ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 17941Recognition of security practices

submitted 5 years ago by Pub. L. 111-5 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 452 words · no verdicts yet

in plain englishAI-generated · not legal advice

The Secretary must consider a company's cybersecurity practices when setting fines, audits, or other remedies. Good practices kept in place for a year can lower fines, shorten audits, or ease penalties. Skipping these practices creates no extra liability, and full enforcement of HIPAA's security rule continues.

(a) In general When the Secretary is deciding fines under Social Security Act sections 1320d–5 or 1320d–6, deciding whether to shorten or narrow an audit under section 17940, or agreeing to other remedies, the Secretary must consider whether a covered entity or business associate can show it had "recognized security practices" in place for at least the previous 12 months. Having those practices in place may: (1) reduce fines under section 1320d–5; (2) lead to an early, favorable end to an audit under section 17940; and (3) reduce the remedies the entity or business associate would otherwise have to agree to when resolving a possible violation of the HIPAA Security Rule (45 C.F.R. part 160 and part 164, subparts A and C). (b) Definitions and other rules (1) "Recognized security practices" means the cybersecurity standards, guidelines, best practices, methods, and processes developed under 15 U.S.C. § 272(c)(15), the approaches issued under 6 U.S.C. § 1533(d), and other cybersecurity programs developed or recognized under other laws' regulations. The covered entity or business associate decides for itself which practices count, as long as they're consistent with the HIPAA Security Rule. (2) Limitation: this section does not let the Secretary increase fines, or make an audit longer or bigger, just because an entity failed to use recognized security practices. (3) No liability for not participating: subject to paragraph (4), a covered entity or business associate cannot be held liable simply for choosing not to use recognized security practices. (4) Rule of construction: nothing here limits the Secretary's power to enforce the HIPAA Security Rule, or overrides an entity's or business associate's existing obligations under that rule.
the actual law source: uscode.house.gov ↗public domain
(a) In general

Consistent with the authority of the Secretary under sections 1320d–5 and 1320d–6 of this title, when making determinations relating to fines under such section 1320d–5 (as amended by section 13410 of Pub. L. 111–5) or such section 1320d–6, decreasing the length and extent of an audit under section 17940 of this title, or remedies otherwise agreed to by the Secretary, the Secretary shall consider whether the covered entity or business associate has adequately demonstrated that it had, for not less than the previous 12 months, recognized security practices in place that may—

(1)

mitigate fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5);

(2)

result in the early, favorable termination of an audit under section 17940 of this title; and

(3)

mitigate the remedies that would otherwise be agreed to in any agreement with respect to resolving potential violations of the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title) between the covered entity or business associate and the Department of Health and Human Services.

(b) Definition and miscellaneous provisions
(1) Recognized security practices

The term “recognized security practices” means the standards, guidelines, best practices, methodologies, procedures, and processes developed under section 272(c)(15) of title 15, the approaches promulgated under section 1533(d) of title 6, and other programs and processes that address cybersecurity and that are developed, recognized, or promulgated through regulations under other statutory authorities. Such practices shall be determined by the covered entity or business associate, consistent with the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title).

(2) Limitation

Nothing in this section shall be construed as providing the Secretary authority to increase fines under section 1320d–5 of this title (as amended by section 13410 of Pub. L. 111–5), or the length, extent or quantity of audits under section 17940 of this title, due to a lack of compliance with the recognized security practices.

(3) No liability for nonparticipation

Subject to paragraph (4), nothing in this section shall be construed to subject a covered entity or business associate to liability for electing not to engage in the recognized security practices defined by this section.

(4) Rule of construction

Nothing in this section shall be construed to limit the Secretary’s authority to enforce the HIPAA Security rule (part 160 of title 45 Code of Federal Regulations and subparts A and C of part 164 of such title), or to supersede or conflict with an entity or business associate’s obligations under the HIPAA Security rule.

Source credit: (Pub. L. 111–5, div. A, title XIII, § 13412, as added Pub. L. 116–321, § 1, Jan. 5, 2021, 134 Stat. 5072.)

history & why it existsrecord from the source credit
  • 2021Enacted · Pub. L. 111-5 · 134 Stat. 5072

A history note hasn’t been published yet. The record shows enactment by Pub. L. 111-5 on 2021-01-05.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case