Skip to main content

CareScope Watch/Compliance/July 30, 2026

NIST's updated security rule guidance is the practical checklist

NIST Special Publication 800-66r2 maps the HIPAA Security Rule to concrete cybersecurity practices, including risk assessment steps and safeguard selection for organizations without security staff.

Why it matters

It is the closest thing to an official answer when a practice asks what good enough looks like.

What it means for your practice

Use it to structure your risk analysis and to sanity-check what a security vendor is proposing. Cite it in your documentation so a reviewer can follow your reasoning.