The Department of Health and Human Services’ Office for Civil Rights yesterday  on recognized security practices under the HIPAA security rule and how covered entities may demonstrate implementation.

“A  to the HITECH Act passed in January 2021, through the  and other prominent health care organizations, provided regulatory relief for a HIPAA covered entity that becomes victim of a cyberattack and can demonstrate that it had recognized security practices such as the  in place for the previous 12 months, said John Riggi, AHA’s national advisor for cybersecurity and risk. “This important video outlines what type of evidence and documentation must be presented to OCR to qualify for the regulatory relief. The evidence must demonstrate that the recognized cybersecurity practices have been implemented and are functioning on an organizational wide basis. In the face of continued high-impact cyberattacks and increased government scrutiny of health care cybersecurity practices, this statute provides significant incentive for hospitals and health systems to voluntarily implement recognized cybersecurity practices.” 

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.…
Headline
The National Counterintelligence and Security Center, the FBI, and the Defense Counterintelligence and Security Center yesterday released guidance on…
AHA Cyber Intel
While the rate of cyberattacks on hospitals has risen dramatically, the severity of the impacts has also grown exponentially. Let’s look at the state of cyber…
Headline
The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The…
Headline
The Trump Administration March 28 announced that it renewed for one year the public emergency for ongoing malicious cyber-enabled activities against the U.S.…
Headline
The FBI March 26 advised that, after extensive investigation and intelligence review, they have not identified any specific credible threat targeted against…