I'm Mary Ann Kolbasek McGee, executive editor at Information Security Media Group. Today I'm speaking with Attorney Betsy Hodge, a partner of the law firm, Acermann. We're going to be discussing state digital health law and regulatory trends. So Betsy, when you look out at the health, data, security, and privacy law landscape, what are you keeping your eye on right now as it pertains to new or pending state laws and regulations and why?
That's a great question. There is so much to be keeping track of right now, Mary Ann, as I'm sure you're aware, I'm looking at the continuing proliferation of state consumer privacy laws to see how they affect healthcare organizations, even though many of those laws have either data level or entity level exemptions for HIPAA covered entity and business associates. Those covered entities and business associates also have personal information that's subject to those general consumer privacy laws. And there are a number of companies in the health data space that are not subject to HIPAA that have to comply with these consumer privacy laws.
On top of that now, we're seeing the next evolution with consumer health data privacy laws, such as Washington's My Health, My Data Act, and we expect the trends with states and privacy laws directed to consumer health information to continue. And then of course, we can't forget regulations and laws with respect to AI and also cybersecurity. States are getting involved with regulating cybersecurity practices for entities in the healthcare space. So there's a lot going on right now.
So Betsy, when it comes to the states that appear to be most aggressive in the efforts to push cybersecurity improvements by hospitals and healthcare entities, what are you seeing? What states tend to be most aggressive right now in that area and why? California, because in that state has a long history of promulgating cybersecurity best practices for all types of businesses, going back to when the current vice president was the attorney general of California. For example, California recently made revisions to its the California Medical Information Act to prohibit pharmacies and other healthcare companies from providing patient information to most law enforcement agencies without a warrant or patient authorization.
And then they're also requiring pharmacies to store and maintain information related to gender-affirming care, abortion and abortion-related services and contraception to segregate that information to protect it. And California, the legislature is back in session and they have a number of AI-related laws that they're looking at. Another state that I'm looking at is New York and the proposed cybersecurity regulations for hospitals that the New York State Department of Health has proposed. It will be interesting to see what the final version of those regulations look like and whether other states will model cybersecurity requirements for hospitals and other healthcare entities based on what New York ultimately puts into effect.
So those are probably due to the primary states I'm looking at. Also, it will be interesting to see how the Washington My Health My Data Act gets enforced in the future. So those are probably the three that I'm looking at right now. Let's see, you mentioned New York's proposed cyber regulations for hospitals and then earlier this year, the US Department of Health and Human Services also said it would likely propose new regulations that would require most hospitals to implement so-called essential and enhanced cybersecurity performance goals.
If HHS does finalize such regulations, how might that potentially compare in contrast with what states are doing in this area? For instance, you mentioned New York. What might we see? You mentioned that it'd be interesting to see if other states kind of follow New York state's need in some of these proposals, but what happens if HHS finalizes such regulations, you think?
That's an interesting question, Mary Ann, because one noticeable requirement in the New York proposed regulations as they exist today and the comment period closed, I believe, July 1. New York is proposing a 72-hour reporting requirement in the event of a cybersecurity incident. This is similar to the requirements that other New York regulators have put into place with respect to companies in the financial services industry, the insurance industry, etc. Obviously 72 hours is a much shorter timeline than what covered entities and business associates have under HIPAA, where you have 60 calendar days from discovery of the breach.
So that's going to make things interesting and challenging for those hospitals in New York. Another consideration is whether the states and their regulations decide to be more prescriptive and more detailed than what HHS may do, even when it updates the security rule, or even when CMS actually proposes cybersecurity requirements on hospitals that participate in Medicare and Medicaid. So I think we may see, similar to what we're seeing in the privacy sphere, with respect to cybersecurity, you may have these competing requirements, making it challenging for healthcare organizations to navigate the various state and federal requirements. So another thing to look at is going forward will OCR or HHS OCR, when it updates the security rule, will it keep the security rule as scalable and flexible as it has been?
And I think as you noted, when HHS published the cybersecurity performance goals, there was some messaging that where currently performance goals may become performance requirements and some of those goals are more specific and prescriptive than the current requirements in the security rule. It will be interesting to see what approach HHS takes with that and then what impact that will have on the covered entities and business associates who may now have to meet multiple cybersecurity requirements. So now Betsy, you mentioned various cybersecurity-related issues from the state and the federal level that you're watching. You also mentioned AI in healthcare, and as we know, that's sort of a hot topic right now.
What are you watching in terms of regulatory and perhaps new laws related to AI? I'm looking to see who's going to take the lead with respect to regulating AI. And as I mentioned before, California currently has several bills pending in the legislature addressing AI, not necessarily specific to healthcare, but some of those bills will affect healthcare entities and their use of AI and what they might be required to disclose in the interest of transparency. So will the regulations come from the states?
Oh, and then of course we know that Utah has, Utah and Colorado have passed AI bills. So will the states be leading the charge or will Congress and HHS, we all know that HHS has promoted the faves principles, that AI be fair, appropriate, valid, effective, and safe, but right now those are principles and don't have the force of law. So we're waiting to see what happens at the federal level, and given that we are close to an election, it seems doubtful that there will be much activity at the federal level yet this year. So I'm looking at that to see who's taking the lead.
So let's see, as you know, many of the largest cyber attacks and breaches that we see in healthcare have involved have a business associate with other third party vendors. What advice do you have to cover entities to be better prepared to deal with these third party incidents? How can they stay ahead of potentially becoming effective of a third party breach or cyber attack or major disruption? Any key advice?
That's a great question and it's becoming more challenging, but I would suggest that covered entities and even business associates look at who their key vendors are, who are the vendors that must continue to operate in order for either the business associate or the covered entity to continue to operate, and think about building in some redundancy for those services. So perhaps contracting, instead of having just one vendor who provides a particular mission critical service, you contract with two or three, perhaps having one as a backup in case one of the primary vendors has an incident and is not able to deliver services. And it's always best to be able to identify those backup or alternate vendors before something happens rather than trying to negotiate a contract while you're in the midst of dealing with a critical issue with one of your vendors and negotiating with someone else. That's not the best time to engage in those discussions with vendors.
And then again, going back to the basics and making sure you conduct a risk analysis periodically. And as part of the risk analysis, think about the mission critical functions and those vendors and what are the risks to those vendors? What are the risks to the organization if those vendors have an issue and can't perform the services that you need? And then after you do the risk analysis, obviously, develop your risk management plan and work at risk management plan to reduce the threats and vulnerabilities and test your business continuity and incident response plans by engaging in tabletop exercises and identify your most critical vendors and perhaps conduct more diligence around their cybersecurity and privacy practices to try to have a better handle on the potential risk and how well that organization would be able to respond if it had an incident that could then affect your organization as well.
And again, you would have to do adopt a risk-based approach to do that. There's no way that any organization could conduct that level of diligence on all its vendors. But if you take the risk-based approach and identify your most critical vendors, I think you would be able to do some more diligence around those vendors. Well, thank you so much, Betsy.
I've been speaking to Attorney Betsy Hodge. I'm Mary-Ann Kolbasak-McGhee of Information Security Media Group. Thanks for joining us.