CHIME Policy Update: Healthcare IT Issues
- Smaller, rural hospitals are increasingly vulnerable to refined cyberattacks, facing challenges amplified by a complex regulatory landscape.
- Savickis described the situation as challenging, citing regulatory uncertainty and potential budget cuts to federal cybersecurity initiatives.
- Beyond funding, Savickis emphasized the need for practical assistance, as many providers lack the personnel to implement basic cyber hygiene.
CHIME‘s latest policy update spotlights critical healthcare IT issues. Smaller rural hospitals face mounting cybersecurity threats and HIPAA compliance challenges, often lacking resources, personnel, and struggling with regulatory burdens. The proposed HIPAA Security Rule revisions, contested by CHIME, could escalate costs and documentation demands. Moreover, the integration of AI introduces a new dimension, simultaneously boosting cyber defenses and empowering threat actors. CHIME is actively exploring policy solutions, advocating for practical assistance and urging health IT leaders to engage with policymakers. News Directory 3 brings you the essential details. Discover what’s next for healthcare IT as the landscape continues to evolve.
Rural Hospitals Grapple wiht Cybersecurity, HIPAA Compliance
Updated June 4, 2025
Smaller, rural hospitals are increasingly vulnerable to refined cyberattacks, facing challenges amplified by a complex regulatory landscape. Mari Savickis, vice president of public policy at CHIME, notes these hospitals frequently enough lack the resources for adequate cybersecurity.
Savickis described the situation as challenging, citing regulatory uncertainty and potential budget cuts to federal cybersecurity initiatives. Reports from Microsoft and the Health Sector Coordinating Council (HSCC) underscore the dire state of cybersecurity in rural healthcare, where workforce shortages, limited funding, and inadequate infrastructure heighten risks.
Beyond funding, Savickis emphasized the need for practical assistance, as many providers lack the personnel to implement basic cyber hygiene. Regulatory ambiguities also hinder the utilization of available exceptions,such as those allowing for the donation of cybersecurity hardware and software.
CHIME is exploring policy options to ease the strain on these facilities, including reducing regulatory burdens. Savickis stated that rural hospitals need the tools, personnel, and policy flexibility to effectively combat cyber threats.
“The rural hospitals—the smalls,as we call them—struggle mightily,” savickis said,emphasizing that these organizations often lack both the financial and human capital to mount adequate cybersecurity defenses.
HIPAA Security Rule Revision
Healthcare IT leaders are also concerned about proposed HIPAA security rule revisions. CHIME opposes the proposal, citing excessive documentation requirements and potentially catastrophic compliance costs. Savickis described the proposal as “seismic,” adding that the documentation alone could overwhelm providers.
Despite initial speculation, the rule remains active. Contentious provisions include those regarding encryption and multifactor authentication, which CHIME believes could necessitate replacing medical devices at a prohibitive cost.
Savickis fears the changes, intended to strengthen protections, may hinder progress by overwhelming providers with administrative tasks. CHIME and the HSCC advocate for a collaborative reassessment of the rule.
“This isn’t the rule that we think will work,” Savickis said. “It was a missed chance.”
AI and Cybersecurity
The role of AI further complicates cybersecurity challenges. While AI can enhance defenses, it also empowers adversaries to launch more sophisticated attacks. Savickis highlighted the growing concern of help desk impersonation scams, where criminals use AI-generated voices to reroute funds.
Rural hospitals risk falling behind if they cannot adopt AI-powered cybersecurity solutions due to broadband limitations or resource constraints. CHIME is updating its AI principles to emphasize equitable access to technologies that can definitely help close the cybersecurity gap.
“AI can be a force multiplier for good,” Savickis said. “But only if providers can actually use it.”
What’s next
Health IT leaders are urged to remain proactive and engaged with policymakers to ensure evolving regulations align with clinical and operational needs, supporting effective patient care in an ever-changing landscape.
