The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Perspective
December’s holiday rush is in full swing on Capitol Hill as Congress returned to Washington this week facing a long list of to-dos and a short time to do them…
Headline
New guidance released yesterday by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI informs health care and other…
Headline
The Coalition to Strengthen America's Healthcare Dec. 4 launched a new national, seven-figure digital, cable and broadcast advertising campaign that highlights…
Headline
The AHA and 22 other organizations Nov. 22 urged Congress to pass an end-of-year health care package that includes action on alternative payment models and a…
Headline
A joint advisory released Nov. 20 by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency and international partners warns of…
Headline
New analysis conducted by Dobson | DaVanzo released Nov. 21 by the Coalition to Strengthen America's Healthcare found that integration can provide more…