false
OasisLMS
Login
Catalog
HIPAA Under the Microscope: Security Rule Updates ...
Presentation
Presentation
Back to course
Pdf Summary
The document explains upcoming proposed changes to the HIPAA Security Rule, which governs how covered entities and business associates protect electronic protected health information (ePHI). The current rule, finalized in 2003, was built for a much different healthcare environment and relies heavily on “addressable” safeguards, which gave organizations flexibility to decide whether certain protections were appropriate.<br /><br />The proposed overhaul would make many security controls mandatory rather than optional. Key expected changes include required multi-factor authentication (MFA) for systems that create, receive, maintain, or transmit ePHI; mandatory encryption of ePHI both at rest and in transit; and stronger network segmentation to separate ePHI systems from IoT devices, guest Wi-Fi, and other non-clinical systems.<br /><br />The rule would also require more routine security testing, such as vulnerability scanning every six months and annual penetration testing, along with written documentation of findings and remediation. Backup and disaster recovery expectations would become more explicit, including offline backups, recovery procedures, and regular testing to protect against ransomware. Organizations would also need stronger asset inventories and network mapping to understand what systems exist and how ePHI flows through them.<br /><br />Vendor oversight would increase as well. Business associate agreements may need to spell out technical safeguards, and covered entities would be expected to verify vendor security controls annually. Business associates may also face much faster breach notification deadlines, potentially requiring notice within 24 hours of a significant incident.<br /><br />The document concludes that these changes may become effective in 2026, with a relatively short compliance window. Organizations are encouraged to start preparing now through budgeting, vendor coordination, technical upgrades, and staff training.
Keywords
HIPAA Security Rule
ePHI
multi-factor authentication
encryption
network segmentation
vulnerability scanning
penetration testing
disaster recovery
vendor oversight
breach notification
×
Please select your language
1
English