Loading...
Loading...
Browse all stories on DeepNewz
VisitHHS Proposes First Cybersecurity Overhaul in Two Decades for Electronic Health Data
Jan 14, 2025, 12:04 AM
The U.S. Department of Health and Human Services (HHS) has proposed a major update to its cybersecurity rules for electronic health data, marking the first significant overhaul in two decades. Announced by the HHS Office for Civil Rights on January 6, the proposed rule aims to address the increasing frequency and sophistication of cyberattacks targeting the healthcare sector, including hospitals, physicians' groups, and the broader healthcare supply chain. Key changes include mandatory encryption of health data at rest and in transit, annual risk assessments, multifactor authentication, and stricter compliance requirements for business associates such as vendors and contractors. The proposal also eliminates flexibility in security measures, requiring all entities to adhere to uniform standards. HHS noted that breaches have risen by more than 50% since 2020, with damages averaging $10 million per incident. The rule is designed to enhance the protection of patient health information and reduce the impact of ransomware attacks, such as the February 2024 Change Healthcare ransomware attack. Public comments on the proposed rule are due by March 6, 2025, and the final implementation timeline remains uncertain, especially with the incoming Trump administration, which may influence the rulemaking process.
View original story
Markets
Yes • 50%
No • 50%
HHS official announcements and Federal Register publications
Yes • 50%
No • 50%
News reports from major media outlets and cybersecurity incident reports
Yes • 50%
No • 50%
Official announcements from the Trump administration or HHS
More than 90% • 25%
Less than 50% • 25%
50% to 75% • 25%
76% to 90% • 25%
Surveys and reports from healthcare industry associations and compliance audits
Industry pushback • 25%
Technical challenges • 25%
Administrative changes • 25%
Other • 25%
Official statements from HHS or government officials, and news reports
Retail • 25%
Healthcare • 25%
Finance • 25%
Government • 25%
Annual cybersecurity reports from leading cybersecurity firms