Tuesday, 31 December 2024
25.8 C
Singapore

The US proposes stricter cybersecurity rules to protect healthcare data

The US proposes healthcare cybersecurity rules, including encryption and MFA, to protect patient data. The first year's cost is estimated at US$9B.

The US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has proposed improving cybersecurity measures within healthcare organisations. This initiative is designed to safeguard patients’ sensitive information from the rising threat of cyberattacks. According to Reuters, the proposal follows significant breaches, including one earlier this year that exposed the private data of over 100 million UnitedHealth patients.

Protecting patient data from cyberattacks

The new rules call for several key measures to prevent breaches and mitigate the damage caused by cyberattacks. Under the proposal, healthcare providers and related organisations would be required to:

  • Implement multifactor authentication (MFA) to secure access to systems.
  • Segment their networks to prevent the spread of intrusions across systems.
  • Encrypt patient data to ensure that even stolen information remains inaccessible.

In addition, the rules mandate specific risk analysis practices, maintaining compliance documentation, and adhering to other cybersecurity protocols.

These measures form part of a larger cybersecurity strategy unveiled by the Biden administration last year. The regulations would amend the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) if approved. This rule, which governs entities such as doctors, nursing homes, and insurance companies, was last updated in 2013.

Significant costs but long-term benefits

While the proposed changes aim to enhance security, they come with a hefty price tag. According to Anne Neuberger, the US deputy national security advisor, the first year of implementation is estimated to cost US$9 billion, followed by US$6 billion annually for the next four years. These costs cover system upgrades, staff , and adopting new technologies.

Healthcare providers must weigh these expenses against the potential benefits of reduced data breaches and increased patient trust. The updated framework is designed to minimise risks in an industry increasingly targeted by cybercriminals.

Public input and timeline for implementation

The OCR plans to publish the proposal in the Federal Register on January 6. This will initiate a 60-day public comment period, allowing stakeholders and members of the public to provide feedback. After the comment period ends, the final rule will be set, potentially leading to a significant shift in how healthcare organisations handle cybersecurity.

As cyberattacks become more sophisticated, the US ‘s focus on strengthening protections for patient data highlights the growing need for vigilance and innovation in cybersecurity. The proposed measures, if adopted, could set a new standard for safeguarding sensitive information in the healthcare sector.

Hot this week

PlayStation Portal now supports cloud streaming for more gaming flexibility

PlayStation Portal gets cloud streaming support for PlayStation Plus Premium subscribers, offering more playability and enhanced audio features.

China records highest number of video game approvals since 2019

China approved over 1,400 video games in 2024, setting a record year for licensing and showcasing strong sales growth and global impact.

LG reveals 2025 gaming monitors with innovative bendable 5K2K OLED

LG unveils its 2025 gaming monitors, led by a 5K2K bendable OLED. These monitors boast 21:9 aspect ratios and advanced features for immersive gaming.

Marriott and Starwood hotels urged to strengthen data security measures

The FTC ordered Marriott and Starwood to improve data security after breaches exposed the information of 344M customers with new policies and transparency.

YouTube tests a new feature to help you decide what to watch

YouTube tests a "Play something" button to help users decide what to watch next, offering personalised video recommendations through the Shorts interface.

Lenovo Yoga Pro 9i review: A powerhouse for creators and professionals

Experience professional-grade performance with the Lenovo Yoga Pro 9i featuring a 16-inch Mini LED display, NVIDIA RTX 4070, and AI-powered tools.

Huawei slashes smartphone prices to compete for high-end market share in China

Huawei slashes prices on flagship smartphones, including the Mate X5 and Pura 70 Ultra, as it fights for market share in China's premium segment.

ByteDance outspends rivals with US$11 billion investment in AI and tech

ByteDance leads China's tech spending with US$11 billion in AI and infrastructure, outpacing rivals and boosting its AI chatbot Doubao.

LG reveals 2025 gaming monitors with innovative bendable 5K2K OLED

LG unveils its 2025 gaming monitors, led by a 5K2K bendable OLED. These monitors boast 21:9 aspect ratios and advanced features for immersive gaming.

Related Articles