Added Information: NOTICE Use SP 800-66 Rev. 2 (Draft), Implementing the HIPAA Security Rule | CSRC (nist.gov)

NIST is planning to update NIST Special Publication (SP) 800-66, Revision 1, An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (“Resource Guide”). NIST’s cybersecurity resources have evolved since SP 800-66, Revision 1, was published in 2008, and stakeholders will benefit from guidance that includes references to these updated resources.

Details

The list of topics below covers the major areas in which NIST is considering updates, including improvements to the guide and awareness, applications, and uses for the guide. NIST is seeking stakeholder input on the purpose of the Resource Guide to educate readers about information security terms used in the HIPAA Security Rule, amplify awareness of NIST cybersecurity resources relevant to the HIPAA Security Rule, amplify awareness of non-NIST resources relevant to the HIPAA Security Rule, and provide detailed implementation guidance for covered entities and business associates.

Comments received by the deadline will be incorporated to the extent practicable. Once completed, the resulting draft of SP 800-66, Rev. 2, will be provided for public review and comment.

Submitted comments, including attachments and other supporting materials, will become part of the public record and are subject to public disclosure. Personally identifiable information and confidential business information should not be included (e.g., account numbers, Social Security numbers, names of other individuals). Comments that contain profanity, vulgarity, threats, or another inappropriate language will not be posted or considered. 

A. Improvements to An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

The following topics are intended to help NIST learn about experiences in applying and using An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (“Resource Guide”) and explore opportunities for improvement. 

  • Describe what content of the Resource Guide is being used and how you are using it.
  • Describe what components of the Resource Guide have been least useful to you and why.
  • Share any key concepts or topics that you believe are missing from the Resource Guide, including what they are and why they merit special attention.
  • Describe how the Resource Guide can be more useful, relatable, and actionable to a variety of audiences (e.g., small health care providers, health plans, health care clearinghouses, business associates).
  • Describe the potential benefits or challenges experienced when aligning the Resource Guide more closely with other related standards, guidelines, or resources (e.g., the Cybersecurity Framework; NIST SP 800-37, Risk Management Framework for Information Systems and Organizations; NIST SP 800-30, Guide for Conducting Risk Assessments; NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations).
  • Describe which components of the Resource Guide you think are best left as static content that should not change until the next revision and which components could be managed as dynamic content (i.e., require more frequent changes or updates to accommodate new information as it becomes available).
B. Application, Implementation, and Uses of An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

Covered entities and business associates have diverse ways of implementing the HIPAA Security Rule. NIST solicits information about how organizations are implementing the Resource Guide, its application, and its use in practice.

  • Describe any tools, resources, or techniques that your organization currently uses or would like to use to implement the HIPAA Security Rule.
  • Describe how your organization manages compliance and security simultaneously (i.e., how your organization achieves compliance with the HIPAA Security Rule while also improving cybersecurity posture).
  • Describe how your organization assesses risk to ePHI (electronically protected health information) and how this assessment leads to the identification of appropriate security controls/practices.
  • Describe how your organization determines that security measures implemented in accordance with the Security Rule are effective in protecting ePHI and how often your organization initiates a process to determine such effectiveness.
  • If your organization implements recognized security practices,[1] describe how you document the process of demonstrating adequate implementation.
    • Describe how these recognized security practices overlap with and diverge from compliance with the HIPAA Security Rule at your organization.
  • Describe how your organization manages concerns regarding business associates’ compliance with the HIPAA Security Rule. Describe the role that contracts, or other agreements serve in protecting ePHI disclosed to business associates.
  • Describe how your organization facilitates communication—both internal and external to the organization—about HIPAA Security Rule implementation and compliance. 

[1] To amend the Health Information Technology for Economic and Clinical Health Act to require the Secretary of Health and Human Services to consider certain recognized security practices of covered entities and business associates when making certain determinations, and for other purposes, Pub. L. 116-321 (January 5, 2021). Available at https://www.congress.gov/bill/116th-congress/house-bill/7898  

An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

NIST SP 800 6 r1

The HIPAA Security Rule requires all covered entities to protect the EPHI that they use or disclose to business associates, trading partners, or other entities. New technologies, such as remote access and removable media technologies, have significantly simplified the way in which data is transmitted throughout the healthcare industry and created tremendous opportunities for improvements and greater efficiency in the healthcare space. However, these technologies have also increased the risk of loss and unauthorized use and disclosure of this sensitive information. Sensitive information that is accessed by, stored on, or transmitted to or from a remote device needs to be protected so that malicious parties cannot access or alter it. An unauthorized release of sensitive information could damage the trust in an organization, jeopardize its mission, or harm individuals if their personal information has been released. 

