logo

Proposed HIPAA Amendments Will Close Healthcare Security Gaps

ID: e52ba194-3bce-5bf6-9d7d-a572f68c4963

STIX ID: report--e52ba194-3bce-5bf6-9d7d-a572f68c4963

Feed Name: Dark Reading

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Fahmida Y. Rashid

...
...

HHS has proposed a major revision to the HIPAA Security Rule that would impose stronger baseline cybersecurity requirements on covered entities and business associates — including mandatory multifactor authentication, encryption of PHI at rest and in transit, maintained asset inventories and network maps, documented incident response and recovery plans with 72-hour restoration targets, semiannual vulnerability scans, annual penetration testing, network segmentation, anti-malware defenses, removal of extraneous software, and yearly compliance audits — with an estimated $9 billion first-year cost and a 60-day public comment period before finalization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.