Showing posts with label Healthcare Cybersecurity. Show all posts
Showing posts with label Healthcare Cybersecurity. Show all posts

Thursday, September 25, 2025

HHS Sends Healthcare IT Deregulatory NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the HHS National Coordinator for Health IT (ONC) on “Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity ”. This would appear to be part of the Trump Administration’s aggressive attempt at reducing the regulatory requirements of the Federal Government.

According to the abstract for this rulemaking in the Spring 2025 Unified Agenda:

“The rulemaking would focus on potential deregulatory actions identified in 45 CFR part 170 (Health Information Technology Standards, Implementation Specifications, and Certification Criteria and Certification Programs for Health IT). Inclusive of proposals would be those that propose to codify all or parts of recent enforcement discretion guidance (Enforcement Discretions | HealthIT.gov) and propose, to remove certain certification criteria, Condition and Maintenance of Certification requirements, and other ONC Health IT Certification Program requirements. Additionally, we are evaluating other potential deregulatory actions under 45 CFR parts 171 (Information Blocking) and 172 (Trusted Exchange Framework and Common Agreement).”


This is not an area that I have spent much time looking at, nor do I expect to cover this rulemaking in any depth in this blog, but I am concerned that this rulemaking could remove or reduce the minimal cybersecurity standards for healthcare IT operations. The history of major healthcare cybersecurity breaches over that last couple of years does little to engender confidence in the adequacy of current cybersecurity regulations in this field, and would seem to argue for additional, not less, regulatory efforts.

Thursday, October 3, 2024

Review - HR 9412 Introduced – Healthcare Cybersecurity

Back in August, Rep Crow (D,CO) introduced HR 9412, the Healthcare Cybersecurity Act of 2024. The bill establishes requirements for: CISA-HHS coordination, CISA healthcare cybersecurity training, HHS developed sector security plans, and requires HHS to develop criteria for identifying high-risk covered assets. The bill would specifically prohibit additional funding to support these efforts.

This bill is very similar to S 4697 [removed from paywall] which was introduced in July by Sen Rosen (D,NV). That bill was considered by the Senate on July 31st, 2024. The bill was amended and recommended reported favorably by a vote of 10 to 1 {Sen Paul (R,KY) was the dissenting vote}. That report (and the amended version) has not yet been published. Paul’s opposition almost assures that the S 4697 will not be considered by the full Senate.

Moving Forward

Neither Crow, nor his three cosponsors, are members of the House Homeland Security Committee to which this bill was assigned for primary consideration. This means that there will probably not be sufficient influence to see the bill considered in Committee. With the funding exclusion added to the bill, I see nothing that would engender any organized opposition. I suspect that there would be some level of bipartisan support for the bill were it to be considered. Whether it would be sufficient to see the bill considered under the suspension of the rules process before the Full House remains to be seen.

 

For more information on this bill and its differences from S 4697, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-9412-introduced - subscription required.

Monday, July 29, 2024

Review - S 4697 Introduced – Healthcare Cybersecurity

Earlier this month, Sen Rosen (D,NV) introduced S 4697, the Healthcare Cybersecurity Act of 2024. The bill establishes requirements for: CISA-HHS coordination, CISA healthcare cybersecurity training, CISA developed sector security plans, and developing criteria for identifying high-risk covered assets. No new funding is authorized by this legislation.

Moving Forward

Rosen and one of her cosponsors {Sen Ossoff (D,GA)} are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there could be sufficient influence to see the bill considered in Committee. I suspect that there would be some level of bipartisan support for this bill, but the Ranking Member {Sen Paul (R,KY)} would be expected to oppose the bill. This would complicate passage in Committee.

Commentary

There is no discussion, or even mention, of the role cybersecurity vulnerabilities in medical software and devices have in the abetting the malicious cyberattacks discussed in the §3 findings. This bill would be the ideal place to formalize which agency (FDA or CISA) would be responsible for receiving, coordinating and publishing reports about vulnerabilities in medical software and devices. The FDA has the benefit of being the regulatory agency responsible for oversight of the safety and efficacy of such systems, thus lending gravitas to their potential coordination efforts. Meanwhile, CISA has the technical expertise and experience (and the current de facto responsibility) to manage this effort. I would suggest inserting a new §4(c) into the bill:

“(c) The Agency will assist the Department with establishing within the Food and Drug Administration an office to receive, coordinate, and make public information related to security vulnerabilities (as defined in 6 U.S.C. 650) in medical software and devices.”

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4697-introduced - subscription required.

Monday, April 29, 2024

Review - S 4054 Introduced -Health Care Cybersecurity

Earlier this month, Sen Warner (D,VA) introduced S 4054, the Health Care Cybersecurity Improvement Act of 2024. The bill would prohibit accelerated Medicare payments to hospitals and medical service providers with significant cashflow problems due to cyber-attacks unless they meet ‘minimum cybersecurity standards’. There is no new funding provided in this legislation.

Moving Forward

Warner is a member of the Senate Finance Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I suspect that there would be Republican opposition to this bill because it would effectively add cybersecurity regulations for the medical sector. I am not sure that there would be sufficient support to see this bill favorably considered. Regardless, this bill would have no chance of being considered by the full Senate under regular order.

Commentary

While there is no mention of cybersecurity regulations in this bill, nor any mandate to develop such regulations, the phrase “meets minimum cybersecurity standards, as determined by the Secretary” effectively means that HHS would need to have regulations in place that define ‘minimum cybersecurity standards’ that the Secretary would use to restrict accelerated payments under these provisions. If the bill had specifically required HHS to promulgate such regulations, the bill would have come under the purview of the Homeland Security and Governmental Affairs Committee where Warner is not a member.

 

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4054-introduced - subscription required.

Monday, March 13, 2023

Committee Hearings – Week of 3-12-23

With just the Senate in session this week, there is a relatively light hearing schedule, but we are seeing the start of FY 2024 budget hearings and hearing on the National Defense Authorization Act, nothing yet of particular interest here. There are two hearings of potential interest here, one markup and one cybersecurity hearing.

Markup

On Wednesday, the Senate Homeland Security and Governmental Affairs Committee will hold a business meeting. In addition to three nominations, they are scheduled to markup one bill: S 559, the Fire Grants and Safety Act. This is a straightforward reauthorization for the US Fire Administration, it includes funding for firefighter assistance grants. I am  not really ‘covering’ this bill, but I am watching it.

Cybersecurity

On Thursday, the Senate Homeland Security Committee will be holding a hearing on “In Need of A Checkup: Examining the Cybersecurity Risks to the Healthcare Sector”. No witness list is available yet. Possibility that medical device security issues will be addressed.

Wednesday, March 30, 2022

Review - S 3904 Introduced – Healthcare Cybersecurity

Last week, Sen Rosen (D,NV) introduced S 3904, the Healthcare Cybersecurity Act of 2022. The bill would task the Cybersecurity and Infrastructure Security Agency (CISA) with specific responsibilities for supporting the Department of Health and Human Services (HHS) efforts to improve cybersecurity practices within the Healthcare and Public Health Sector. No funding is authorized in this bill.

Moving Forward

Rosen and one of her two cosponsors {Sen Hassan (D,NH)} are members of the Senate Homeland Security and Governmental Affairs Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any organized opposition. I suspect that this bill would receive bipartisan support in Committee.

The bill is unlikely to make it to the floor of the Senate under regular order. There is a remote possibility that the bill could be taken up by the Senate under the unanimous consent process. The most likely way the bill would move forward would be for it to be included as part of a larger piece of legislation, perhaps as an amendment.

Commentary

In many ways this is just another feel good cybersecurity bill that would make it look like Congress was taking action on a very real problem. The study required in the bill would be the most helpful component of the legislation, but CISA is not required to present it to Congress who would be required to take legislative action to approve additional funding or program authorizations to allow HHS to take significant actions to improve healthcare cybersecurity. And the bill only ‘allows’ HHS to consider the provisions in the report when updating the Healthcare and Public Health Sector Specific Plan. It does not require an update or mandate that the recommendations made be considered when an update is completed. There is not even a requirement for a follow-up GAO report.

The biggest ‘feel good without doing anything of significance’ actions in the bill have to do with the two requirements dealing with Cyber Security Advisors; training and incident response. CSAs are a very limited resource within CISA, with only four or five available per region. At most they are only going to be able to provide corporate level cybersecurity-overview training or ‘report back to CISA’ incident response reviews. And even that will be limited as they are also required to support all of the other critical infrastructure sectors as well.

For more details about the requirements of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3904-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */