Description

Announced Planned updates of NIST SP 800-66

On 5 September 2023, the US National Institute for Standards and Technology (NIST) announced that it would publish a final draft of Special Paper (SP) 800-66 Revision 2 in late 2023. The SP provides guidance on the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule, which requires regulated entities processing electronic protected health information (ePHI) to protect such information from hazards, and impermissible uses and disclosures. Specifically, the SP provides guidance on topics like risk assessments, risk management, and various types of safeguards. The revision will be based on a public consultation on the SP in 2022. NIST provided details of a number of intended changes, such as providing more resources for small regulated entities, clarifying the definitions of "risk analysis" and "risk assessment", and making changes to the Appendix

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2021-04-29
in consultation

On 29 April 2021, the National Institute of Standards and Technology opened a public consultation o…

2021-07-09
processing consultation

On 9 July 2021, the National Institute of Standards and Technology closed the public consultation o…

2022-07-21
in consultation

On 21 July 2022, the US National Institute for Standards and Technology (NIST) opened a consultatio…

2022-10-05
processing consultation

On 5 October 2022, the US National Institute for Standards and Technology (NIST) closed a consultat…

2023-09-05
under deliberation

On 5 September 2023, the US National Institute for Standards and Technology (NIST) announced that i…

2024-02-14
adopted

On 14 February 2024, the National Institute of Standards and Technology adopted a Cybersecurity Res…