March 13, 2025

The American College of Radiology® (ACR®) recommended to the U.S. Department of Health and Human Services (HHS) that it rescind or otherwise rework its proposed rule to revise cybersecurity requirements within the Health Insurance Portability and Accountability Act (HIPAA) Security Rule. If finalized, it would likely result in significant compliance costs and burdens at a time of decreased reimbursement and increased practice expenses.

The proposed rule, published late last year by the Biden administration, was widely criticized as rushed and indiscriminate. ACR emphasized its strong support for enhancing cybersecurity in the healthcare sector in general, but noted the proposal needs revision to reflect the various roles, available resources, and good faith compliance efforts of the disparate affected parties. The College suggested HHS should extensively engage the physician community to inform its future policy proposals and establish help centers that provide cybersecurity assistance to providers and small entities.  

For more information or if you have questions about ACR’s comment letter, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • ACR Strategizes for 2026 State Legislative Sessions

    ACR joined other medical societies at the AMA State Legislative Roundtable to discuss policies that impact practices and patient care.

    Read more
  • Mobile Cancer Screening Act

    ACR emphasized the importance of bringing cancer screening directly to the communities that need it most to ensure early detection and intervention.

    Read more
  • ACR Challenges BCBS Policy

    3D imaging is not routinely performed and requires added resources, including specialized software, trained personnel and physician input.

    Read more