United States of America: Adopted Health Insurance Portability and Accountability Act (HIPAA) via Cybersecurity Resource Guide

Description

Adopted Health Insurance Portability and Accountability Act (HIPAA) via Cybersecurity Resource Guide

On 14 February 2024, the National Institute of Standards and Technology adopted a Cybersecurity Resource Guide, implementing the Security Rule under the Health Insurance Portability and Accountability Act (HIPAA). The Cybersecurity Resource Guide provides information on the protection of electronic protected health information (ePHI) that is held or maintained by regulated entities. Regulated entities include healthcare providers, health plan providers, healthcare clearinghouses, and business associates that perform certain functions or activities that involve the use or disclosure of protected health information. Any ePHI created, received, maintained, or transmitted by a regulated entity must be safeguarded against reasonably foreseeable threats, risks, and unauthorised uses or disclosures. The document offers practical guidance and resources for regulated entities of all sizes, helping them to secure ePHI and enhance their understanding of the security measures outlined in the HIPAA Security Rule, including the HIPAA risk management requirements, that mandate a risk analysis including an accurate and thorough assessment of potential risks and vulnerabilities to the confidentialities, integrity, and availability of electronic protected health information.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: cloud computing, storage and databases
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2021-04-29
in consultation

On 29 April 2021, the National Institute of Standards and Technology opened a public consultation o…

2021-07-09
processing consultation

On 9 July 2021, the National Institute of Standards and Technology closed the public consultation o…

2022-07-21
in consultation

On 21 July 2022, the US National Institute for Standards and Technology (NIST) opened a consultatio…

2022-10-05
processing consultation

On 5 October 2022, the US National Institute for Standards and Technology (NIST) closed a consultat…

2023-09-05
under deliberation

On 5 September 2023, the US National Institute for Standards and Technology (NIST) announced that i…

2024-02-14
adopted

On 14 February 2024, the National Institute of Standards and Technology adopted a Cybersecurity Res…