HIPAA Security Rule Part One: Proposed Overhaul Closes Some Gaps, Opens Others

By the EHR Association Privacy & Security Workgroup

This three-part blog series shares the EHR Association’s stance on OCR’s proposed changes to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information. Part one is focused on our overarching concerns and issues with proposed definitions.

Proposed changes to the existing HIPAA Security Rule, released as HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, include some long-overdue updates. However, the resources and costs required by healthcare provider organizations, health IT developers, and other regulated entities to comply with the sweeping changes will be too great for many to bear.

That was one of several important messages we shared with the HHS Office of Civil Rights (OCR) in our comment letter on the proposed rule

(more…)

Finding the Right Balance: Smart Deregulation in Health IT

by Leigh Burchell (Altera Digital Health), Chair, EHR Association Executive Committee

The current administration has made deregulation a central policy priority, aiming to reduce burden and costs in as many sectors of the economy as possible, including health care. This is exemplified by the January 2025 Executive Order 14192: Unleashing Prosperity Through Deregulation, which requires federal agencies to eliminate ten regulations for each new one introduced. 

As the trade association for health IT developers, we believe that smart deregulation should focus on removing outdated, redundant, and low-value requirements with ASTP/ONC and CMS playing a role more focused on driving improvements in standardized interoperability and health data exchange. Health IT regulation should support—not hinder—the industry’s collective ability to deliver safe, effective, and innovative technology solutions, without compromising the progress made or devaluing the investments in health IT over the last fifteen years. As always, we remain committed to working alongside federal agencies within the construct of a regulatory environment that benefits providers, developers, and—most importantly—patients.

(more…)
  • Categories

  • Follow EHRA on Twitter

  • Enter your email address to follow this blog and receive notifications of new posts by email.

    Join 198 other subscribers
  • Contact Us

    Kasey Nicholoff
    staff @ ehra.org

    Amanda Patanow
    Communications and Media
    ehracomms @ npccs.com