easier for organizations to fully comply. Indeed, NIST sources are frequently cited throughout the Proposed Rule. Key proposed changes are as follows.
It is very likely that you already have many of these controls in place for other compliance or risk reasons. All of these controls can materially contribute to mitigating unacceptable risk. Keep an eye on the rulemaking process as it unfolds and participate in the comment period if you can. GuidePoint Security can provide expert guidance with your HIPAA compliance efforts. GuidePoint offers HIPAA gap assessment, OCR-compliant risk assessment, and advisory services, delivered by consultants with operations backgrounds who understand how to apply the HIPAA requirements to your environment.
Dan Mengel
Practice Director, Compliance,
GuidePoint Security
Dan Mengel, Practice Director at GuidePoint Security, began his career in the security industry in 2000. He has delivered high-quality consulting services, directly and by leading others, in the areas of information security program architecture, security policy development, and security vulnerability, risk, and compliance assessments. He has developed sales and delivery processes and documentation templates for all of these engagement types. Dan is currently leading GuidePoint’s Compliance team in delivering assessment and advisory services for multiple information security standards. He also has significant prior experience designing and integrating security technology solutions from Cisco, Check Point, Websense, RSA, and others.
Dan earned a Bachelor of Science degree in Computer Information Systems from Goldey-Beacom College and holds several recognized information security industry certifications.