Jan. 15, 2025
The U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR) published a proposed rule in the Jan. 6 Federal Register to substantially increase the stringency of the cybersecurity requirements for regulated entities in the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule.

The intent of the proposed rule is to address prevalent cyberattack threats to electronic protected health information (ePHI) by proposing changes to various risk analyses, review, documentation, and other practices. Compliance costs for these proposals are estimated by OCR to be significant. However, the incoming administration signaled its intent to review many of the transition period’s major rules and proposals.

The American College of Radiology® (ACR®) is reviewing and communicating closely with other national physician organizations. To provide input for inclusion in future ACR comments, contact Michael Peters, ACR Senior Director, Government Affairs.

Related ACR News

  • AI Effect on Clinical Practice

    The 2025 SIIM-ACR Data Science Summit brought together leaders in radiology, informatics and healthcare artificial intelligence to explore how AI is reshaping clinical practice.

    Read more
  • Scope of Practice Expansion Bills Become Law in Oklahoma

    Two harmful scope of practice expansion bills in Oklahoma, House Bill (HB) 2298 and HB 2584, recently became law after the state legislature voted to override Gov. Kevin Stitt’s (R) executive decision to veto the bills.

    Read more
  • ACR Advocacy for Members Continues in No Surprises Act Case

    The American College of Radiology® (ACR®) continues its advocacy in the surprise patient billing arena.

    Read more