|
|
Content Assessment: Safeguarding ePHI? NIST Updates Guidance for Health Care Cybersecurity
Information - 94%
Insight - 92%
Relevance - 91%
Objectivity - 94%
Authority - 95%
93%
Excellent
A short percentage-based assessment of the qualitative benefit of the recent announcement and initial public draft report by NIST on safeguarding electronic protected health information (ePHI).
Background Note: The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the Nationโs measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analyses to advance the development and productive use of information technology. ITLโs responsibilities include the development of management, administrative, technical, and physical standards and guidelines for the cost-effective security and privacy of other than national security-related information in federal information systems. This document from NIST provides practical guidance and resources that can be used by regulated entities of all sizes to protect ePHI and better understand the security concepts discussed in the HIPAA Security Rule.
NIST Announcement and Special Publication*
NIST Updates Guidance for Health Care Cybersecurity
Revised draft publication aims to help organizations comply with HIPAA Security Rule.
Announcement (July 21, 2022)
In an effort to help health care organizations protect patientsโ personal health information, the National Institute of Standards and Technology (NIST) has updated its cybersecurity guidance for the health care industry.ย
NISTโs new draft publication, formally titledย Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guideย (NIST Special Publication 800-66, Revision 2), is designed to help the industry maintain the confidentiality, integrity and availability of electronic protected health information, or ePHI. The term covers a wide range of patient data, including prescriptions, lab results, and records of hospital visits and vaccinations.ย
โOne of our main goals is to help make the updated publication more of a resource guide,โ said Jeff Marron, a NIST cybersecurity specialist. โThe revision is more actionable so that health care organizations can improve their cybersecurity posture and comply with the Security Rule.โย
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that requires the creation of national standards to protect sensitive patient health information from being disclosed without the patientโs consent or knowledge. Part of HIPAA is the Security Rule, which specifically focuses on protecting ePHI that a health care organization creates, receives, maintains or transmits. NIST does not create regulations to enforce HIPAA, but the revised draft is in keeping with NISTโs mission to provide cybersecurity guidance. NISTโs updated guidance is particularly timely as the U.S. Department of Health and Human Servicesย has notedย a rise in cyberattacks affecting health care.ย
NIST is seeking comments on the draft publication until Sept. 21, 2022.
One of the main reasons NIST has developed the revision is to integrate it with other NIST cybersecurity guidance that did not exist whenย Revision 1ย was published in 2008. Since then, NIST has developed its well-knownย Cybersecurity Framework, and it also has repeatedly updated its collection ofย Security and Privacy Controlsย (NIST SP 800-53) that organizations can use to tailor their own risk management approaches. The new HIPAA Security Rule guidance draft makes explicit connections to these and other NIST cybersecurity resources.ย
โWe have mapped all the elements of the HIPAA Security Rule to the Cybersecurity Framework subcategories and to controls in NIST SP 800-53โs latest version,โ Marron said. โWe have increased our emphasis on the guidanceโs risk management component, including integratingย enterprise risk managementย concepts.โย
The draft takes into account more than 400 unique responses NIST received to itsย pre-draft call for commentsย last year. Marron describes the draft as more of a refresh than an overhaul, as the documentโs structure has changed only slightly, but the content has been updated with an increased emphasis on assessment and management of risk to ePHI. Many of the significant changes are implied in the publicationโs โNote to Reviewers,โ which asks readers for thoughts on specific sections.ย
Marron said that as with many related NIST cybersecurity publications, the revised draft was not intended to be a checklist for health care organizations to follow, but rather to guide them in improving their management of risk to ePHI.ย
โWe provide a resource that can assist you with implementing the Security Rule in your own organization, which may have particular needs,โ he said. โOur goal is to offer guidance and resources you can use in one readable publication.โ
NIST is accepting comments on the draft until Sept. 21, 2022, by email toย sp800-66-comments@nist.gov.
Read the original announcement.
NIST - Implementing the HIPAA Security Rule - A Cybersecurity Resource Guide
Read the original publication.
Additional Reading
- A Safe Space? EDPB and EDPS Adopt Joint Opinion on European Health Data Space Proposal
- A Solid Foundation? NIST Publishes Review of Digital Forensics Methods
Source: ComplexDiscovery

























