Developments in Cybersecurity for Healthcare Providers

Parker Poe Adams & Bernstein LLP
Contact

The Cybersecurity Act of 2015, included in the Omnibus Appropriations and Tax Reform Package adopted into law in December, 2015 (link), specifically addresses cybersecurity in the healthcare industry.

Broadly, the Act (A) establishes the Department of Homeland Security (DHS) as the clearing-house for sharing of cybersecurity threats for the federal government, and (B) provides new rights for network operators (i) to monitor their own  networks for the purpose of protecting the network from attempts at hacking, denial of service attacks and other network weaknesses, and (ii)  to share cyber threat indicators, and related defensive measures, with others.

Section 405 of the Cybersecurity Act specifically addresses cybersecurity in the healthcare industry by:

1.    Requiring the Department of Health and Human Services (DHHS) to develop a report outlining responsibility within DHHS for coordinating efforts regarding cybersecurity threats;
2.    Creating a new healthcare industry cybersecurity task force comprised of healthcare stakeholders, cybersecurity experts and federal agencies with specific assignments, which include (i) analyzing how industries, other than the healthcare industry, have implemented strategies to address cyberliability threats, (ii) analyzing barriers that private healthcare entities face to address cyber attacks, (iii) reviewing challenges to securing networked medical devices of software that connects to an electronic health record, and (iv) developing information to be provided to healthcare providers for purposes of improving preparedness for, and response to, cybersecurity threats;
3.    Requiring DHHS to establish guidelines and best practices that serve as a resource for cost-effectively reducing cyberliability risks consistent with HIPAA and other relevant laws.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Parker Poe Adams & Bernstein LLP | Attorney Advertising

Written by:

Parker Poe Adams & Bernstein LLP
Contact
more
less

Parker Poe Adams & Bernstein LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide