Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Critical Infrastructure Security - HIPAA to Mandate Increased Cybersecurity Measures in Response to Escalating Number of Attacks
Critical Infrastructure Security Attacks Latest News News & Analysis Security

HIPAA to Mandate Increased Cybersecurity Measures in Response to Escalating Number of Attacks

Adam ParlettBy Adam ParlettJanuary 15, 2025Updated:January 15, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybersecurity
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The U.S. Department of Health and Human Services (HSS) Office for Civil Rights (OCR) has published a Notice of Proposed Rulemaking (NPRM) proposing substantial cybersecurity requirements for all regulated entities and their business associates to be added to the HIPAA Security Rule.

Comments are due on or before March 7, 2025, with a final ruling due to take effect 60 days after publication and a compliance date 180 days after that. Following these dates, the NPRM also proposes a transition period beyond the 180-day compliance period to allow regulated entities to modify their business associate agreements in response to the changes.

Why Now?

The 390-page NPRM marks the first time OCR has updated the HIPAA Security Rule since 2013 in the wake of a substantial increase in breaches. The OCR Breach Portal data for 2024 makes for sobering reading and necessitates urgent action. The Secretary of the HHS OCR Breach of Unsecured Protected Health Information is required to post any breaches of unsecured protected health information affecting 500 or more individuals. As of December 20th, a staggering total of 677 major health data breaches affecting more than 182.4 million people had been recorded for the year 2024.

The main contributor to the dramatic increase in numbers was one attack in particular, the Change Healthcare ransomware attack, which happened in February and consumed the news in March when the story broke. One of the key takeaways from this attack was that UnitedHealth (Change Healthcare is a subsidiary of UnitedHealth) wasn’t using multifactor authentication (MFA), despite it being an industry standard practice.

Eliminating Ambiguity

An important aspect of the NPRM is how the HSS OCR is proposing to address issues around compliance by seeking to clarify the terms “addressable” and “required” implementation specifications. Currently, regulated entities can implement an addressable specification, use alternative security measures, or choose not to comply at all, which has led to confusion.

The NPRM proposes to eliminate this distinction, establishing that the HIPAA Security Rule provides a minimum standard for cybersecurity protections. This change will make it clear that regulated entities must comply with all standards and specifications, although they can determine how to meet them, with limited exceptions.

Industry Perspective

Ted Miracco, CEO of approov, believes that “Rebuilding user trust and safety remain critical priorities, given the extensive number of data breaches that have occurred in recent years, and their devastating impacts.” Ted identifies that the action taken by HIPPA is long overdue and thinks that enforcing tighter security measures is the right approach. He does concede, however, that mobile developers will be held to a tighter standard and have more work under these new proposals.

Lawrence Pingree, VP at dispersive, welcomes the changes. He expresses the view that “In security, the more prescriptive the controls, the better since this reduces the variance of approaches that might not adequately address current threats.” Lawrence does cautiously advise though that the biggest challenge is to ensure such prescriptive guidance does not become outdated.

Time For Change

In reviewing the NPRM, absorbing the breach portal statistics, and gauging the industry reaction, it is clear that things couldn’t continue as they were. Under the proposal, HIPAA-regulated entities would be forced to modernize. Under the rule, no form of encryption is required, and safeguards such as MFA, login attempt limitation procedures, and patch management are not required. This had to change, and hopefully, after being reviewed by the new administration in Washington, it will.

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    New Lazarus Group Scam Targets Crypto Jobseekers

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The evolution of cyber risk: Addressing geopolitical threats

May 13, 20265 Mins Read

“Recovery Is the New Prevention”: a Q&A with CSO of Health-ISAC, Errol Weiss

May 7, 20266 Mins Read

Pro-Russian threat actors target Swedish heat and power plant in failed cyberattack

April 20, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}