<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-13-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA22</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202310</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Proposed Modifications to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rule will propose modifications to the Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) under the Health Insurance Portability and Accountability&nbsp;Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will improve cybersecurity in the health care sector by&nbsp;strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Section 3(f)(1) Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>First Time Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>Undetermined</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Health Insurance Portability and Accountability Act of 1996 (HIPAA), sec. 262 (42 U.S.C. 1320d-2)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Information Technology for Economic and Clinical Health (HITECH) Act, sec. 13401 (42 U.S.C. 17931)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>In February 2003, the HIPAA Security Rule established standards for the security of electronic protected health information&nbsp;(ePHI) to be implemented by HIPAA covered entities and, by amendment of the HITECH Act, their business associates&nbsp;(collectively, "regulated entities"). Prior to the HIPAA Security Rule, standard security measures did not exist in the health&nbsp;care industry to address the security of ePHI while stored and exchanged between entities. Since 2003, the Department&nbsp;has received&nbsp; recommendations from the National Committee on Vital and Health Statistics (NCVHS), an advisory&nbsp;committee to the Secretary of HHS, and the public to update and strengthen security standards to protect ePHI, especially&nbsp;in light of newer threats not previously contemplated in 2003 such as ransomware. Additionally, the Department has&nbsp;reviewed media reports advocating the strengthening of protections provided by the HIPAA Security Rule as well as a&nbsp;report from a U.S. Senator advocating for modernizing HIPAA to increase protections of ePHI in the face of current cyber&nbsp;threats.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The current HIPAA Security Rule has not been updated to address the recent dramatic increase in cyber-attacks on the&nbsp;health care sector that are undermining the security of individuals&rsquo; ePHI. Section 1173(d) of the Social Security Act&nbsp;requires the Secretary of HHS to adopt security standards that take into account the technical capabilities of record&nbsp;systems used to maintain health information, the costs of security measures, the need to train persons who have access&nbsp;to health information, the value of audit trails in computerized record systems, and the needs and capabilities of small&nbsp;health care providers and rural health care providers. Since publication of the HIPAA Security Rule in 2003, there has&nbsp;been an evolution in technical capabilities of record systems used to maintain health information and costs of security&nbsp;measures that support updating the HIPAA Security Rule to help ensure that it can continue to provide a baseline of&nbsp;security standards to meet current and emerging security risks and threats to ePHI.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS considered whether these policy updates could be implemented through guidance. However, the Department&nbsp;determined that this would be insufficient to prevent and address cybersecurity threats and vulnerabilities facing the U.S.&nbsp;health care system. Revisions to the existing HIPAA Security Rule will help ensure the cybersecurity of individuals&rsquo; ePHI.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>To be determined.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>To be determined.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>09/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Undetermined</FEDERALISM>
        <ENERGY_AFFECTED>Undetermined</ENERGY_AFFECTED>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
