{"id":11077,"date":"2026-01-23T14:21:24","date_gmt":"2026-01-23T14:21:24","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=11077"},"modified":"2026-01-23T14:21:24","modified_gmt":"2026-01-23T14:21:24","slug":"hhs-watchdog-urges-cyber-governance-overhaul","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=11077","title":{"rendered":"HHS Watchdog Urges Cyber Governance Overhaul"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"generic-article\">\n<p class=\"text-muted\">\n                                            <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/governance-risk-management-c-93\" id=\"asset_topic_1_1\">Governance &amp; Threat Administration<\/a>\n                                                    <\/p>\n<p>                    <span class=\"article-sub-title\">OIG: Gaps in Requirements, Third-Occasion Oversight Put Businesses, Well being Sector at Threat<\/span><br \/>\n                <span class=\"article-byline\"><br \/>\n                                                <a rel=\"nofollow\" target=\"_blank\" class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/marianne-kolbasuk-mcgee-i-626\">Marianne Kolbasuk McGee<\/a> (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.twitter.com\/HealthInfoSec\"><i class=\"fa fa-twitter\"\/>HealthInfoSec<\/a>)                                                    \u2022<br \/>\n                        <span class=\"text-nowrap\">January 22, 2026<\/span> \u00a0 \u00a0 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/hhs-watchdog-urges-cyber-governance-overhaul-a-30588#disqus_thread\"\/><\/span><\/p>\n<figure>\n                <img decoding=\"async\" src=\"https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/articles\/hhs-watchdog-urges-cyber-governance-overhaul-image_large-10-a-30588.jpg\" alt=\"HHS Watchdog Urges Cyber Governance Overhaul\" class=\"img-responsive \"\/><figcaption>The U.S. Division of Well being and Human Providers&#8217; Workplace of Inspector Basic in new studies says the division ought to higher standardize and unify its method to cyber governance. (Picture: HHS)<\/figcaption><\/figure>\n<p>Auditors say the U.S. Division of Well being and Human Providers ought to buttress its potential to reply to cyberthreats by standardizing governance and controls throughout its many divisions &#8211; and in addition do a greater job of overseeing its many contractors and the danger they introduce.<\/p>\n<p><b>See Additionally:<\/b> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/on-demand-nydfs-mfa-compliance-real-world-solutions-for-financial-institutions-a-30428?rf=RAM_SeeAlso\">On-Demand | NYDFS MFA Compliance: Actual-World Options for Monetary Establishments<\/a><\/p>\n<p>A fractured method to cybersecurity with various controls throughout division and packages &#8220;complicate HHS\u2019s preparedness efforts to stop or reply to cybersecurity dangers,&#8221; wrote the HHS Workplace of the Inspector Basic in certainly one of two new <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/oig.hhs.gov\/documents\/tmc\/11444\/FY2025-HHS-OIG-TMC-508.pdf\" target=\"_blank\">studies<\/a> printed this week. <\/p>\n<p>Auditors famous enhancements however stated that efforts to consolidate cybersecurity features &#8220;is usually nonetheless depending on every division and program.&#8221;<\/p>\n<p>As well as, third-party dangers, posed by legions of contractors and different third-party distributors, complicate issues additional. &#8220;Cybersecurity options have to be applied not simply inside the division but additionally by the hundreds of HHS contractors, grantees and different exterior entities,&#8221; auditors wrote. <\/p>\n<p>Auditors additionally included cybersecurity threat administration as a high precedence in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/oig.hhs.gov\/documents\/sar\/11445\/Fall_2025_SAR--508.pdf\" target=\"_blank\">semiannual report<\/a> this week to Congress. A profitable cyberattack may jeopardize departmental operations and in addition doubtlessly compromise the well being and welfare of the people HHS serves.