The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Headline
The Senate is expected to vote this week on its own continuing resolution to fund the federal government through Dec. 11. The chamber, scheduled to leave for…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies July 29 released joint guidance outlining minimum elements for a…
Headline
John Riggi, AHA national advisor for cybersecurity and risk, shares insights from a conversation with two FBI leaders about the surge of cyberattacks on the U.…
Headline
The AHA July 27 expressed support for the National Nursing Workforce Center Act of 2025 (S. 1482), legislation that would establish state-based nursing…
AHA Cyber Intel
Earlier this year, the FBI launched a two-month national campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense),…
Headline
The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber…