decisionhealth Newsletters, Part B News - 2025 Issue 1 (January)
New HIPAA rule makes the ‘addressable’ required, even before it’s finalized
Subscribe or sign in to view the full article.
Article Overview
This article explains a proposed HHS update to the HIPAA Security Rule and why it matters to physician practices, hospitals, business associates, and compliance teams. It covers the agency’s expectations around cybersecurity safeguards, security risk assessment scope, operational planning, and the practical burden of meeting evolving HIPAA security expectations even before the rule is finalized.
Why This Topic Matters
Healthcare organizations need to understand how the proposal may affect current cybersecurity programs, vendor oversight, documentation, and security risk assessment processes. The article is relevant to leaders responsible for HIPAA compliance, privacy, IT security, and business associate management.
Article Sections
-
HHS proposed HIPAA Security Rule update
Introduces the proposed federal update and its focus on cybersecurity expectations for regulated healthcare entities. Discusses the broader context for the rule and why it is being proposed.
-
HHS clarifies what is ‘addressable’
Explains how the proposal addresses the meaning of addressable implementation specifications under HIPAA. Describes how the agency is framing current expectations for regulated entities.
-
Not just new tools
Covers expanded security planning and risk assessment expectations beyond individual safeguards. Summarizes the proposal’s emphasis on resilience, testing, inventories, and contingency planning.
-
BAs’ burden — and yours
Describes how the proposal may affect business associates and the covered entities that work with them. Addresses operational and vendor-management implications raised in the article.
-
Impact of the incoming administration
Reviews commentary on whether a change in administration may alter the timing or scope of finalization. Notes the article’s discussion of policy direction and industry expectations.
-
Takeaway: Get to work
Summarizes the article’s overall message for healthcare organizations preparing for possible security rule changes. Highlights the compliance and operational planning implications discussed by experts.
What You Will Learn
- The general focus of the proposed HIPAA Security Rule update
- How the proposal may affect cybersecurity planning for covered entities and business associates
- The types of operational areas the article says organizations should review
- Why the proposal is being viewed as important even before finalization
- How compliance, privacy, IT, and vendor management teams may be affected
Who Should Read This
- Covered entities
- Business associates
- Physician practice managers
- Health system compliance teams
- Healthcare privacy officers
- IT and cybersecurity leaders
- Healthcare legal counsel
Subscribe or sign in to view the full article.



Quick, Current, Complete - www.findacode.com