Businessolver
Businessolver Blog

Cybersecurity and the HIPAA Security Rule

Get the Businessolver Blog in your inbox
Brooke Salazar, JD Sr. Director of Compliance profile photo
By Brooke Salazar, JD Sr. Director of Compliance
 on March 5, 2024
Share:

The NIST[1] and the OCR[2] has published its final version of guidance to increase cybersecurity and compliance with the HIPAA Security Rule.

The new guidance gives tailored direction to covered entities to improve cybersecurity risk assessment and management. It replaces the July 2022 cybersecurity HIPAA guidance draft.

Security Rule Highlights

The Security Rule:

    • is โ€œflexible, scalable, and technology-neutralโ€ฆ.there is no one single compliance approach that will work for all regulated entitiesโ€ and
    • addresses covered entities based on their size, nature, and unique security risks.

For example, plan sponsors are given individual guidance that are specified in tables โ€œdesignated to initiate the thought process for regulated entities to implement the requirements of the Security Rule.โ€

This Guidance is meant to be used as a resource to assist regulated entities be compliant with the HIPAA Security Rule and with cybersecurity.

Additional Highlights

  • Risk assessments should be customized to effectively identify risk for a plan sponsor.
  • Plan sponsors can use risk management and cybersecurity methods that effectively safeguard their ePHI that are appropriate to their organization.
  • The guidance gives various security measures for each standard of the Security Rule.

What else?

The guidance also emphasizes the importance of general cybersecurity training for the entire organization.ย  It also emphasizes the importance of ensuring that HIPAA security standards work within the existing IT architecture.ย  As far as workforce security, the guidance recognizes that training should coincide with positionโ€™s job descriptions and responsibilities.ย  For example, if the organization has a self-insured health plan and is a manufacturer, should the entire organization receive HIPAA training or should the identified positions receive HIPAA training based on its roles and responsibilities that correlate with access to ePHI.

The guidance extends past the HIPAA Security Rule to highlight an organizationโ€™s business need to safeguard data as โ€œmission-critical.โ€ย  It cites ransomware attacks and large data breaches that cost millions of dollars that makes the safeguarding of data a business necessity.ย  While the guidance cites patient protection, the application of such guidance may be applied across various industries that have federal mandates to protect data.

 


 

[1] National Institute of Standards and Technology

[2] HHS Office of Civil Rights