The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Headline
The House is expected to begin a final vote Nov. 12 on the Senate-backed funding package, bringing a potential end to the government shutdown one step closer.…
Headline
The Senate Nov. 10 passed legislation to fund the federal government that will now head to the House for a vote as early as the evening of Nov. 12, as an end…
Headline
The Senate Nov. 9 took a critical first step toward ending the government shutdown as seven Democrats and Sen. Angus King, I-Maine, joined Republicans to…
Headline
Senate negotiations on a potential funding deal to end the record-long government shutdown are ongoing, and the chamber is likely to continue working through…
Headline
The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners released joint guidance Oct. 30 on best practices for…
Headline
The AHA expressed support Nov. 3 for the bipartisan Home Health Stabilization Act (H.R. 5142), legislation that would establish a two-year pause on planned…