U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.


We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

Second Draft of “Securing Telehealth Remote Patient Monitoring Ecosystem” (SP 1800-30) is Available for Comment
May 06, 2021

NIST's National Cybersecurity Center of Excellence (NCCoE) has released the second draft of NIST Special Publication (SP) 1800-30, Securing Telehealth Remote Patient Monitoring Ecosystem.

Increasingly, healthcare delivery organizations (HDOs) incorporate telehealth and remote patient monitoring (RPM) as part of a patient’s care regimen. RPM systems may offer convenience and may be cost-effective for patients and HDOs, which promotes increased adoption rates. Without adequate privacy and cybersecurity measures, however, unauthorized individuals may expose sensitive data or disrupt patient monitoring services.

The NCCoE developed a reference architecture that demonstrates how HDOs may use standards-based approaches and commercially available cybersecurity technologies to implement privacy and cybersecurity controls, thereby enhancing the resiliency of the telehealth RPM ecosystem.

After adjudicating all the comments from the first draft, notable adjustments were made to the RPM Practice Guide, including:

  • Adjusted the security and privacy control mapping in accordance with NIST SP 800-53 Revision 5.
  • Enhanced cybersecurity capabilities in the Identity Management and Data Security sections.
  • Updated the final architecture to include secure broadband communication between the patient's home and the telehealth platform provider.
  • Included guidance from NIST’s Cybersecurity for the Internet of Things program on device cybersecurity capabilities and nontechnical supporting capabilities that telehealth platform providers should be aware of in their biometric device acquisition processes.

Share Your Expertise

Please download the document and share your expertise with us to strengthen the guide. The public comment period for the second draft is open now through June 7th, 2021. See the publication details for links to the draft and instructions for submitting comments.

Related Topics

Security and Privacy: general security & privacy

Sectors: healthcare

Created May 06, 2021