The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for cybersecurity incidents under the Cyber Incident Reporting for Critical Infrastructure Act. The AHA called the requirements redundant to those from other federal agencies and that they add an unnecessary burden to hospitals while maintaining care through a cybersecurity incident. AHA urged CISA and other agencies to guarantee data anonymity across all federal agencies, and said applicability of the reporting rules are confusing, calling for them to be simplified due to compliance and operational burdens to hospitals in addition to privacy risks. AHA also expressed concern about the proposed rule’s penalties, calling them “vague and potentially severe,” and recommended that CISA revise the rule to incentivize collaboration instead.

Related News Articles

Headline
The FBI, Cybersecurity and Infrastructure Security Agency and Australian Cyber Security Centre June 4 released an advisory on updated actions and tactics used…
Headline
The National Security Agency, Cybersecurity and Infrastructure Security Agency and international partners May 22 released guidance on securing data used for…
Headline
The FBI, along with the National Security Agency and other international cybersecurity agencies, this week released a joint agency advisory on cyber operations…
Headline
The FBI's Internet Crime Complaint Center released an alert May 7 warning of cyber actors exploiting vulnerabilities in end-of-life routers. Routers dated 2010…
Headline
The FBI’s Internet Criminal Complaint Center May 15 released an alert warning of a malicious text and voice messaging campaign involving impersonators…
Headline
In his latest AHA Cyber Intel blog, John Riggi, AHA national advisor for cybersecurity and risk, examines the state of cyber and physical threats in 2025 as…