1. Home
  2. |Insights
  3. |NIST HIPAA Security Rule Guidance

NIST HIPAA Security Rule Guidance

Client Alert | less than 1 min read | 12.04.08

The Department of Commerce's National Institute of Standards and Technology has published a set of detailed guidance materials to serve as a framework for complying with the HIPAA security rules. The guidance includes checklists for compliance requirements, a glossary, cross references to standards and definitions, and a table of prior NIST published standards on security in various types of situations. Click here to download "An Introductory Resource Guide for Implementing the Health Insurance Portability and Accoutability Act (HIPAA) Security Rule" [PDF] from csrc.nist.gov.

Insights

Client Alert | 8 min read | 10.01.25

BIS Issues “Affiliates Rule” to Dramatically Expand Applicability of Entity and Military End-User Lists

On September 29, 2025, the U.S. Department of Commerce Bureau of Industry and Security (BIS) announced a sweeping Interim Final Rule (IFR), (the “Affiliates Rule”) expanding which entities qualify as Entity List or Military End-User entities, thereby subjecting those entities to elevated export control restrictions under the Export Administration Regulations (EAR). U.S. export restrictions applicable to entities on the Entity List, Military End-User (MEU) List, and Specially Designated Nationals and Blocked Persons (SDN List) now apply to foreign affiliates that are, in the aggregate, owned 50% or more by one or more of the aforementioned entities. An entity that becomes subject to these restrictions because of its ownership structure will be subject to the most restrictive controls that attach to any of its parent entities, regardless of ownership stakes....