In December 2006, CMS issued HIPAA security guidance document, Remote Use of and Access to Electronic Protected Health Information, to reinforce some of the ways a covered entity may protect EPHI when it is accessed or used outside of the organization’s physical purview. It sets forth some strategies that may be reasonable and appropriate under the HIPAA Security Rule, for covered entities to follow (based upon their individual technological capabilities and operational needs), for the offsite use of, or access to, EPHI. This guidance also places significant emphasis on the importance of risk analysis and risk management strategies, policies and procedures, and security awareness and training on the policies and procedures for safeguarding EPHI during its remote access, storage, and transmission.

NIST publications on remote access, storage, and transmission security technologies can be valuable resources to support secure remote use solutions. These publications seek to assist organizations in understanding particular technologies and to provide security considerations and practical, real-world recommendations for implementing and securing these technologies within an organization.

Special Publication 800-114, User’s Guide to Securing External Devices for Telework and Remote Access, was developed to help teleworkers secure the external devices they use for telework, such as personally owned and third-party privately owned desktop and laptop computers and consumer devices (e.g., cell phones, personal digital assistants). The document focuses specifically on security for telework involving remote access to organizations’ nonpublic computing resources by providing:

  • Recommendations for securing telework computers’ operating systems and applications, as well as home networks that the computers use;
  • Basic recommendations for securing consumer devices used for telework; Advice on protecting the information stored on telework computers and removable media; and
  • Advice on protecting the information stored on telework computers and removable media; and
  • Tips on considering the security of a device owned by a third party before deciding whether it should be used for telework.

Special Publication 800-113, Guide to SSL VPNs, assists organizations in understanding SSL VPN technologies and in designing, implementing, configuring, securing, monitoring, and maintaining SSL VPN solutions. This publication intends to help organizations determine how best to deploy SSL VPNs within their specific network environments by:

  • Describing SSL and how it fits within the context of layered network security;
  • Presenting a phased approach to SSL VPN planning and implementation that can help in achieving successful SSL VPN deployments; and
  • Comparing SSL VPN technology with IPsec VPNs and other VPN solutions.

Special Publication 800-77, Guide to IPsec VPNs, assists organizations in mitigating the risks associated with the transmission of sensitive information across networks by providing practical guidelines on implementing security services based on Internet Protocol Security (IPsec). This publication intends to help organizations determine how best to deploy IPsec VPNs within their specific network environments by:

  • Discussing the need for, and types of, network layer security services and how IPsec addresses these services;
  • Providing a phased approach to IPsec planning and implementation that can help in achieving successful IPsec deployments;
  • Providing specific recommendations relating to configuring cryptography for IPsec;
  • Using a case-based approach to show how IPsec can be used to solve common network security issues; and
  • Discussing alternatives to IPsec and under what circumstances each may be appropriate.

Special Publication 800-52, Guidelines for the Selection and Use of Transport Layer Security (TLS), provides guidelines on the selection and implementation of the TLS protocol while making effective use of Federal Information Processing Standards (FIPS)-approved cryptographic algorithms. TLS provides a mechanism to protect sensitive data during electronic dissemination across the Internet. This guideline:

  • Describes the placement of security in each layer of the communications protocol stack, as defined by the OSI Seven Layer Model;
  • Provides criteria for developing specific recommendations when selecting, installing and using transport layer security; and
  • Discusses client implementation, server, and operational considerations.

Special Publication 800-111, Guide to Storage Encryption Technologies for End User Devices, assists organizations in understanding storage encryption technologies for end user devices and in planning, implementing, and maintaining storage encryption solutions. The types of end user devices addressed in this document are personal computers (desktops and laptops), consumer devices (e.g., personal digital assistants, smart phones), and removable storage media (e.g., USB flash drives, memory cards, external hard drives, writeable CDs and DVDs). This publication:

  • Provides an overview of the basic concepts of storage encryption for end user devices;
  • Provides guidelines on commonly used categories of storage encryption techniques (i.e., full disk, volume and virtual disk, and file/folder), and explains the types of protection they provide;
  • Discusses important security elements of a storage encryption deployment, including cryptographic key management and authentication; and
  • Examines several use cases which illustrate multiple ways to meet most storage encryption needs.

Draft Special Publication 800-124, Guidelines on Cell Phone and PDA Security, provides an overview of cell phone and personal digital assistant (PDA) devices in use today and offers insights for making informed information technology security decisions regarding their treatment. This publication:

Presents an overview of handheld devices and discusses associated security threats and technology risks;
Examines the security concerns associated with handheld devices; and

Discusses user- and organization-oriented measures and safeguards available for mitigating the risks and threats.
All NIST publications are accessible on the public Computer Security Resource Center (CSRC) Web site at http://csrc.nist.gov.

Main Menu