Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

The HHS Seeks Comments on Proposed Changes to HIPAA Security Rule

From the College  |  February 10, 2025

Early last month, the U.S. Department of Health & Human Services (HHS) Office for Civil Rights published a proposed rule, which seeks comments on proposed modifications to the Security Standards for the Protection of Electronic Protected Health Information, commonly known as the “Security Rule.” The proposed changes aim to address modern breach and cybersecurity risks to electronic protected health information and common deficiencies observed by the HHS in Security Rule compliance investigations. They also incorporate current industry best practices and court decisions affecting enforcement of the Security Rule.

The relevant provisions are summarized below.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Technology Asset Inventory & Network Map

The proposed standards specify development and revision of a technology asset inventory and network map illustrating the movement of ePHI throughout the regulated entity’s electronic information systems on an ongoing basis, but at least every 12 months and following any change to the regulated entity’s environment or operations that may affect ePHI.

Risk Analysis

The changes include greater specificity for conducting a risk analysis, which must include a review of the technology asset inventory and network map; identification of all reasonably anticipated threats to the confidentiality, integrity and availability of ePHI; identification of potential vulnerabilities and predisposing conditions to the regulated entity’s relevant electronic information systems; and an assessment of the risk level for each identified threat and vulnerability, based on the likelihood that each identified threat will exploit the identified vulnerabilities.

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

Annual Security Rule Compliance Audits

HIPAA-regulated entities will be required to conduct a HIPAA Security Rule compliance audit at least every 12 months.

Contingency Planning & Security Incident Response

The modifications would establish written procedures for restoring electronic information systems and data within 72 hours; conduct an analysis of the relative criticality of electronic information systems and technology assets to establish the restoration priority; establish written security incident response plans and procedures on how workforce members can report potential or known security incidents; establish written procedures on how the entity will respond; and implement written procedures for testing and revising incident response plans.

Notification Requirements

Certain regulated entities must be notified within 24 hours when a workforce member’s access to ePHI or certain electronic information systems is changed or terminated. Business associates must notify covered entities when they have implemented their contingency plans without unnecessary delay and no later than 24 hours after the contingency plan has been implemented.

Annual Verification of Business Associates’ & Contractors’ Technical Safeguards

At least every 12 months, business associates must have a subject matter expert verify that they have deployed the technical safeguards required by the Security Rule to protect ePHI. The same applies to business associates’ contractors for their business associates.

Page: 1 2 | Single Page
Share: 

Filed under:From the CollegeTechnology Tagged with:electronic protected health information (ePHI)HIPAASecurity

Related Articles

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties

    April 1, 2013

    Physicians’ business associates can now face civil and criminal penalties for violating HIPAA laws guarding the confidentiality of protected health information

    HIPAA Security Standards: What Rheumatologists Need to Know

    April 1, 2015

    Maintain compliance with updated federal rules governing privacy protection for patient health information

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences