As cyber threats evolve, legal provisions like the Health Insurance Portability and Accountability Act (HIPAA) may not be sufficient to protect healthcare data. Proposed legislation, including the Healthcare Cybersecurity Act and the Health Infrastructure Security and Accountability Act (HISAA), could strengthen protections. However, these fail to address non-traditional health data like fitness tracker information. A more comprehensive approach is required, encompassing consumer health data and collaboration between tech and healthcare companies, as well as robust leadership from CISOs.

OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve alleged violations of the HIPAA


