Base
Proposed RuleSignificant2024-309832025-01-06

HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information

Health and Human Services Department,

Abstract

The Department of Health and Human Services (HHS or "Department") is issuing this notice of proposed rulemaking (NPRM) to solicit comment on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information ("Security Rule") under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The proposed modifications would revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The proposals in this NPRM would increase the cybersecurity for ePHI by revising the Security Rule to address: changes in the environment in which health care is provided; significant increases in breaches and cyberattacks; common deficiencies the Office for Civil Rights has observed in investigations into Security Rule compliance by covered entities and their business associates (collectively, "regulated entities"); other cybersecurity guidelines, best practices, methodologies, procedures, and processes; and court decisions that affect enforcement of the Security Rule.

Action & Dates

Action
Notice of proposed rulemaking; notice of Tribal consultation.
Dates
Comments: Submit comments on or before March 7, 2025.

CFR References

Topics

Administrative practice and procedureComputer technologyDrug abuseEmployee benefit plansHealthHealth careHealth facilitiesHealth insuranceHealth professionsHealth recordsHospitalsInvestigationsMedicaidMedical researchMedicarePenaltiesPrivacyPublic healthReporting and recordkeeping requirements

Public Comment

Comments Close
2025-03-07

Document Excerpt

Document Headings Document headings vary by document type but may contain the following: the agency or agencies that issued and signed a document the number of the CFR title and the number of each part the document amends, proposes to amend, or is directly related to the agency docket number / agency internal file number the RIN which identifies each regulatory action listed in the Unified Agenda of Federal Regulatory and Deregulatory Actions See the Document Drafting Handbook for more details. Department of Health and Human Services Office of the Secretary 45 CFR Parts 160 and 164 RIN 0945-AA22 ( printed page 898) AGENCY: Office for Civil Rights (OCR), Office of the Secretary, Department of Health and Human Services. ACTION: Notice of proposed rulemaking; notice of Tribal consultation. SUMMARY: The Department of Health and Human Services (HHS or “Department”) is issuing this notice of proposed rulemaking (NPRM) to solicit comment on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information (“Security Rule”) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The proposed modifications would revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The proposals in this NPRM would increase the cybersecurity for ePHI by revising the Security Rule to address: changes in the environment in which health care is provided; significant increases in breaches and cyberattacks; common deficiencies the Office for Civil Rights has observed in investigations into Security Rule compliance by covered entities and their business associates (collectively, “regulated entities”); other cybersecurity guidelines, best practices, methodologies, procedures, and processes; and court decisions that af

Read full document on FederalRegister.gov →

Full Document

Citation: 90 FR 898

HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information — Federal Register 2024-30983 | Open Gov by Base