HIPAA Security Rule Update — Proposed Rule with AI Provisions
United States (Federal) | HIPAA Security Rule NPRM (RIN 0945-AA22)
Categories
Key Requirements
Establishes that ePHI in AI training data, algorithm data, and prediction models maintained by covered entities is protected under HIPAA. Requires entities using AI tools to include them in risk analysis and risk management activities. Would mandate multi-factor authentication, encryption, regular security testing, and 72-hour recovery capability.
Regulated Parties
HIPAA covered entities and business associates using AI to process electronic protected health information (ePHI)
Enforcement
HHS Office for Civil Rights (OCR)
Notes
First significant HIPAA update in over 10 years since the 2013 Omnibus Rule. Status uncertain under deregulatory posture.
Want full access to all legislation details?
Upgrade to a Subscriber plan for unlimited law detail views, the state map, and upcoming effective date tracking.
View Plans