Recognized Security Practices
Recognized Security Practices are established cybersecurity standards, guidelines, and processes that a healthcare organization can voluntarily adopt to help protect health information. Under a 2021 amendment to the HITECH Act, HHS OCR is required to take an organization's use of these practices into account when it investigates security incidents or determines potential penalties. Adopting them is optional, and an organization generally does not face direct penalties simply for choosing not to implement them.
Recognized Security Practices (RSP), as defined under the 2021 HITECH Act amendment, are the standards, guidelines, best practices, methodologies, procedures, and processes developed under certain statutory authorities, for example, practices developed under the National Institute of Standards and Technology (NIST) framework, among others referenced in the amendment. The amendment requires HHS OCR to consider whether a regulated entity had, in the prior 12 months, adequately demonstrated the use of RSPs when making certain enforcement determinations, including audits, resolution of potential penalties, and mitigation. Implementation of RSPs is voluntary; a regulated entity that elects not to adopt them does not, per the evidence, suffer direct repercussions solely for that choice. Important limitations: RSPs operate as a mitigating factor in the enforcement context and do not amend, replace, or expand the underlying obligations of the HIPAA Security Rule, nor does adopting RSPs by itself establish or guarantee HIPAA compliance. Practitioners should verify the specific enumerated authorities, applicability, and any evidentiary expectations against the current statutory text and OCR guidance, and note that state law or other frameworks may impose additional requirements.
Why it matters
For covered entities and business associates, the practical significance of Recognized Security Practices lies in how they can influence HHS OCR enforcement outcomes. Under the 2021 HITECH Act amendment, OCR is required to consider whether a regulated entity had adequately demonstrated the use of RSPs during the prior 12 months when making certain enforcement determinations, including audits, the resolution of potential penalties, and mitigation. In practice, this means an organization that has invested in and can document its use of established security practices may be positioned more favorably when it is under investigation following a security incident.
At the same time, it is important to understand the limits of what RSPs accomplish. They function as a mitigating factor in the enforcement context; they do not amend, replace, or expand the underlying obligations of the HIPAA Security Rule. Adopting RSPs does not by itself establish or guarantee HIPAA compliance, and an entity still must meet the Security Rule's administrative, physical, and technical safeguard requirements regardless of whether it adopts RSPs. Conversely, implementation is voluntary, and per the available evidence a regulated entity that chooses not to adopt RSPs does not suffer direct repercussions solely for that choice.
Because the value of RSPs is realized largely through documentation and demonstrable use over a trailing period, organizations should treat evidence-keeping as central rather than incidental. The specific enumerated authorities, applicability, and evidentiary expectations should be verified against the current statutory text and OCR guidance, and readers should note that state law or other frameworks may impose additional requirements beyond what the HITECH amendment addresses.
Who it's relevant to
Inside RSP
Common questions
Answers to the questions practitioners most commonly ask about RSP.