March 13, 2025

The American College of Radiology® (ACR®) recommended to the U.S. Department of Health and Human Services (HHS) that it rescind or otherwise rework its proposed rule to revise cybersecurity requirements within the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. If finalized, it would likely result in significant compliance costs and burdens at a time of decreased reimbursement and increased practice expenses.

The proposed rule, published late last year by the Biden administration, was widely criticized as rushed and indiscriminate. ACR emphasized its strong support for enhancing cybersecurity in the healthcare sector in general, but noted the proposal needs revision to reflect the various roles, available resources, and good faith compliance efforts of the disparate affected parties. The College suggested HHS should extensively engage the physician community to inform its future policy proposals and establish help centers that provide cybersecurity assistance to providers and small entities.  

For more information or if you have questions about ACR’s comment letter, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • Federal Government Shutdown: Key Updates

    Key information and resources for ACR members regarding the October 2025 U.S. federal government shutdown.

    Read more
  • CMS Appears to Lift Majority of Medicare Claims Holds

    The most recent update by CMS directs MACs to lift the hold on certain services impacted by select expired Medicare legislative payment provisions.

    Read more
  • Urge Your Representative to Cosponsor ROOT Act Today

    ACR urges support for H.R. 5737, the ROOT Act, to fix CMS imaging rules and save Medicare billions. Contact your rep to cosponsor today.

    Read more