Recognized Security Practices Consideration
Recognized Security Practices are cybersecurity measures that a healthcare organization can put in place to help protect health data, such as recognized standards, guidelines, and best practices. Under a 2021 amendment to the HITECH Act, if an organization can show it had these practices in place for a period of time before an incident, HHS may take that into account as a mitigating factor when deciding on enforcement actions or penalties. Having recognized security practices in place does not guarantee HIPAA compliance and does not prevent enforcement; it is one consideration that may reduce potential consequences.
Recognized Security Practices Consideration refers to the mechanism established by Section 13412 of the HITECH Act, as amended in 2021, requiring HHS to take into consideration whether a regulated entity had certain recognized security practices in place when making specified HIPAA Security Rule enforcement determinations. As reflected in the evidence, the amendment adds three enforcement considerations (generally described as affecting matters such as potential penalty amounts and the scope of certain remedies/audits) applicable where the entity can demonstrate the practices were in place for the prior 12 months. The statute defines recognized security practices as including standards, guidelines, best practices, methodologies, procedures, and processes, and a practice must be 'in place' to be considered as a possible mitigating factor. Important limitations: this is a discretionary consideration by HHS OCR, not a safe harbor and not evidence of full HIPAA compliance; the burden of demonstrating that practices were in place rests with the regulated entity; and the specific applicable practices, the 12-month look-back, and the enforcement effects should be verified against the current statutory text and HHS guidance. Practitioners should also note that this consideration applies within HIPAA/HITECH enforcement and does not displace obligations under the Privacy Rule, Breach Notification Rule, state law, or other frameworks.
Why it matters
For healthcare organizations subject to the HIPAA Security Rule, the Recognized Security Practices Consideration created by the 2021 amendment to Section 13412 of the HITECH Act offers a meaningful, if limited, incentive to invest in mature cybersecurity programs. When HHS OCR makes certain enforcement determinations, it is required to take into account whether a regulated entity had recognized security practices in place, which can affect matters such as potential penalty amounts and the scope of certain remedies or audits. In practice, this means the effort an organization puts into adopting recognized standards, guidelines, and best practices before an incident occurs may reduce the potential consequences it faces afterward.
It is critical to understand what this consideration is not. Having recognized security practices in place is not a safe harbor, does not establish full HIPAA compliance, and does not prevent OCR from pursuing enforcement. It is a discretionary mitigating factor, and the burden of demonstrating that the practices were actually in place, generally for the prior 12 months, rests with the regulated entity. An organization that cannot produce evidence of its practices, or that adopted them only after an incident, is unlikely to benefit from this consideration.
Because the consideration applies specifically within HIPAA and HITECH Security Rule enforcement, it does not displace obligations under the Privacy Rule, the Breach Notification Rule, state law, or other frameworks. Organizations should treat recognized security practices as one component of a broader compliance and risk management posture rather than a substitute for one, and should verify the current statutory text and HHS guidance, as the specific applicable practices, the look-back period, and the enforcement effects are subject to change.
Who it's relevant to
Inside RSP
Common questions
Answers to the questions practitioners most commonly ask about RSP.