Skip to content
Politically.com Search all
Menu

Proposed rule 2024-30983

HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information

The Department of Health and Human Services (HHS or "Department") is issuing this notice of proposed rulemaking (NPRM) to solicit comment on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information ("Security Rule") under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The proposed modifications would revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The proposals in this NPRM would increase the cybersecurity for ePHI by revising the Security Rule to address: changes in the environment in which health care is provided; significant increases in breaches and cyberattacks; common deficiencies the Office for Civil Rights has observed in investigations into Security Rule compliance by covered entities and their business associates (collectively, "regulated entities"); other cybersecurity guidelines, best practices, methodologies, procedures, and processes; and court decisions that affect enforcement of the Security Rule.

Source: FederalRegister.gov API v1Recently refreshed. Last successful refresh: 2026-07-31 22:49:02 UTC.

Source-supplied record

Document details

Document number
2024-30983
Published
Jan 6, 2025
Effective
Not supplied
Comments close
Mar 7, 2025
Federal Register citation
90 FR 898

CFR references

  • Title 45, part 160
  • Title 45, part 164