March 13, 2025

The American College of Radiology® (ACR®) recommended to the U.S. Department of Health and Human Services (HHS) that it rescind or otherwise rework its proposed rule to revise cybersecurity requirements within the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. If finalized, it would likely result in significant compliance costs and burdens at a time of decreased reimbursement and increased practice expenses.

The proposed rule, published late last year by the Biden administration, was widely criticized as rushed and indiscriminate. ACR emphasized its strong support for enhancing cybersecurity in the healthcare sector in general, but noted the proposal needs revision to reflect the various roles, available resources, and good faith compliance efforts of the disparate affected parties. The College suggested HHS should extensively engage the physician community to inform its future policy proposals and establish help centers that provide cybersecurity assistance to providers and small entities.  

For more information or if you have questions about ACR’s comment letter, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • ACR Advocates Changes to Improve IPPS, OPPS

    ACR submitted official comments to the Centers for Medicare and Medicaid Services in response to the agency’s RFI related to the FY 2026 Hospital Inpatient Prospective Payment System.

    Read more
  • ACR Provides Recommendations About Fed Health Tech Programs

    The College’s feedback is in response to the government’s request for information regarding the health technology ecosystem.

    Read more
  • ACR Drives Results at June AMA House of Delegates Meeting

    The ACR team engaged in policy discussions, helping to shape the future of healthcare and ensure the voice of radiology is heard loud and clear.

    Read more