The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…
Headline
Boston Scientific, a large supplier of medical devices, said in an Aug. 26 statement posted on its website that on Aug. 25 it “identified a cybersecurity…
Headline
The AHA Aug. 25 submitted comments to Sen. Bill Cassidy, R-La., on the 340B Drug Pricing Integrity and Affordability for Patients Act (340B for Patients Act),…
Headline
Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart…
Headline
The Department of Homeland Security today released a proposed rule to establish a new $103,265 filing fee for H-1B visa petitions that are subject to statutory…
Headline
The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable…