Read more at source.
Read more at source.
The proposal is an update to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. A 60-day public comment period is expected to open soon. The HHS has also shared a fact sheet outlining the proposal. The plan is estimated to cost $9 billion in the first year and $6 billion over the subsequent four years.
The proposal comes in light of a marked increase in large-scale breaches over the past few years. Just this year, the healthcare industry was hit by multiple major cyberattacks, including hacks into Ascension and UnitedHealth systems that caused disruptions at hospitals, doctors offices and pharmacies. From 2018-2023, reports of large breaches increased by 102 percent, and the number of individuals affected by such breaches increased by 1002 percent, primarily due to increases in hacking and ransomware attacks.
In 2023, over 167 million individuals were affected by large breaches - a new record. This highlights the urgent need for improved cybersecurity measures in the healthcare sector.