Latest News

NIST updates guidance for health care cybersecurity

Written on Jul 28, 2022

The National Institute of Standards and Technology (NIST) has updated its cybersecurity guidance for the health care industry.  

NIST’s new draft publication is designed to help the industry maintain the confidentiality, integrity and availability of electronic protected health information, or ePHI. The term covers a wide range of patient data, including prescriptions, lab results and records of hospital visits and vaccinations.  

Part of HIPAA is the Security Rule, which specifically focuses on protecting ePHI that a health care organization creates, receives, maintains or transmits. NIST does not create regulations to enforce HIPAA, but the revised draft is in keeping with NIST’s mission to provide cybersecurity guidance. NIST’s updated guidance is particularly timely as the U.S. Department of Health and Human Services has noted a rise in cyberattacks affecting health care.  

NIST is seeking comments on the draft publication until Sept. 21, 2022. 

One of the main reasons NIST has developed the revision is to integrate it with other NIST cybersecurity guidance that did not exist when Revision 1 was published in 2008. Since then, NIST has developed its well-known Cybersecurity Framework, and it also has repeatedly updated its collection of Security and Privacy Controls (NIST SP 800-53) that organizations can use to tailor their own risk management approaches. The new HIPAA Security Rule guidance draft makes explicit connections to these and other NIST cybersecurity resources.  

The draft takes into account more than 400 unique responses NIST received to its pre-draft call for comments last year. Marron describes the draft as more of a refresh than an overhaul, as the document’s structure has changed only slightly, but the content has been updated with an increased emphasis on assessment and management of risk to ePHI. Many of the significant changes are implied in the publication’s “Note to Reviewers,” which asks readers for thoughts on specific sections.  

NIST is accepting comments on the draft until Sept. 21, 2022, by email to sp800-66-comments@nist.gov.