<\/p>\n<p>Improved departmental cybersecurity is a longstanding concern. &#8220;HHS faces persistent cybersecurity threats that exacerbate challenges associated to how the Division makes use of knowledge and expertise important to engaging in its mission,&#8221; auditors underscored in a November 2025 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/oig.hhs.gov\/documents\/audit\/11266\/A-18-24-06111.pdf\" target=\"_blank\">report<\/a> (see: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/inspector-general-flags-security-gap-in-nih-genomics-project-a-30050\"><i>Inspector Basic Flags Safety Hole in NIH Genomics Venture<\/i><\/a>).<\/p>\n<p>Auditors say the present state of cybersecurity at HHS will not be completely the division&#8217;s fault. &#8220;Challenges stay that the division has restricted authorities or sources to handle, together with the business\u2019s reliance on legacy expertise and workforce challenges.&#8221;<\/p>\n<p>Neither do out-of-date laws round cybersecurity and knowledge privateness issues assist issues.<\/p>\n<p>HHS\u2019s potential to implement &#8220;the decades-old HIPAA Privateness Rule and HIPAA Safety Rule &#8211; might not be ample to handle up to date privateness considerations of defending well being info or elevated dangers to the safety of digital protected well being info,&#8221; auditors wrote.<\/p>\n<p> &#8220;Working inside the statutory authorities established by HIPAA in 1996, HHS should adapt as privateness and safety wants evolve.&#8221;<\/p>\n<p>The division&#8217;s Workplace of Civil Rights within the closing days of the Biden administration issued a proposed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/security\/hipaa-security-rule-nprm\/factsheet\/index.html\" target=\"_blank\">overhaul<\/a> to the 20-year-old HIPAA safety rule, and equally within the closing days of the primary Trump administration issued proposed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.hhs.gov\/sites\/default\/files\/hhs-ocr-hipaa-nprm.pdf\" target=\"_blank\">modifications<\/a> to the almost 30-year-old HIPAA Privateness Rule. <\/p>\n<p>Each proposals stay on HHS&#8217; present <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.reginfo.gov\/public\/do\/eAgendaMain?operation=OPERATION_GET_AGENCY_RULE_LIST&amp;currentPub=true&amp;agencyCode=&amp;showStage=active&amp;agencyCd=0900&amp;csrf_token=6A65645ED912AACF7E616EF534C3C1702993E1BEB544400AE191CB2E5E10F62799BCD61E6B842CCAA9D6A9FEDBB2604CE9F6\" target=\"_blank\">regulatory agenda<\/a> however to this point OCR has not publicly disclosed the way it plans to proceed with finalizing both rule (see: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bankinfosecurity.com\/health-data-privacy-cyber-regs-what-to-watch-in-2026-a-30320\"><i>Well being Knowledge Privateness, Cyber Regs: What to Watch in 2026<\/i><\/a>).<\/p>\n<p>An HHS spokesperson stated the division is already addressing most of the points spotlighted within the OIG studies.<\/p>\n<p>&#8220;HHS is streamlining its IT and cybersecurity methods to higher serve the Division and the American folks, modernizing outdated, Biden-era methods, to enhance safety, effectivity and accountability throughout HHS,&#8221; the spokesperson stated.<\/p>\n<\/p><\/div>\n<p><template id="fMNIeeUKo6eUgS03qDOR"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Governance &amp; Threat Administration OIG: Gaps in Requirements, Third-Occasion Oversight Put Businesses, Well being Sector at Threat Marianne Kolbasuk McGee (HealthInfoSec) \u2022 January 22, 2026 \u00a0 \u00a0 The U.S. Division of Well being and Human Providers&#8217; Workplace of Inspector Basic in new studies says the division ought to higher standardize and unify its method to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":11079,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[959,2091,275,7523,1425,7522],"class_list":["post-11077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cyber","tag-governance","tag-hhs","tag-overhaul","tag-urges","tag-watchdog"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11077"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11077\/revisions"}],"predecessor-version":[{"id":11078,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11077\/revisions\/11078"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/11079"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 05:43:33 UTC -->