Proposed Changes to the HIPAA Security Rule
Prefer to listen instead of read? No problem! Listen to the blog post at any time by clicking here.
On January 6, 2025, the Department of Health and Human Services (HHS) published a Notice of Proposed Rulemaking (NPRM) to make changes to the Security Rule under the Health Insurance Portability and Accountability Act (HIPAA). In response to the growing number of significant cybersecurity attacks and persistent non-compliance by HIPAA-regulated entities with the current Security Rule, these changes would strengthen the required protections and security protocols for electronic protected health information (ePHI) that HIPAA-regulated entities must implement. The proposed updates to the Security Rule requirements loosely mirror those found in the DOL’s Cybersecurity Program Best Practices (not a requirement itself, but a standard for ERISA plans). More information can be found in the HHS Fact Sheet for the NPRM.


