The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision () enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Perspective
Public
Just 16 days from now, more than 1,000 hospital and health system leaders from across the country will arrive in Washington, D.C., for the 2025 AHA Annual…
Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.…
Headline
The Centers for Medicare & Medicaid Services today released a notice seeking public comment on the collection of information request regarding the State…
Chairperson's File
Public
This is an incredibly dynamic and transformative time for health care. One resource I have found incredibly helpful in speaking with many of you and engaging…
Perspective
Public
Congressional lawmakers are heading home for a two-week district work period after both the Senate and House passed a revised budget resolution for fiscal year…
Headline
The Trump administration yesterday released executive orders on reducing anti-competitive regulatory barriers and repealing certain regulations deemed unlawful…