Lexology December 31, 2024
The U.S. Department of Health and Human Services (HHS) has issued an unpublished Notice of Proposed Rulemaking (NPRM)1 that strengthens the Health Insurance Portability and Accountability Act (HIPAA) Security Rule and, if finalized, will have a significant impact on the healthcare sector.
HHS observed that healthcare breaches can lead to harms far greater than those of breaches in other business sectors. In the announcement regarding the rules,2 HHS Deputy Secretary Andrea Palm indicated that the changes are designed in part to strengthen cybersecurity and that “[t]hese attacks endanger patients by exposing vulnerabilities in our health care system, degrading patient trust, disrupting patient care, diverting patients, and delaying medical procedures.” HHS Office for Civil Rights (OCR) Director Melanie Fontes Rainer stated,...