Lexology December 15, 2023
Concept paper includes future plans to update the HIPAA Security Rule and establish voluntary cybersecurity performance goals
The U.S. Department of Health and Human Services (“HHS”) issued a concept paper describing its overarching strategy to address healthcare cybersecurity. The concept paper builds on the Biden-Harris Administration’s National Cybersecurity Strategy, which was released in March 2023.
HHS’s healthcare cybersecurity strategy consists of four “pillars for action” aimed at strengthening resilience for hospitals, patients, and communities threatened by cyberattacks. The action items contained within each of the four pillars include the following:
- Establish Voluntary Cybersecurity Performance Goals (CPGs) for the Healthcare Sector. HHS, in collaboration with industry participants, intends to establish CPGs to aid healthcare institutions in planning and prioritizing implementation...