NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

CISA Sends CIRCIA Final Rule for White House Review

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, which has been sent to the White House for review. CIRCIA requires CISA to develop and implement regulations for critical infrastructure entities concerning the reporting of cybersecurity incidents and ransomware payments to CISA. CISA worked with the Sector Risk Management Agencies for each of the 16 critical infrastructure sectors, the Department of Justice, other appropriate federal agencies, and the DHS-chaired Cyber Incident Reporting Council when developing the rule.

CIRCIA covers 16 critical infrastructure sectors, including healthcare and public health (HPH), and will apply to businesses, government entities, contractors, and other entities. The key requirements are for critical infrastructure entities to report cyber incidents to CISA within 72 hours of a determination that a substantial incident has occurred. In the event of a ransomware attack where a ransom is paid, CISA must be notified within 24 hours of the payment being made.

There are thresholds for reporting, which are generally based on company size and annual revenue, although they vary from sector to sector. An estimated 316,000 entities will need to comply with the reporting requirements. For the healthcare sector, they include hospitals with 100 or more beds, any critical access hospital regardless of size, any HPH sector entity that exceeds the Small Business Administration size standards, as well as manufacturers of regulated drugs and medical devices. The reporting requirements will be in addition to the reporting requirements under HIPAA.

CISA currently encourages all critical infrastructure entities to voluntarily report cyber incidents and ransom payments; however, mandatory reporting is necessary to allow CISA to effectively track cyber trends across critical infrastructure sectors, deploy resources to assist victims, and warn other entities about attacks and techniques in time for them to take action to prevent attacks or mitigate harm from a successful attack.

CISA’s Notice of Proposed Rulemaking (NPRM) was published on April 4, 2024, followed by a 30-day comment period that was extended in response to comments from industry groups due to the length and complexity of the rule. CISA received a significant volume of comments from stakeholders and the public on the proposed rule, including substantial criticism due to its broad scope and overlap with existing reporting requirements.

While the initial target was an October 2025 release of a final rule, the release date was extended to May 2026, and again to September 2026. CISA has held town hall meetings, and the final rule has now been sent to the Office of Management and Budget for review. A final rule is expected to be published before the end of the year.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist