The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, which has been sent to the White House for review.
CIRCIA requires CISA to develop and implement regulations for critical infrastructure entities concerning the reporting of cybersecurity incidents and ransomware payments to CISA. CISA worked with the Sector Risk Management Agencies for each of the 16 critical infrastructure sectors, the Department of Justice, other appropriate federal agencies, and the DHS-chaired Cyber Incident Reporting Council when developing the rule.
CIRCIA covers 16 critical infrastructure sectors, including healthcare and public health (HPH), and will apply to businesses, government entities, contractors, and other entities. The key requirements are for critical infrastructure entities to report cyber incidents to CISA within 72 hours of a determination that a substantial incident has occurred. In the event of a ransomware attack where a ransom is paid, CISA must be notified within 24 hours of the payment being made.
There are thresholds for reporting, which are generally based on company size and annual revenue, although they vary from sector to sector. An estimated 316,000 entities will need to comply with the reporting requirements. For the healthcare sector, they include hospitals with 100 or more beds, any critical access hospital regardless of size, any HPH sector entity that exceeds the Small Business Administration size standards, as well as manufacturers of regulated drugs and medical devices.
The reporting requirements will be in addition to the reporting requirements under HIPAA. CISA currently encourages all critical infrastructure entities to voluntarily report cyber incidents and ransom payments; however, mandatory reporting is necessary to allow CISA to effectively track cyber trends across critical infrastructure sectors, deploy resources to assist victims, and warn other entities about attacks and techniques in time for them to take action to prevent attacks or mitigate harm from a successful attack.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy CISA’s Notice of Proposed Rulemaking (NPRM) was published on April 4, 2024, followed by a 30-day comment period that was extended in response to comments from industry groups due to the length and complexity of the rule.
CISA received a significant volume of comments from stakeholders and the public on the proposed rule, including substantial criticism due to its broad scope and overlap with existing reporting requirements. While the initial target was an October 2025 release of a final rule, the release date was extended to May 2026, and again to September 2026. CISA has held town hall meetings, and the final rule has now been sent to the Office of Management and Budget for review.
A final rule is expected to be published before the end of the year. The post CISA Sends CIRCIA Final Rule for White House Review appeared first on The HIPAA Journal .
Originally published at hipaajournal.com


