Over three years ago, the Office for Civil Rights (OCR), began talking about recognized security practices (RSPs) in health information technology. This was in response to a HITech Act amendment in Public Law 116-3218 that required OCR to take into account any recognized security practices Covered Entities and business associates had put in place at least a year prior to a breach or unauthorized disclosure of Protected Health Information (PHI).
Table of contents
- Impact of Recognized Security Practices on HIPAA Investigations
- What are the sources of “Recognized Security Practices”?
- What are some of the common Recognized Security Practices?
- How does OCR apply its findings on the implementation of RSPS to penalty calculations?
- What Action should I take in light of these Developments?
Impact of Recognized Security Practices on HIPAA Investigations
Now, there have been actions taken in the cases of two HIPAA Covered Entities following investigations of unauthorized disclosures. The presence or absence of recognized security practices played a role in determining potential fines levied by OCR. In one case, the covered entity benefited from a finding that it had adequately demonstrated it met the requirements for implementing recognized security practices at least 12 months in advance of the breach of its systems. In the second case, OCR did not find the covered entity had adequately demonstrated compliance with the requirements.
What are the sources of “Recognized Security Practices”?
Right now, there is only guidance (and certainly no actual regulations) on what constitutes recognized security practices. OCR published the below video on the subject of recognized security practices that the law refers to two specific sources of recognized security practices.
- Section 2(c)(15) of the National institute of Standards and Technology Act. This provision describes one of the implementation activities of NIST to include: “on an ongoing basis, facilitate and support the development of a voluntary, consensus-based, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to cost-effectively reduce cyber risks to critical infrastructure.”
- Section 405(d) of the Cybersecurity Act of 2015. This is a list of cybersecurity practices and sub-practices from the Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP) technical volumes. Volume 1 discusses ten cybersecurity practices for small healthcare industry organizations. Volume 2 discusses the same ten cybersecurity practices for medium and large health industry organizations.
There is a third source of recognized security practices: Other programs that address other statutory authorities on cybersecurity recognized by statute or regulation. This category can include specific state laws or regulations. Regardless of the source of practices you are incorporating into your cybersecurity policies and implementing RSPS, be sure to document the source (law, regulation, etc.) your are relying on.
What are some of the common Recognized Security Practices?
There are several ways to summarize the common recognized security practices, but we will mention just a few of them.
- The Office of the Chief Information Officer of the Department of Health and Human Services (HHS) published a fact sheet on the Section 405(d) recommendations for cybersecurity practices mentioned above. The 10 practices detailed in this Fact Sheet include practices tailored to counter some of the current threats (email phishing, ransomware, loss or theft of equipment/data) identified in healthcare today.
- Email protection systems
- Endpoint protection systems
- Access management
- Data protection and Loss prevention
- Asset Management
- Network Management
- Vulnerability Management
- incident Response
- Medical Device Security
- Cybersecurity Policies.
- A second, fairly comprehensive set of recommendations can be found in a crosswalk between the HIPAA Security Rule and the NIST Cybersecurity Framework. This crosswalk also helps in documenting the source of regulations you rely on for your cybersecurity program.
- The third source of recommendations for improving the security of electronic protected health information is the proposed revisions for the Security Rule. The stated intent of the new regulations is to modify the Security Standards for the Protection of Electronic Protected Health Information, aka, the HIPAA Security Rule.
How does OCR apply its findings on the implementation of RSPS to penalty calculations?
As we previously noted, there have been two recent cases of OCR penalties being imposed where the issue of certain Recognized Security Practices was noted.
- The first case involved Providence Medical Institute, a physician group practice in Torrance, California. The OCR investigated three ransomware attacks over a six year period. After calculating a maximum fine of $300,000, OCR reduced the fine by 20%, to $240,000. As part of the process, OCR requested PMI furnish data demonstrating it had RSPs in place for at least 12 months prior to the first breach in 2018. OCR was evidently satisfied that PMI met the burden of proof in this case, and entered the reduction. There was no further information how OCR arrived at the amount or percentage of the reduction in the announcement in October 2024.
A second wrinkle in this case was the lack of requirement for a Corrective Action Plan since PMI paid the penalty. It is possible that covered entities and business associates can avoid paying the penalty and incur greater costs in implementing the CAP.
- The second case involved Children’s Hospital Colorado (CHC) in Aurora, CO, announced in December 2024. Breaches at CHC involved phishing attacks through email, with a multi-factor authentication system being disabled and another breach when an individual responded to a request for authentication for access he had not requested! The OCR did not find that CHC adequately demonstrated it had implemented RSPs at least 12 months in advance of the breach(es).
What Action should I take in light of these Developments?
The OCR provided a short, succinct list of actions to take in publishing the settlement in the CHC case:
Preventing breaches or unauthorized disclosures is not cheap now, and will be more expensive in the future if the new amendments to the HIPAA Security Rule are implemented. But these costs are almost certainly lower than the cost of a breach, with a response to patients, notifications to the OCR and a state attorney general, plus an lengthy investigation and civil money penalties by the OCR!
