HSCC Proposes Year-long Consultation Process Rather Than HIPAA Security Rule NPRM

The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) has issued a policy statement regarding the HIPAA Security Rule Notice of Proposed Rulemaking (NPRM) published by the HHS’ Office for Civil Rights (OCR) in the Federal Register in January 2025. The NPRM was published by OCR a few days before the administration change and proposed a swathe of new cybersecurity requirements for HIPAA-regulated entities. The comment period has now closed, and OCR has confirmed it is reading and categorizing the 4,745 comments submitted in response to the NPRM, which will inform future actions.

While there is broad agreement that healthcare cybersecurity needs to improve, the NPRM has attracted considerable criticism due to the extent of the proposed changes and the budgetary and implementation challenges associated with compliance. In February 2025, eight industry groups, including the College of Healthcare Information Management Executives and the American Healthcare Association, wrote to President Trump and HHS Secretary Robert F. Kennedy Jr,. urging them to rescind the proposed HIPAA Security Rule update – HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information.

They argued that the depth and breadth of the proposed changes and an unreasonable timeline for compliance would present significant challenges and would place an undue financial strain on hospitals and healthcare systems, which would ultimately result in higher healthcare costs for patients, reduced investment in other critical areas, and could stifle innovation in healthcare. They questioned the Biden administration’s estimated cost of compliance – $9 billion in the first year, and $6 billion in years two through five – suggesting that cost is woefully inadequate and in all likelihood would be substantially higher.

The HSCC CWG has now weighed in and has issued a policy statement, recommending the Trump administration suspend any further consideration of the NPRM. Instead HSCC CWG requests “a structured series of consultations and workshops to forge consensus on a modernized policy for healthcare cybersecurity resiliency, responsibility, and accountability.”

HSCC Executive Director, Greg Garcia explained that the current NPRM is “not practicable or effective,” and that is a view held by a significant number of the 52 CWG member industry associations that have submitted feedback to the HHS. Garcia also claims that in addition to the high cost and complexity of implementing the proposed changes, their effectiveness at improving security is dubious.

Rather than requiring extensive updates to healthcare cybersecurity to be implemented together as proposed in the NPRM, there should be a year-long consultation process with HIPAA-regulated entities. The goal should be to determine which cybersecurity controls should be mandatory and then develop a workable plan to implement those cybersecurity controls using a phased approach, carefully considering that many healthcare organizations have budget and resource restrictions.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

HSCC suggests the government should design a healthcare-specific regulatory framework that maps to the NIST Cybersecurity Framework. “We propose that the HSCC Cybersecurity Working Group and other leaders in the industry convene with government to design a healthcare-specific policy, programmatic and regulatory framework that maps to CSF for all interconnected owners/operators and their supporting infrastructure in the healthcare ecosystem,” explained Garcia in the policy statement.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/