The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, National Security Agency, FBI and international agencies Aug. 13…
Headline
The Department of Justice Aug. 11 announced a series of actions taken against the BlackSuit ransomware group, also known as “Royal,” including the disruption…
Headline
The AHA Aug. 11 urged the Centers for Medicare & Medicaid Services to prioritize payments to hospitals from the Rural Health Transformation Program. The…
Headline
The AHA and Federation of American Hospitals Aug. 8 filed an amicus brief in the U.S. District Court for the Eastern District of Texas in support of the U.S.…
Headline
President Trump Aug. 7 issued an executive order, “Improving Oversight of Federal Grantmaking,” requiring government agencies to review new and discretionary…
Headline
The Senate Appropriations Committee July 31 advanced the fiscal year 2026 appropriations bill for the Departments of Labor, Health and Human Services,…