The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Perspective
As we’ve seen from recent media reports, Congress — and especially the House right now — continues to struggle to put together a plan to keep the government…
Headline
The Health Information Sharing and Analysis Center (H-ISAC) Sept. 19 alerted the health sector to an emerging threat that targets senior executives through…
Headline
AHA Sept. 20 urged leaders of the Senate Health, Education, Labor and Pensions Committee to remove from the Bipartisan Primary Care and Health Workforce…
Headline
The Department of Health and Human Services Sept. 18 alerted the health care sector to a critical vulnerability in ManageEngine products that allows an…
Headline
Certain policy decisions and challenges in implementing the No Surprises Act have undermined the unbiased and timely process Congress intended and contributed…
Headline
The AHA and American Medical Association Sept. 18 urged the U.S. Court of Appeals for the 5th Circuit to affirm a district court decision that invalidated a No…