All posts in category Privacy and Security
The EHR Association’s Privacy & Security Workgroup issued the following statement to mark Cybersecurity Awareness Month (October).
“In healthcare, cybersecurity protects more than data. It protects clinicians’ ability to deliver quality care. When a cyberattack forces a health system to take its records and scheduling systems offline, divert ambulances and delay procedures, the consequences reach the bedside.”
Understanding the scale and nature of that risk is the first step toward reducing it and the dangers it presents to healthcare providers and patients. At its 2026 HIPAA Security conference, OCR reported that in 2025, healthcare organizations reported 650 large data breaches, each affecting 500 or more people and collectively exposing the protected health information (PHI) of over 45 million individuals.
(more…)
Posted by EHR Association on October 8, 2026
https://ehrablog.org/2026/10/08/cybersecurity-is-patient-safety-ehr-association-privacy-security-workgroup-marks-cybersecurity-awareness-month/
By the EHR Association Privacy & Security Workgroup
With the recent publication of the US Department of Health and Human Services’ (HHS) 2026 unified regulatory agenda, the HHS Office for Civil Rights (OCR) hit the snooze button on HIPAA Security Rule updates. Final rulemaking for the January 2025 HIPAA Security Notice of Proposed Rule Making (NPRM) was targeted for a May 2026 release in the previous unified agenda, but notably excluded from the current agenda. Instead, it was transitioned to a long-term action with a target date of July 2027.
While this delay buys time to get the rule right, it isn’t cost-free, as the cyberattack trend that justified the NPRM in the first place hasn’t paused.
(more…)
Posted by EHR Association on September 15, 2026
https://ehrablog.org/2026/09/15/the-security-snooze-button-hipaa-security-rule-delayed-to-at-least-july-2027/
By the EHR Association’s Privacy & Security Workgroup
Health care faces several security risks that make a focus on cybersecurity particularly critical. In particular, the industry is challenged by dual threats: highly valuable patient data (worth more on the black market than financial data at this point) and system interdependencies that directly introduce additional risk. A single cyber incident can disrupt hospital operations, delay treatments, and even jeopardize patient safety.
(more…)
Posted by EHR Association on October 28, 2025
https://ehrablog.org/2025/10/28/cybersecurity-awareness-month-key-cybersecurity-controls-and-practical-challenges/
By the EHR Association’s Privacy & Security Workgroup
Healthcare cybersecurity risks have surged to unprecedented levels over the 22 years since the HIPAA Security Rule was first implemented—and the 12 years since its last update.
According to the HIPAA Wall of Shame, of the 614 data breaches reported in 2013, 43% (269) affected the healthcare industry. That was the first year since 2005 that the healthcare sector ranked higher than business in terms of the number of data breaches. At 9 million, healthcare also recorded the second-highest number of affected individuals.
(more…)
Posted by EHR Association on October 15, 2025
https://ehrablog.org/2025/10/15/cybersecurity-awareness-month-2025-the-state-of-healthcares-cybersecurity/
October is Cybersecurity Awareness Month. The 2025 theme is “Building a Cyber Strong America,” highlighting the need to strengthen the country’s infrastructure against cyber threats and ensure resilience and security. In recognition of healthcare’s rising threat profile and the urgent need to shore up cybersecurity industry-wide, the EHR Association shares the following statement:
Cybersecurity Awareness Month is an ideal opportunity to highlight the healthcare industry’s unique security risks, in particular the dual threat we collectively face from the highly valuable patient data held in our health IT systems, as well as the critical dependencies that directly impact patient care. Health data is a top target for nefarious actors, and a single cyber incident can cause lasting harm by disrupting operations, delaying treatments, and jeopardizing lives. To reduce the industry’s risk profile, the EHR Association advocates for stronger protections and realistic, risk-based implementations of security safeguards that enhance resilience without overwhelming resource-constrained hospitals, health systems, and other provider organizations.
– EHR Association Privacy & Security Workgroup
Posted by EHR Association on October 1, 2025
https://ehrablog.org/2025/10/01/ehra-statement-on-2025-cybersecurity-awareness-month/
By the EHR Association Privacy & Security Workgroup
This three-part blog series shares the EHR Association’s stance on OCR’s proposed changes to the HIPAA Security Rule. Part one focused on our overarching concerns and issues with proposed definitions. Part two and this installment highlight our concerns with OCR’s proposed expectations.
The HIPAA Security Rule is overdue for modernization, given the rapid pace of technological change and increasing cybersecurity threats. While we support OCR’s intent to strengthen protections for electronic protected health information (ePHI), our analysis of the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information raised concerns and questions we hope will be addressed before finalization.
(more…)
Posted by EHR Association on May 9, 2025
https://ehrablog.org/2025/05/09/hipaa-security-rule-part-three-risk-based-and-industry-aligned-approaches-recommended/