this is the default page template
AHPA submitted comments on: HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information. Click here for the full comment letter. Below are some key takeaways.- AHPA recommends that HHS retain a technology-neutral, risk-based cybersecurity framework rather than adopting uniform mandates that may not reflect differences in organizations’ size, resources, systems, and risk profiles. It urges HHS to rely more heavily on established recommendations from the Health Sector Coordinating Council and National Institute of Standards and Technology.
- Adopt a phased, flexible implementation timeline: AHPA argues that the proposed compliance period is insufficient given the rule’s scope and technical complexity. It recommends a multiyear, phased implementation developed in consultation with regulated entities, with additional flexibility and support for physician practices, rural hospitals, and other organizations with limited financial and technical resources.
- Replace inflexible operational mandates with risk-based standards: AHPA opposes several requirements it considers impractical, including restoring electronic information systems within 72 hours of a disruption and terminating workforce access within one hour of employment termination. It also recommends allowing organizations to determine logging, system reviews, encryption, and compensating controls based on their own risk analyses and patient-safety needs.
- Clarify and narrow the rule’s terminology and reporting scope: AHPA opposes expanding “security incident” to include every unsuccessful access or interference attempt because organizations may experience hundreds of thousands of failed attempts. It recommends limiting “technology assets” to relevant hardware systems that store electronic protected health information and clearly defining terms such as “resiliency,” “critical risk,” “high risk,” and “direct management control.”
- Reassess compliance costs and provide federal financial support: AHPA argues that HHS substantially underestimated the staffing, technology, auditing, testing, contracting, and reporting costs associated with the proposed rule. AHPA estimates that the changes could increase each member system’s cybersecurity costs by more than $11 million. It recommends increased federal reimbursement or funding and, if funding is unavailable, a multiyear rollout focused initially on the highest-risk applications.