HIPAA Security Rule Update Due in December 2024

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has completed its long-awaited modification to the HIPAA Security Rule; however, the department remains tight-lipped about exactly what the update entails, other than further cybersecurity requirements for HIPAA-regulated entities.

The HHS explained in its December 2023 Healthcare Cybersecurity Strategy concept paper some of the steps the department is taking to improve cybersecurity in healthcare. The goals included establishing cybersecurity performance goals for the healthcare sector and updating the 20-year-old HIPAA Security Rule. The cybersecurity performance goals were announced in January 2024 and consist of two sets of voluntary goals that the HHS encourages all HIPAA-regulated entities to adopt.

When establishing those goals, the HHS said voluntary goals alone would be unlikely to drive the necessary behavioral change to improve cybersecurity across the healthcare sector, and that the HHS would be looking to introduce new cybersecurity requirements through further rulemaking, including an update to the HIPAA Security Rule.

The proposed rule has now been passed to the Office of Information and Regulatory Affairs at the Office of Management and Budget for review and OCR has indicated a Notice of Proposed Rulemaking should be issued at some point in December 2024.

The purpose of the modification of the HIPAA Security Rule is to “improve cybersecurity in the health care sector by strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.” OCR considers the update to the HIPAA Security Rule to be critical to healthcare cybersecurity.

The update is long overdue as cyberattacks have been increasing at an alarming rate and unprecedented numbers of healthcare records have been exposed or stolen. Over the past 3 years, more than 700 large healthcare data breaches have been reported to OCR each year and almost 167 million healthcare records were exposed or stolen last year – more than the combined number of breached records over the previous 3 years. The recently confirmed data breach at Change Healthcare, the largest healthcare data breach to date involving 100 million records, has taken the number of breached records in 2024 passed last year’s record-breaking total.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

In a recent video presentation, Nick Heesters, OCR’s Senior Advisor for Cybersecurity, said large healthcare data breaches increased by 102% between 2018 and 2023 and there has been a 950% increase in breached healthcare records. Between 2019 and 2023, hacking incidents increased by 89% and ransomware attacks increased by 102%. It is not only the number of breaches and compromised healthcare records that is worrying. Ransomware attacks are having an impact on patient care. They force hospitals to take critical systems offline, emergency departments are placed on divert, and appointments and surgeries are postponed. Patient care is often disrupted for several weeks.

At last week’s HHS-NIST HIPAA Summit, OCR Director Melanie Fontes Rainer gave a keynote speech where she explained that the update to the HIPAA Security Rule is one of OCR’s key priorities. The HIPAA Security was written to be flexible, scalable, and not overly prescriptive, but the threat landscape has evolved dramatically over the past two decades and updates are required to the Security Rule to better protect patient data. Fontes Rainer declined to comment on what modifications have been made but did confirm that the proposed rule includes substantive updates. HIPAA-regulated entities will have to wait a few more weeks to discover what new measures they will need to implement to ensure compliance.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/