On September 26, 2024, the Health Infrastructure Security and Accountability Act was introduced in the U.S. Senate. The bill would amend the Health Insurance Portability and Accountability Act (HIPAA) and direct the U.S. Department of Health and Human Services (HHS) to develop new “mandatory minimum cybersecurity standards for health care providers, health plans, clearinghouses and business associates.” It would further mandate annual cybersecurity audits and stress tests for healthcare entities, with particular waivers for small providers. To fund these new endeavors, the bill would remove fine caps for large corporations, fund the HHS’s oversight through user fees, and allocate $1.3 billion to hospitals for cybersecurity improvements.

HHS has indicated its backing of the bill, with Deputy Secretary Andrea Palm stating, “Clear accountability measures and mandatory cybersecurity requirements for all organizations that hold sensitive data are essential.” At this writing, the American Hospital Association (AHA) has declined to comment on the bill.

One of the bill’s sponsors, Senator Ron Wyden of Oregon, has commented that the bill is necessary because “megacorporations like UnitedHealth are flunking Cybersecurity 101, and American families are suffering as a result.” UnitedHealth’s subsidiary Change Healthcare was subject to one of the largest ransomware attacks in America’s history, leading to significant impacts on patients and healthcare providers. The fallout from this ransomware breach continues to be felt across the healthcare industry.

Given that the bill was introduced as Congress concluded its last day of business until the upcoming election, it is unlikely to progress any further during this legislative session. Moreover, depending upon the outcome of the upcoming election, the bill faces an uncertain future. Nevertheless, the healthcare industry is likely to continue to face pressure to improve its cybersecurity standards, whether voluntarily or through legal mandates.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of John W. Kaveney John W. Kaveney

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory…

Partner, Healthcare and Litigation

John provides legal guidance to healthcare sector clients on a broad variety of topics, including Medicare/Medicaid reimbursement issues, corporate compliance, data privacy and cybersecurity concerns, healthcare provider licensure and medical staffing concerns, involuntary commitment laws, and general healthcare regulatory support. He represents a diverse roster of healthcare entities, including for-profit and nonprofit hospitals and health systems, academic medical centers, individual physicians and physician groups, ambulatory surgery centers, ancillary service providers, medical billing companies, skilled nursing and rehabilitation facilities, behavioral health centers and pharmacies.

John advises on Medicaid reimbursement matters before the New Jersey Division of Medical Assistance and Health Services (DMAHS), which administers the state’s Medicaid programs, and handles Medicare reimbursement disputes, both in New Jersey and in numerous other states, before the federal Provider Reimbursement Review Board (PRRB).

In the area of corporate compliance, John supports clients on matters including the implementation of new, and the assessment and improvement of existing, compliance programs. He assists healthcare clients in navigating compliance audits, internal investigations, and governmental investigations related to compliance issues, including potential violations of the federal Stark Law, Anti-Kickback Statute (AKS), and Civil Monetary Penalties law (CMP). He further provides general guidance concerning compliance and regulatory matters under state and federal healthcare laws.

On issues related to information privacy and cybersecurity at the intersection of healthcare law, John assists providers with issues arising under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). This includes the implementation and assessment of privacy and security policies and procedures to ensure the proper protection and utilization of protected health information (PHI) both by healthcare providers and the business associates with which they contract. In addition, he represents healthcare clients in investigating, reporting, and remediating information breaches and the liability such breaches create under various information privacy and security laws.

John also counsels healthcare providers with professional licensure issues and advises hospitals and health systems regarding their medical staff bylaws and corresponding policies and procedures, as well as assisting with internal investigations of medical staff members and the corresponding disciplinary process. He further provides legal guidance related to New Jersey’s involuntary commitment laws, and provides representation in civil litigation.

John serves as Editor-In-Chief of Healthcare Perspectives, Greenbaum’s blog covering issues of interest to the healthcare industry.

Results may vary depending on your particular facts and legal circumstances.

Contact information:

jkaveney@greenbaumlaw.com | 973.577.1796 | vCard | LinkedIn

For more information visit the Greenbaum, Rowe, Smith & Davis LLP website.