Tuesday, 4 March 2025
31.3 C
Singapore
38.7 C
Thailand
26.6 C
Indonesia
27.5 C
Philippines

The US proposes stricter cybersecurity rules to protect healthcare data

The US proposes healthcare cybersecurity rules, including encryption and MFA, to protect patient data. The first year's cost is estimated at US$9B.

The US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has proposed improving cybersecurity measures within healthcare organisations. This initiative is designed to safeguard patientsโ€™ sensitive information from the rising threat of cyberattacks. According to Reuters, the proposal follows significant breaches, including one earlier this year that exposed the private data of over 100 million UnitedHealth patients.

Protecting patient data from cyberattacks

The new rules call for several key measures to prevent breaches and mitigate the damage caused by cyberattacks. Under the proposal, healthcare providers and related organisations would be required to:

  • Implement multifactor authentication (MFA) to secure access to systems.
  • Segment their networks to prevent the spread of intrusions across systems.
  • Encrypt patient data to ensure that even stolen information remains inaccessible.

In addition, the rules mandate specific risk analysis practices, maintaining compliance documentation, and adhering to other cybersecurity protocols.

These measures form part of a larger cybersecurity strategy unveiled by the Biden administration last year. The regulations would amend the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) if approved. This rule, which governs entities such as doctors, nursing homes, and insurance companies, was last updated in 2013.

Significant costs but long-term benefits

While the proposed changes aim to enhance security, they come with a hefty price tag. According to Anne Neuberger, the US deputy national security advisor, the first year of implementation is estimated to cost US$9 billion, followed by US$6 billion annually for the next four years. These costs cover system upgrades, staff training, and adopting new technologies.

Healthcare providers must weigh these expenses against the potential benefits of reduced data breaches and increased patient trust. The updated framework is designed to minimise risks in an industry increasingly targeted by cybercriminals.

Public input and timeline for implementation

The OCR plans to publish the proposal in the Federal Register on January 6. This will initiate a 60-day public comment period, allowing stakeholders and members of the public to provide feedback. After the comment period ends, the final rule will be set, potentially leading to a significant shift in how healthcare organisations handle cybersecurity.

As cyberattacks become more sophisticated, the US governmentโ€™s focus on strengthening protections for patient data highlights the growing need for vigilance and innovation in cybersecurity. The proposed measures, if adopted, could set a new standard for safeguarding sensitive information in the healthcare sector.

Hot this week

Samsung unveils new Galaxy A56 5G, Galaxy A36 5G and Galaxy A26 5G with AI features

Samsungโ€™s new Galaxy A56 5G, A36 5G and A26 5G bring AI features, advanced cameras, and durability with up to 6 years of updates.

MOVA Z50 Ultra review: Worldโ€™s first HydroSync mopping & AI-powered cleaning innovation

Experience hands-free cleaning with the MOVA Z50 Ultra, featuring heated water mopping, AI-powered navigation, and a self-maintaining dock for effortless floor care.

Appleโ€™s fully modernised Siri might not arrive until 2027

Apple may not release a thoroughly modern version of Siri until 2027, with a major AI-powered upgrade expected to roll out in phases.

OpenAI delays GPT-4.5 rollout due to lack of GPUs

OpenAI CEO Sam Altman says the company is facing a GPU shortage, delaying the rollout of GPT-4.5 and prompting plans for future AI chip development.

Adobe: Driving Singapore’s digital transformation through Smart Nation 2.0

Adobe is driving Singaporeโ€™s Smart Nation 2.0 with AI, personalisation, and accessibility, enhancing citizen engagement and digital governance.

Adobe: Driving Singapore’s digital transformation through Smart Nation 2.0

Adobe is driving Singaporeโ€™s Smart Nation 2.0 with AI, personalisation, and accessibility, enhancing citizen engagement and digital governance.

Smart Communications reveals 5 key trends shaping customer conversations in 2025

Smart Communicationsโ€™ 2025 Trends Report highlights key trends in AI, personalisation, and modernisation, shaping the future of customer conversations.

Microsoft to shut down Skype in May and focus on Teams

Microsoft will shut down Skype on May 5 and focus on Teams. Users can transfer their chats and contacts to Teams for a seamless switch.

Trump pushes for U.S. crypto reserve to boost digital assets

Donald Trump calls for a U.S. crypto reserve to support digital assets, highlighting XRP, Solana, and Cardano and later adding Bitcoin and Ethereum.

Related Articles