The Department of Health and Human Services’ Office for Civil Rights yesterday released a video on recognized security practices under the HIPAA security rule and how covered entities may demonstrate implementation.

“An amendment to the HITECH Act passed in January 2021, through the efforts of AHA and other prominent health care organizations, provided regulatory relief for a HIPAA covered entity that becomes victim of a cyberattack and can demonstrate that it had recognized security practices such as the Health Industry Cybersecurity Practices in place for the previous 12 months, said John Riggi, AHA’s national advisor for cybersecurity and risk. “This important video outlines what type of evidence and documentation must be presented to OCR to qualify for the regulatory relief. The evidence must demonstrate that the recognized cybersecurity practices have been implemented and are functioning on an organizational wide basis. In the face of continued high-impact cyberattacks and increased government scrutiny of health care cybersecurity practices, this statute provides significant incentive for hospitals and health systems to voluntarily implement recognized cybersecurity practices.” 

Related News Articles

Headline
A non-malicious global technology outage that began in the early morning of July 19 is continuing to affect many industries and is having varying effects on…
Headline
John Riggi, AHA’s national advisor for cybersecurity and risk, participated July 18 as the opening keynote speaker in the Information Security Media Group’s…
Headline
A joint advisory issued the week of July 8 by the Cybersecurity and Infrastructure Security Agency, National Security Agency, FBI and several international…
Headline
The AHA July 2 submitted comments to the Cybersecurity and Infrastructure Security Agency on its proposed rule establishing reporting requirements for…
Headline
The Department of Health and Human Services Health Sector Cybersecurity Coordination Center June 27 issued an alert about a critical vulnerability in MOVEit, a…
Headline
A joint report released June 26 by the Cybersecurity and Infrastructure Security Agency, FBI, the Australian Cyber Security Centre and Canadian Centre for…