The US Department of Health and Human Services (HHS) has published a proposed rule to overhaul the HIPAA Security Rule, aiming to better protect health data from cybersecurity threats. Changes would enforce stricter standards for healthcare entities in establishing and maintaining defenses, including requiring robust cybersecurity requirements. The suggested revisions would also align the Security Rule with industry best practices such as the NIST Cybersecurity Framework and the EU’s GDPR. Public comments can be submitted until 7 March.

The privacy tension driving the medical data shift nobody wants to talk about
Most people assume their medical data sits in quiet storage, protected by familiar rules. That belief gives a sense of safety, but new research argues


