<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-25-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0945-AA22</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0945</CODE>
            <NAME>Office for Civil Rights</NAME>
            <ACRONYM>OCR</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0900</CODE>
            <NAME>Department of Health and Human Services</NAME>
            <ACRONYM>HHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Proposed Modifications to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rule will propose modifications to the Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). These modifications will improve cybersecurity in the health care sector by strengthening requirements for HIPAA regulated entities to safeguard electronic protected health information to prevent, detect, contain, mitigate, and recover from cybersecurity threats.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Section 3(f)(1) Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>Undetermined</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>45 CFR 160</CFR>
            <CFR>45 CFR 164</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>Health Insurance Portability and Accountability Act of 1996 (HIPAA), sec. 262 (42 U.S.C. 1320d-2)</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Health Information Technology for Economic and Clinical Health (HITECH) Act, sec. 13401 (42 U.S.C. 17931)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>In February 2003, the HIPAA Security Rule established standards for the security of electronic protected health&nbsp;information (ePHI) to be implemented by HIPAA covered entities and, by amendment of the HITECH Act, their&nbsp;business associates (collectively, "regulated entities"). Prior to the HIPAA Security Rule, standard security measures&nbsp;did not exist in the health care industry to address the security of ePHI while stored and exchanged between entities.&nbsp;Since 2003, the Department has received recommendations from the National Committee on Vital and Health Statistics&nbsp;(NCVHS), an advisory committee to the Secretary of HHS, and the public to update and strengthen security standards&nbsp;to protect ePHI, especially in light of newer threats not previously contemplated in 2003 such as ransomware.&nbsp;Additionally, the Department has reviewed media reports advocating the strengthening of protections provided by the&nbsp;HIPAA Security Rule as well as a report from a U.S. Senator advocating for modernizing HIPAA to increase protections&nbsp;of ePHI in the face of current cyber threats.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The current HIPAA Security Rule has not been updated to address the recent dramatic increase in cyber-attacks on&nbsp;the health care sector that are undermining the security of individuals&rsquo; ePHI. Section 1173(d) of the Social Security&nbsp;Act requires the Secretary of HHS to adopt security standards that take into account the technical capabilities of record systems used to maintain health information, the costs of security measures, the need to train persons who&nbsp;have access to health information, the value of audit trails in computerized record systems, and the needs and&nbsp;capabilities of small health care providers and rural health care providers. Since publication of the HIPAA Security&nbsp;Rule in 2003, there has been an evolution in technical capabilities of record systems used to maintain health&nbsp;information and costs of security measures that support updating the HIPAA Security Rule to help ensure that it can&nbsp;continue to provide a baseline of security standards to meet current and emerging security risks and threats to ePHI.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>HHS considered whether these policy updates could be implemented through guidance. However, the Department&nbsp;determined that this would be insufficient to prevent and address cybersecurity threats and vulnerabilities facing the&nbsp;U.S. health care system. Revisions to the existing HIPAA Security Rule will help ensure the cybersecurity of&nbsp; individuals&rsquo; ePHI.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Department expects that this rule will be significant under section 3(f)(1) of E.O. 12866. New costs attributable to&nbsp;this proposed rule would be associated with regulated entities&rsquo; obligations to comply with updated requirements to&nbsp;safeguard the confidentiality, integrity, and availability of ePHI. The Department believes that implementing the proposed changes would reduce the incidence of breaches in health care and the costs of mitigating breaches when&nbsp;they occur, resulting in substantial savings and increased protection of ePHI.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>None.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>12/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
            <SMALL_ENTITY>Governmental Jurisdictions</SMALL_ENTITY>
            <SMALL_ENTITY>Organizations</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Undetermined</FEDERALISM>
        <ENERGY_AFFECTED>Undetermined</ENERGY_AFFECTED>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marissa</FIRST_NAME>
                <LAST_NAME>Gordon-Nguyen</LAST_NAME>
                <TITLE>Senior Advisor for Health Information Privacy, Data, and Cybersecurity Policy</TITLE>
                <AGENCY>
                    <CODE>0945</CODE>
                    <NAME>Office for Civil Rights</NAME>
                    <ACRONYM>OCR</ACRONYM>
                </AGENCY>
                <PHONE>800 368-1019</PHONE>
                <TDD_PHONE>800 537-7697</TDD_PHONE>
                <EMAIL>ocrprivacy@hhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>200 Independence Avenue SW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20201</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
