The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Headline
The federal government shut down Oct. 1 following a failed Senate vote on the House-passed continuing resolution to fund the government by midnight Sept. 30.…
Headline
The AHA Sept. 29 asked the Trump administration to provide exemptions for health care personnel from the proclamation issued Sept. 19 announcing changes to the…
Headline
The Office of Science and Technology Policy issued a request for information Sept. 26 seeking feedback on federal regulations that hinder AI development,…
Headline
The AHA Sept. 24 expressed support for the Medical Student Education Authorization Act (H.R. 5428), legislation introduced in the House Sept. 17 that would…
Headline
The AHA expressed support Sept. 22 to House and Senate sponsors of the Medicare Advantage Prompt Pay Act (H.R. 5454/S. 2879), legislation that would apply a…
Headline
The Senate Sept. 19 failed to adopt a continuing resolution by a 44-48 vote  that would have funded the government through Nov. 21. The CR was passed by…