On January 5, 2021, the president signed into law H.R. 7898, an Act that amends the Health Information Technology for Economic and Clinical Health (HITECH) Act to require the Secretary of Health and Human Services (HHS) to consider specific recognized security practices of covered entities and business associates when making certain determinations regarding fines, penalties, and other remedies related to HIPAA violations, as well as determinations relating to the length and extent of HITECH audits.
In particular, the law requires the Secretary to consider certain security practices as a mitigating factor when considering fines under Section 1176 (general penalties for HIPAA violations) or Section 1177 (penalties for wrongful disclosure of individually identifiable health information), the length and extent of a HITECH audit under Section 13411, or other remedies relating to violations of the HIPAA Security Rule.
Under the new law, the Secretary shall consider whether the entity has adequately demonstrated that it had, for not less than the previous 12 months, “recognized security practices” in place. “Recognized security practices” is defined by the Act to mean the standards, guidelines, best practices, methodologies, procedures, and processes developed under the following frameworks:
- Section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act;
- This section relates to the NIST Cybersecurity Framework. Section 2(c)(15) of the NIST Act empowered the Director of NIST to facilitate the development of a voluntary, industry-led set of standards and processes to cost-effectively reduce cyber risks to critical infrastructure (the NIST Cybersecurity Framework).
- The approaches promulgated under section 405(d) of the Cybersecurity Act of 2015;
- Section 405(d) of the Cybersecurity Act of 2015 called for a more coordinated approach to cybersecurity in the healthcare industry. Supporting that mission, in 2018, HHS issued voluntary cybersecurity guidance for healthcare entities (“Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients”) based on the recommendations of the 405(d) Task Group, a HHS and industry-led collaborative task group.
- Other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities.
The Act does not create any liability or authorize the Secretary to increase fines (or the length of an audit) due to a lack of compliance with the recognized security practices, however the law also does not affect an entity’s obligations to comply with the requirements of the HIPAA Security Rule.