HITECH 2024-2025 regulatory pipeline + sectoral application. KEY 2024-2025 INITIATIVES: (a) HIPAA SECURITY RULE NPRM (Notice of Proposed Rulemaking) issued by HHS OCR 27 December 2024 (89 FR 105672) proposing the FIRST MAJOR HIPAA Security Rule modernisation since 2013; comments closed 7 March 2025; potential Final Rule 2025-2026; proposed enhancements include (i) MULTI-FACTOR AUTHENTICATION (MFA) requirement for access to ePHI; (ii) MANDATORY ENCRYPTION of ePHI at rest + in transit (currently 'addressable' standard); (iii) NETWORK SEGMENTATION + ZERO TRUST architecture; (iv) ASSET INVENTORY + technology asset management; (v) RANSOMWARE RESPONSE PROGRAM including written ransomware response procedures; (vi) ANNUAL COMPLIANCE AUDIT + Risk Analysis update; (vii) BUSINESS ASSOCIATE compliance documentation + 24-hour breach reporting to covered entity; (viii) WORKFORCE TRAINING enhancements + specific cybersecurity training; (ix) VULNERABILITY MANAGEMENT + PATCH MANAGEMENT; (x) INCIDENT RESPONSE program enhancements. (b) REPRODUCTIVE HEALTH PRIVACY FINAL RULE (89 FR 16140 of 22 April 2024, effective 25 June 2024): strengthens HIPAA Privacy Rule protections for reproductive health information; prohibits CE/BA from disclosing reproductive health PHI for criminal/civil/administrative investigation or proceeding against individual or person facilitating reproductive care that is lawful under circumstances; requires attestation + tracks ongoing legal challenges including 2024-2025 court cases. (c) ONC ASTP STANDARDS + ROADMAP - ongoing USCDI evolution + FHIR R4 + R5 + R6 implementation + Open APIs + Health IT modules + Information Blocking enforcement + new Disincentives Rule for healthcare providers (2024) + reductions in Medicare reimbursement. (d) HHS RECOGNIZED SECURITY PRACTICES (HSPP) Safe Harbor (HITECH Act Section 13412 amendment, January 2021): HIPAA enforcement leniency for covered entity/BA demonstrating recognized cybersecurity practices implemented for 12+ months prior to breach (NIST CSF + 405d + others). (e) OCR ENFORCEMENT PRIORITIES 2024-2025: ransomware + breach response + RIGHT OF ACCESS INITIATIVE continued + reproductive health + ONC Information Blocking coordination + interoperability + state coordination. (f) HEALTHCARE CYBERSECURITY ATTACK CRISIS - 2024 ransomware attacks on Change Healthcare + Ascension Health + multiple major hospital systems; HHS sectoral cybersecurity guidance + Healthcare and Public Health (HPH) Sector Critical Infrastructure cybersecurity requirements + NIST Healthcare CSF + CISA Health Sector Risk Assessment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.