New HIPAA Cybersecurity Rules Pull No Punches
ID: be76b999-2207-5a18-b765-646dad294c90
STIX ID: report--be76b999-2207-5a18-b765-646dad294c90
Feed Name: Dark Reading
HHS has proposed a comprehensive, prescriptive overhaul of the HIPAA Security Rule that would require uniform cybersecurity controls—such as multifactor authentication, encryption, patch management, backups, incident reporting, and regular risk assessments—by eliminating the addressable/required distinction; the draft is framed as a response to a sharp rise in large-scale healthcare breaches and ransomware, but experts warn the stricter rule could impose substantial compliance costs (estimated billions) and strain smaller providers, potentially increasing demand for outsourced security services like virtual CISOs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
