Discussion: View Thread

  • 1.  HIPAA Release New Stricter Cybersecurity Rules

    Posted 01-06-2025 12:39 PM

    Hello Everyone,

    Wanted to make everyone in the group aware of the new HIPAA cybersecurity regulations that just came out. Here is an article that reviews some of the main changes and implications. Also, I have created summary of the article below to in case you are on a time crunch.

    New HIPAA Security Rules Pull No Punches

    The article discusses the upcoming changes to HIPAA cybersecurity rules for healthcare organizations starting in 2025. Here are the key points:

    Stricter Standards: The new rules will impose stricter cybersecurity standards on healthcare organizations, including providers, plans, clearinghouses, and their business associates.

    New Requirements: These include multifactor authentication, encryption, patch management, access controls, backup and recovery, incident reporting, risk assessments, and compliance audits.

    Cost Implications: Implementing these new measures is expected to cost around $9 billion in the first year and $6 billion annually for the next four years.
    Challenges for Smaller Organizations: Smaller healthcare organizations may struggle with the costs and complexity of these new requirements, potentially needing to hire virtual CISOs to manage their cybersecurity strategies.

    Elimination of Flexibility: The new rules will remove the distinction between "addressable" and "required" rules, making all cybersecurity measures mandatory for all organizations, regardless of size or circumstance.

    These changes aim to enhance the protection of electronic protected health information (ePHI) against rising threats like ransomware.

     



    ------------------------------
    Joey O'Bryhim
    Associate Web Specialist
    National Association of County and City Health Officials (NACCHO)
    Washington DC
    (703)785-8118
    ------------------------------


  • 2.  RE: HIPAA Release New Stricter Cybersecurity Rules

    Posted 01-10-2025 11:15 AM

    Thanks, Joey!

    This is helpful. I saw an article the other week about this coming down and wondering what it was about. Are there resources already available for LHDs to complete risk assessments or compliance audits with IT , their Attorney, and whomever else?

     

    I feel like I've heard so much of this ends up being 'so much' that it ends up being outsourced to have performed, but is it possible to complete some of these requirements in house?

     

     

    -Sam

     

    How was your experience today? Your survey feedback will help us improve!

     

     

    Sam Jarvis, MS, LEHP, CERC, CPH | he/him/his

    Community Health Division Manager

    Johnson County Public Health
    855 S Dubuque St. Iowa City, IA 52240


        Direct: 319-688-5884

       sjarvis@johnsoncountyiowa.gov

        www.johnsoncountyiowa.gov 

     

    "Salus populi suprema est lex" – The welfare of the people is the supreme law

     

    NOTICE OF CONFIDENTIALITY: This e-mail, including any attachments, is intended only for the use of the individual or entity to which it is addressed and may contain confidential information that is legally privileged and exempt from disclosure under applicable law.  If the reader of this message is not the intended recipient, you are notified that any review, use, disclosure, distribution or copying of this communication is strictly prohibited.  If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.

     






  • 3.  RE: HIPAA Release New Stricter Cybersecurity Rules

    Posted 01-13-2025 07:57 AM

    Hey Sam,

    The HIPAA changes aren't final yet, so they don't have any new resources or training yet on their site yet. ASTP and CISA do have free risk assessment tools and guides to complete a risk assessment. Those resources you can find here:

    Risk Assessments | CISA

    Security Risk Assessment Tool | HealthIT.gov



    ------------------------------
    Joey O'Bryhim
    Associate Web Specialist
    National Association of County and City Health Officials (NACCHO)
    Washington DC
    (703)785-8118
    ------------------------------