HHS to Establish Cybersecurity Goals, Seeks Increased HIPAA Penalties

In an effort to improve health care sector cybersecurity, HHS said it would establish voluntary cybersecurity performance goals for the health care sector and provide resources to health care entities to encourage and help them implement those best cybersecurity practices. Ultimately, these voluntary standards could become mandatory via Medicare and Medicaid regulations, the agency said.

HHS—which released these goals and planned steps on Dec. 6 in a concept paper—also said it would implement an agency-wide strategy to support greater enforcement and accountability and expand and “mature” the one-stop shop within HHS for health care sector cybersecurity. The concept paper builds on the national cybersecurity strategy that the Biden administration released in 2022.[1]

The HHS concept paper outlines four “pillars for action”:

1. Publish voluntary health care and public health sector cybersecurity performance goals. In its concept paper, HHS said that health care organizations currently have access to numerous cybersecurity standards and guidelines, potentially creating confusion regarding which ones to prioritize.

This document is only available to subscribers. Please log in or purchase access.
 


Would you like to read this entire article?

If you already subscribe to this publication, just log in. If not, let us send you an email with a link that will allow you to read the entire article for free. Just complete the following form.

* required field