Blog: HHS Releases Crosswalk Between HIPAA Security Rule and NIST Framework

Cooley LLP
Contact

The U.S. Department of Health and Human Services (HHS), Office of Civil Rights (OCR)  recently released a “crosswalk” developed with the National Institute of Standards and Technology (NIST) mapping  the Health Insurance Portability and Accountability Act (HIPAA) Security Rule and the NIST Framework for Improving Critical infrastructure Cybersecurity (the Framework).  This crosswalk was developed in order to assist healthcare organizations improve cybersecurity preparedness by using the Framework as a common language.  The crosswalk also includes mappings to other commonly used security frameworks.

The NIST Framework was released in 2014 in order to provide a voluntary framework to assist companies in reducing cyber risks to critical infrastructure.  This Framework has been voluntarily adopted as the standard for companies to follow when evaluating cybersecurity issues across various industries, including the healthcare industry.  Companies subject to HIPAA must implement strong security safeguards to comply with the HIPAA Security Rule and many have adopted the NIST Framework to do so.

This crosswalk should can as a tool for covered entities and business associates to evaluate potential gaps in HIPAA compliance and steps necessary to achieve compliance with  HIPAA obligations.   While the HIPAA Security Rule does not mandate use of the NIST Framework nor does compliance with the NIST Framework guarantee HIPAA compliance, the crosswalk allows companies to identify and manage security risks in a comprehensive way.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Cooley LLP | Attorney Advertising

Written by:

Cooley LLP
Contact
more
less

Cooley LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide