The AHA today urged the Department of Health and Human Services’ Office for Civil Rights to quickly initiate rulemaking for a legislative provision (H.R. 7898) enacted by Congress this year to recognize certain recommended security practices when making determinations related to Health Insurance Portability and Accountability Act audits, fines and resolution agreements.

“The law appropriately recognizes that covered entities and business associates, like all entities including the Federal Government, can never fully eliminate the risk of cyberattacks,” AHA wrote. “When the inevitable attack occurs, entities should not be penalized, but rather treated as the victims of a crime. The law translates this concept by allowing certain measures of regulatory relief if the HIPAA-covered entity or business-associate victim had in place federally recognized security practices, such as those defined under the National Institute of Standards and Technology (NIST) Cybersecurity Framework and developed under Section 405(d) of the Cybersecurity Act of 2015.”
 

Related News Articles

Headline
The FBI's Internet Crime Complaint Center released an alert May 7 warning of cyber actors exploiting vulnerabilities in end-of-life routers. Routers dated 2010…
Headline
The FBI’s Internet Criminal Complaint Center May 15 released an alert warning of a malicious text and voice messaging campaign involving impersonators…
Headline
The House Budget Committee May 18 advanced the fiscal year 2025 budget reconciliation bill by a 17-16 vote along party lines, as four Republicans who…
Headline
The House Energy and Commerce Committee today advanced by a 30-24 vote along party lines its portion of the fiscal year 2025 reconciliation bill following a…
Headline
Department of Health and Human Services Secretary Robert F. Kennedy Jr. May 14 testified on President Trump’s discretionary budget proposal for fiscal year…
Headline
The House Ways and Means Committee today advanced its portion of the fiscal year 2025 reconciliation bill by a 26-19 vote along party lines, following an hours…