HHS’ proposed HIPAA Amendment to Strengthen Cybersecurity in Healthcare and how Private AI can Support Compliance
On December 27, 2024, the U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), issued a proposed rule to enhance the cybersecurity measures required under the HIPAA Security Rule. This Notice of Proposed Rulemaking (NPRM) seeks to bolster the defenses of the U.S. healthcare system against the rising tide of cyberattacks, particularly those targeting electronic protected health information (ePHI). The changes aim to address critical weaknesses, clarify obligations, and align the Security Rule with modern cybersecurity practices.