Jan. 15, 2025
The U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR) published a proposed rule in the Jan. 6 Federal Register to substantially increase the stringency of the cybersecurity requirements for regulated entities in the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule.

The intent of the proposed rule is to address prevalent cyberattack threats to electronic protected health information (ePHI) by proposing changes to various risk analyses, review, documentation, and other practices. Compliance costs for these proposals are estimated by OCR to be significant. However, the incoming administration signaled its intent to review many of the transition period’s major rules and proposals.

The American College of Radiology® (ACR®) is reviewing and communicating closely with other national physician organizations. To provide input for inclusion in future ACR comments, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • Detailed Summary of FY2026 IPPS Final Rule

    This rule provides updates to payment rates and policies for inpatient hospitals and long-term care hospitals.

    Read more
  • AHRQ Draft Report for Lumbar Fusions

    ACR submitted comments to AHRQ’s draft report on lumbar fusions, raising concerns about coverage, patient selection, and scope of reviewed procedures.

    Read more
  • CMS Announces Automatic MIPS Exemption for Providers Affected by Natural Disasters

    CMS announced it will allow automatic exemption from the 2025 MIPS for providers in certain Texas and California counties affected by natural disasters.

    Read more