Showing posts with label HHS. Show all posts
Showing posts with label HHS. Show all posts

Friday, January 10, 2025

Review - HHS Publishes HIPAA Cybersecurity NPRM – Medical Devices

On Monday the Department of Health and Human Services (HHS) published a notice of proposed rulemaking (NPRM) in the Federal Register (90 FR 898-1022) on “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information”. HHS is proposing to modify the Security Standards for the Protection of Electronic Protected Health Information (“Security Rule”) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act).

With its emphasis on Protected Health Information (PHI) the main focus of this proposed rule is on information technology, and generally falls outside the scope of this blog. Having said that, there are 52 mentions of the term ‘medical device’ in this NPRM, starting with the realization that:

“Almost every stage of modern health care relies on stable and secure computer and network technologies, including, but not limited to, the following: appointment scheduling, prescription orders, telehealth visits, medical devices, patient records, medical and pharmacy claims submissions and billing, insurance coverage verifications, payroll, facilities access and management, internal and external communications, and clinician resources. These tools and technologies are an integral part of the modern health care system, but they also present opportunities for bad actors to cause harm through hacking, ransomware, and other means.”

NOTE: A large number of those reference to ‘medical device’ are found in the footnotes, providing links to informational documents relating to medical device cybersecurity issues.

This means that personnel interested in the cybersecurity of medical devices, facility access controls, and building maintenance controls are going to have to pay attention to these proposed HIPPA cybersecurity rules.

Soliciting Comments

HHS is soliciting comments on this NPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket #HHS-OCR-0945-AA22). Comments should be submitted by March 7th, 2025.

 

For more information on the medical device involvement in this proposed rule, including comments on additional areas that should be further clarified, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hhs-publishes-hipaa-cybersecurity - subscription required.

Thursday, December 19, 2024

OMB Approves HIPPA Security NPRM

Yesterday OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice of proposed rulemaking from HHS’s Office for Civil Rights (OCR) on “Proposed Modifications to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information”. This NPRM was sent to OIRA on October 18th, 2024.

According to the Fall 2024 Unified Agenda entry for this rulemaking:

“This rule will propose modifications to the Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will improve cybersecurity in the health care sector by strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.”

The Fall 2024 Unified Agenda has included expanded supporting information on rulemakings, including entries for ‘Statement of Need’, “Summary of the Legal Basis”, and ‘Alternatives’. The ‘Statement of Need’ comment for this rulemaking is of potential interest:

“In February 2003, the HIPAA Security Rule established standards for the security of electronic protected health information (ePHI) to be implemented by HIPAA covered entities and, by amendment of the HITECH Act, their business associates (collectively, "regulated entities"). Prior to the HIPAA Security Rule, standard security measures did not exist in the health care industry to address the security of ePHI while stored and exchanged between entities. Since 2003, the Department has received recommendations from the National Committee on Vital and Health Statistics (NCVHS), an advisory committee to the Secretary of HHS, and the public to update and strengthen security standards to protect ePHI, especially in light of newer threats not previously contemplated in 2003 such as ransomware. Additionally, the Department has reviewed media reports advocating the strengthening of protections provided by the HIPAA Security Rule as well as a report from a U.S. Senator advocating for modernizing HIPAA to increase protections of ePHI in the face of current cyber threats.”

It will be interesting to see if this NPRM specifically addresses security requirements for medical devices that store or transmit ePHI.

 
/* Use this with templates/template-twocol.html */