Health Providers Fret Over Cost of Cybersecurity in Privacy Rule

May 12, 2026, 4:18 PM UTC

An HHS proposal to require hospitals and other healthcare facilities to scale up their patient data security infrastructure is drawing criticism over concerns that it could cost billions to implement.

The US Department of Health and Human Services may soon finalize an update to its Health Insurance Portability and Accountability Act security rule. The change is designed to address increased cyberattacks on the US healthcare system by requiring healthcare providers and their business associates to strengthen cybersecurity protections for patients’ protected health information.

The update would be the HHS’ first major changes to the HIPAA security rule since 2013, when ...

Learn more about Bloomberg Law or Log In to keep reading:

See Breaking News in Context

Bloomberg Law provides trusted coverage of current events enhanced with legal analysis.

Already a subscriber?

Log in to keep reading or access research tools and resources.