https://csrc.nist.gov/publications/detail/sp/800-66/rev-2/draft
Comments Due: October 5, 2022 (public comment period is CLOSED)Email Questions to: [[email protected]](mailto: [email protected]?Subject=Comments%20on%20SP%20800-66r2%20initial%20public%20draft)
Planning Note (4/25/2023):
See an update on the revision of NIST SP 800-66.
Author(s)
Jeffrey Marron (NIST)
Announcement
The HIPAA Security Rule specifically focuses on protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI), as defined by the Security Rule. All HIPAA-regulated entities must comply with the requirements of the Security Rule.
This draft update:
- Includes a brief overview of the HIPAA Security Rule
- Provides guidance for regulated entities on assessing and managing risks to ePHI
- Identifies typical activities that a regulated entity might consider implementing as part of an information security program
- Lists additional resources that regulated entities may find useful in implementing the Security Rule
NIST would appreciate feedback on the following questions (from the Note to Reviewers section):
- Do you find the overall organization of the document appropriate? Do you have suggestions for improving the document’s organization?
- Is it helpful to have the Risk Assessment Guidance and Risk Management Guidance sections sequential? Do you have suggestions for improving these sections and/or making them more useful to regulated entities?
- Are there Key Activities, Descriptions, and/or Sample Questions that should be added to or removed from the tables in Section 5? Are there specific techniques, threats, or topics that need to be added to Section 5 as Key Activities, Descriptions, and/or Sample Questions?
- Does the appendix about the National Online Informative References (OLIR) Program help the reader? Is its purpose clear?
- Is Appendix F helpful in its current format? Are there resources that should be added to or removed from the Appendix? Should Appendix F be reorganized in any way? Does the annotation of the resources help? Are there additional suggestions for improving Appendix F?