A significant increase in cyberattacks and data breaches in healthcare has occurred in recent years, and these attacks often lead to more significant harm than breaches in other sectors.
As a result, the U.S. Department of Health and Human Services (HHS) recently proposed significant changes to the HIPAA Security Rule to strengthen cybersecurity and protect electronic protected health information (ePHI). The proposed rule would require health plans, healthcare clearinghouses, and most health care providers, and their business associates, to strengthen cybersecurity protections for individuals’ protected health information (PHI).
What is the HIPAA Security Rule?
The HIPAA Security Rule is a set of national standards designed to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). It is one of several rules, collectively known as the HIPAA Rules, that protect the privacy and security of protected health information (PHI). The Security Rule applies only to ePHI, which is individually identifiable health information transmitted or maintained in electronic media.
The Security Rule was initially published in 2003 and was last revised in 2013. It requires regulated entities, including covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates, to implement administrative, physical, and technical safeguards to protect ePHI.
The Security Rule aims to:
- Ensure the confidentiality, integrity, and availability of all ePHI an entity creates, receives, maintains, or transmits.
- Protect against reasonably anticipated threats or hazards to the security or integrity of such information.
- Protect against any reasonably anticipated uses or disclosures of such information not permitted by the Privacy Rule.
- Ensure compliance by the workforce.
What are the Key Proposed Changes to the Security Rule?
The key proposed changes include:
- Eliminating the distinction between required and addressable implementation specifications, making all implementation specifications required with limited exceptions. This change aims to establish a clear baseline for protection.
- Requiring documentation of all Security Rule policies, procedures, plans, and analyses to promote accountability and consistency in implementing security measures.
- Updating definitions and revising implementation specifications to reflect changes in technology and terminology. This ensures the rule remains relevant in a rapidly evolving technological landscape.
- Encrypting ePHI at rest and in transit, with limited exceptions. Encryption is considered crucial for protecting ePHI from unauthorized access.
- Implementing multi-factor authentication (MFA) with limited exceptions. MFA adds an extra layer of security by requiring users to provide multiple forms of authentication.
- Developing and maintaining a technology asset inventory and a network map that illustrates the movement of ePHI. This inventory helps organizations understand their systems and data flow, facilitating better risk management.
- Conducting more detailed risk analyses. Organizations must assess their systems and data flow, identify threats and vulnerabilities, and determine risk levels.
- Strengthening security incident response plans and procedures. Organizations must implement measures to restore systems and data quickly after an incident and have processes for reporting and responding to incidents.
- Conducting annual compliance audits against the Security Rule requirements. Regular audits help organizations ensure ongoing compliance.
- Implementing technical controls for electronic information systems processing ePHI, such as anti-malware protection and vulnerability scans. This enhances the security posture of systems that handle ePHI.
- For business associates: Requiring notification to covered entities within 24 hours of activating the contingency plan in ePHI emergencies. This ensures timely communication and coordinated response to incidents.
- Requiring business associates to provide annual written certifications by subject matter experts confirming the deployment of technical safeguards. This requirement adds another layer of accountability for business associates.
Clarifications
In addition to the specific changes outlined in the proposed rule, HHS also seeks to clarify several aspects of the Security Rule, including:
- Ensuring deploy and implement emphasizes that safeguards must be operational throughout the regulated entity’s environment. This delivers comprehensive protection and avoids loopholes in implementation.
- Elevating risk management to a standard level by requiring organizations to have a written risk management plan. Requiring a written plan emphasizes the importance of proactive risk assessment and mitigation.
- Elevating encryption from an addressable implementation specification to a required standard. This reflects the widespread availability and affordability of encryption solutions and their critical role in protecting ePHI.
What is the impact of these proposed changes?
The Notice of Proposed Rulemaking (NPRM) was published in the Federal Register on January 6, 2025, with a 60-day public comment period. HHS expects the proposed changes to significantly impact regulated entities, with estimated first-year compliance costs totaling approximately $9 billion and years 2 through 5 incurring estimated annual expenses of $6 billion.
While acknowledging the potential administrative challenges and costs, HHS emphasizes that the enhanced security posture would likely reduce breaches and their associated costs. It is important to note that the incoming administration may modify or postpone the final rule.
What changes should organizations consider in light of these proposed rules?
In light of the proposed changes to the HIPAA Security Rule, organizations should take proactive steps to prepare for the potential impact on their operations and compliance obligations. The proposed changes, if finalized, will require substantial adjustments to security practices and policies. Here are some key actions businesses can take to prepare:
Assess Current Compliance
Conduct a comprehensive review of your existing security practices and policies, comparing them against the proposed changes in the NPRM. Determine areas where your organization already aligns with the proposed requirements and identify gaps to be addressed. Focus on encryption, multi-factor authentication, risk analysis, incident response, and business associate agreements.
Develop a Transition Plan
Create a detailed plan outlining the steps needed to achieve compliance with the proposed changes. This plan should include timelines, resource allocation, and responsibilities for different aspects of the implementation process. For example, determine the compliance deadline for modifying business associate agreements. Prioritize actions based on the level of effort required and the potential impact on your organization’s security posture.
Engage with Stakeholders
Communicate the proposed changes and your transition plan to key stakeholders, including leadership, IT staff, compliance personnel, and employees. Engage with business associates to discuss necessary contract updates and ensure their awareness of the proposed changes and how they will impact their responsibilities.
Budget for Compliance
Analyze the potential financial implications of implementing the proposed changes, considering technology upgrades, staff training, and potential consulting fees. Allocate necessary resources to cover these costs and explore funding options.
Update Policies and Procedures
Revise existing or develop new written policies and procedures to address the new requirements outlined in the NPRM, ensuring they are comprehensive, clear, and accessible to all employees. Regularly review and update these documents to maintain relevance. Pay particular attention to documentation requirements and maintenance schedules for various safeguards.
Enhance Security Infrastructure
Invest in technology upgrades and security solutions to meet the proposed requirements, such as encryption tools, MFA solutions, vulnerability scanning tools, and security incident response platforms. Implement network segmentation to limit access to ePHI and enhance security controls for relevant electronic information systems. Consider seeking guidance from cybersecurity experts and exploring available resources and best practices.
Provide Workforce Training
Develop comprehensive training programs to educate workforce members on the updated Security Rule requirements, emphasizing their roles and responsibilities in safeguarding ePHI. Focus on security awareness, incident reporting procedures, and adhering to organizational policies and procedures. Implement role-based training to ensure that workforce members receive instruction relevant to their duties.
Monitor Ongoing Developments
Stay informed about the progress of the NPRM through the public comment period and subsequent rulemaking process. Monitor industry publications and government announcements for updates and guidance related to the final rule. Be prepared to adapt your transition plan and compliance efforts to align with the final requirements.
Submit Comments
Participate in the public comment period by submitting feedback to HHS. Share your organization’s perspective on the proposed rule, highlight any concerns or challenges, and offer suggestions for improvement.
Stay Agile
Recognize that cybersecurity is an evolving field, and the regulatory landscape may continue to change. Embrace a culture of continuous improvement and stay informed about emerging threats and best practices. Be prepared to adjust your security practices and policies as needed to maintain a robust security posture.
By taking these steps, businesses can proactively prepare for the proposed changes to the HIPAA Security Rule, mitigating potential risks and ensuring the continued protection of ePHI in an increasingly complex cybersecurity environment.
Certifi’s health insurance premium billing and payment solutions help healthcare payers improve member satisfaction while reducing administrative costs.

