March 13, 2025

The American College of Radiology® (ACR®) recommended to the U.S. Department of Health and Human Services (HHS) that it rescind or otherwise rework its proposed rule to revise cybersecurity requirements within the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. If finalized, it would likely result in significant compliance costs and burdens at a time of decreased reimbursement and increased practice expenses.

The proposed rule, published late last year by the Biden administration, was widely criticized as rushed and indiscriminate. ACR emphasized its strong support for enhancing cybersecurity in the healthcare sector in general, but noted the proposal needs revision to reflect the various roles, available resources, and good faith compliance efforts of the disparate affected parties. The College suggested HHS should extensively engage the physician community to inform its future policy proposals and establish help centers that provide cybersecurity assistance to providers and small entities.  

For more information or if you have questions about ACR’s comment letter, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • ACR Advises Changes to Washington State PAD Report

    ACR urged the WA State Health Technology Clinical Committee to not act on the draft report that would limit coverage of endovascular procedures for PAD.

    Read more
  • ACR Releases Impact Tables for 2026 MPFS Proposed Rule

    The tables cover specific proposed changes in reimbursement rates between 2025 and 2026 for each CPT® code.

    Read more
  • Take Action: Contact Your US Senators to Cosponsor ROOT Act

    Support the ROOT Act—Senate cosponsors needed to fix CMS issues with imaging AUC under PAMA. College member advocacy is key.

    Read more