NIST Seeking Comment on HIPAA Security Rule Update

Attention! NIST has planned to update the HIPAA Security Rule (SP 800-66). This is an update to Revision 1, which was published in 2008, and will provide current cybersecurity standards around safeguards of ePHI. These updates will include improving the current guide and awareness, uses for the guide, and applications of the guide to systems and information. Additional assistance is requested to help educate users with understanding key terms, enhance awareness of NIST resources relevant to HIPAA, and provide detailed implementation guidance for CE’s, BA’s, and HE’s.

Stakeholders may now provide input for the updates to the Rule through June 15, 2021. If you’d like to provide a comment, please visit the call for comments page. If you’d like to know more about HIPAA, see the introduction to the rule in the newsletters section of the website. Additionally, you may submit all comments to sp800-66@comments@nist.gov if you have constructive feedback for the revised publication. Remember to include “Resource Guide for Implementing the HIPAA Security Rule Call for Comments” exactly as it is written in the subject line. Check out the “call for comments” link for additional information.


See the Newsletters page for the latest content and to subscribe to the regular update, see the About page for information around who DPP is, and check out the Contact page to reach out to DPP with any questions or concerns. These are my thoughts and should not be taken as professional advice simply because you are not paying me for my opinion.

Once you understand how valuable your information is, then you can begin taking steps to keep it private.