New Senate Bill Seeks to Amend HIPAA with Mandatory Minimum Healthcare Cybersecurity Standards

Greenbaum, Rowe, Smith & Davis LLP
Contact

On September 26, 2024, the Health Infrastructure Security and Accountability Act was introduced in the U.S. Senate. The bill would amend the Health Insurance Portability and Accountability Act (HIPAA) and direct the U.S. Department of Health and Human Services (HHS) to develop new “mandatory minimum cybersecurity standards for health care providers, health plans, clearinghouses and business associates.” It would further mandate annual cybersecurity audits and stress tests for healthcare entities, with particular waivers for small providers. To fund these new endeavors, the bill would remove fine caps for large corporations, fund the HHS’s oversight through user fees, and allocate $1.3 billion to hospitals for cybersecurity improvements.

HHS has indicated its backing of the bill, with Deputy Secretary Andrea Palm stating, “Clear accountability measures and mandatory cybersecurity requirements for all organizations that hold sensitive data are essential.” At this writing, the American Hospital Association (AHA) has declined to comment on the bill.

One of the bill’s sponsors, Senator Ron Wyden of Oregon, has commented that the bill is necessary because “megacorporations like UnitedHealth are flunking Cybersecurity 101, and American families are suffering as a result.” UnitedHealth’s subsidiary Change Healthcare was subject to one of the largest ransomware attacks in America’s history, leading to significant impacts on patients and healthcare providers. The fallout from this ransomware breach continues to be felt across the healthcare industry.

Given that the bill was introduced as Congress concluded its last day of business until the upcoming election, it is unlikely to progress any further during this legislative session. Moreover, depending upon the outcome of the upcoming election, the bill faces an uncertain future. Nevertheless, the healthcare industry is likely to continue to face pressure to improve its cybersecurity standards, whether voluntarily or through legal mandates.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Greenbaum, Rowe, Smith & Davis LLP

Written by:

Greenbaum, Rowe, Smith & Davis LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Greenbaum, Rowe, Smith & Davis LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide