HHS requests info on cybersecurity practices at health organizations

HHS must consider an organization’s security practices over the year prior to a privacy incident when imposing HIPAA fines.