Big changes are on the horizon for the Health Insurance Portability and Accountability Act (HIPAA) as a major overhaul of its Security Rule is set to take effect in 2025. These updates are expected to present significant challenges for healthcare organizations and their business associates, marking the most transformative change to HIPAA since the HITECH Act of 2008.
Starting in early 2025, the Department of Defense (DoD) will include new contracting requirements for contractors to comply with the Cybersecurity Maturity Model Certification 2.0 (CMMC), with all contracts including those requirements by October of 2026. This phased rollout will impact Managed Service Providers (MSPs), data centers, and any organization engaged in the DoD’s supply chain. With the DoD rolling out these new requirements, contractors must prepare to meet these heightened security standards if they wish to continue doing business with the DoD.
As the threat of cyber-attacks grows, so does the need for protection. The U.S. Securities and Exchange Commission (SEC) has begun to do just that as they roll out new rules to protect investors from the material threat of cybersecurity incidents. The rules will require companies registered with the SEC to disclose material cybersecurity incidents and report on their cybersecurity practices to create a standardized approach to how organizations provide reporting.
PCI DSS Transition The PCI Security Standards Council updated the Payment Card Industry Data Security Standard (PCI DSS) on March 31, 2022, to facilitate higher levels of security for cardholder data. As of March 31, 2024, the transition of PCI DSS 3.2.1 to PCI DSS 4.0 went into full effect.