What a Healthcare Compliance Attorney Heard at the OCR’s HIPAA Security Conference – The HIPAA Journal
The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.
Posted By Jake Dewberry, JD on Sep 22, 2026
I spent two days at the beginning of September at the National Institute of Standards and Technology campus in Gaithersburg, Maryland, at the conference NIST co-hosts with the Office for Civil Rights on HIPAA security. It is a government event held on a federal campus, which keeps it small, and the attendance tends to attract those closest to the work: the people in the room are the ones writing the guidance, enforcing the rules, or responsible for following them. Over two days I heard presentations from and spoke with OCR leadership, with security practitioners, and with the people who carry compliance responsibility inside healthcare organizations.
I went expecting to spend most of my attention on the proposed Security Rule overhaul, which has drawn heavier objection from the healthcare industry than any HIPAA rulemaking in years. OCR Deputy Director Timothy Noonan has previously said the agency received roughly 4,745 comments on it. A great many raised the same point: the proposed requirements would cost too much, and the organizations least able to absorb that cost would be hit hardest.
The agenda over two days covered a lot of ground, and most of it was technical. But OCR’s own sessions kept coming back to a requirement that is not part of the proposal at all. The risk analysis has been mandatory since 2005, and turns up missing or deficient in nearly every enforcement action the agency brings. That is not news to anyone who has worked through an OCR investigation, but conversations I had between sessions only reinforced it.
So the objection to the proposed rule deserves to be taken seriously, and in part it is correct. But a significant share of it is aimed at obligations that already exist, and the debate over what compliance will cost in 2027 skips past a more immediate problem: many organizations are not meeting the requirements already in place.
Where the rulemaking stands
The proposed rule was published in the Federal Register on January 6, 2025, at 90 FR 898. The comment period closed on March 7, 2025. The rulemaking remains on the Unified Agenda as a long-term action. OCR Director Paula Stannard clarified the expected timing in her keynote: final action anticipated in July of 2027. That date is worth understanding correctly. It is the point by which OCR currently projects taking its next formal action, not necessarily a publication date for a final rule. What form the rule takes when it arrives is not yet knowable, but the direction is.
A proposed rule is the agency telling the industry where it believes the standard needs to be. The changes are not arbitrary additions and are a reflection of what OCR keeps finding when it investigates. Whatever the final text says, that is where this is heading, and an organization waiting for the date before it begins risks starting from further behind.
OCR did not back away from the reasoning behind the changes. Director Stannard tied them to the increase in large breaches and cyberattacks and to the deficiencies the agency keeps finding in security investigations. She also provided context as to where things stand on the proposed rule changes as comment review is still underway, adding the administration “may have a different view on some of the burdens and benefits of the proposed changes.” Director Stannard also noted she was limited in what she could say mid-rulemaking, but pointed to the cyber strategy the President released in March. One pillar of that strategy is common-sense regulation: streamlining cyber rules and keeping them agile enough for the private sector to match evolving threats, while recognizing Americans’ right to privacy in their own data. Another pillar is securing critical infrastructure, which includes healthcare. So, how far the requirements go may still change. That they are coming is not really in question..
What “addressable” was always supposed to mean
Under the current Security Rule, each implementation specification is labeled either required or addressable. That distinction has been widely misunderstood, and the misunderstanding is the source of a good deal of the present objection. An addressable specification has never been optional. 45 CFR 164.306(d) sets out what a covered entity must actually do with one. First, assess whether the specification is a reasonable and appropriate safeguard in your environment. If it is, implement it. If it is not, you must document why it is not reasonable and appropriate, and then implement an equivalent alternative measure if an equivalent alternative measure is reasonable and appropriate.
Translation: addressable means you have to achieve the protection. It gives you room to achieve it a different way if your circumstances call for that, provided you write down your reasoning and what you did instead. It does not give you room to skip it. An organization that read “addressable” and concluded “optional” was simply not complying.
OCR has said so directly. In the preamble to the proposed rule, at 90 FR 917, the Department states that it is concerned some regulated entities proceed as if compliance with an addressable implementation specification is optional, describes that interpretation as incorrect, and concludes that compliance with the specifications currently designated as addressable is not and should not be optional. This was a throughline across the OCR sessions in Gaithersburg, and the agency’s frustration with the misreading was evident. That is the context for the proposal to eliminate the required and addressable distinction and make implementation specifications required, with limited specified exceptions. For an organization that has been applying 164.306(d) as written, the change alters the label rather than the obligation.
What is genuinely new, and who it falls on
It would be inaccurate to suggest the proposed rule is only a relabeling exercise. The proposal would add a technology asset inventory and network map, a compliance audit at least every twelve months, vulnerability scanning at least every six months, penetration testing at least every twelve months, multifactor authentication, network segmentation, written procedures to restore certain systems within 72 hours, and annual written verification from business associates. The Department’s own regulatory impact analysis projects roughly $9 billion in first-year costs across the industry.
Several of these are controls the information security field settled on years ago. Multifactor authentication, asset inventories, and routine vulnerability scanning are treated as baseline practice in mature security programs; OCR did not invent them. Multifactor authentication in particular is less a compliance item than a basic security control. An environment protected by a password alone is reachable by an attacker with ordinary tools and a little patience. Adding it where it does not exist costs something, but that cost is small compared to what it prevents.
Others represent real new expenses. Annual penetration testing and network segmentation are meaningful investments for a practice with a handful of providers and an outsourced IT vendor. Obtaining written verification from every business associate each year is a genuine administrative burden for an organization with dozens of vendors and nobody assigned to compliance full time.
The burden would not fall evenly. Larger organizations are more likely to have the baseline controls in place already and to absorb what they do not. The weight lands on the organizations with the least capacity to carry it, which is why the cost objection is not frivolous even where the underlying controls are sound.
Stannard offered the counterweight from the same keynote: the cost of doing nothing. A successful cyberattack, she noted, can cost far more in reputation, ransom, remediation, protections for those whose information was taken, and civil lawsuits from the individuals harmed. A compliance program exists to reduce the odds of an attack succeeding, limit how much is exposed if one does, and change the nature of what follows. OCR is going to ask for documents either way. The difference is whether the investigation is focused on understanding how your safeguards failed or about why you never put any in place..
One requirement nobody is objecting to
45 CFR 164.308(a)(1)(ii)(A) requires a covered entity to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information it holds. The parenthetical beside it in the regulation reads “Required” and it has read that way since April 2005.
OCR has been unambiguous about its role. The agency requests a risk analysis in every Security Rule investigation it conducts, and it remains among the most commonly deficient documents organizations produce. OCR has also drawn a distinction that catches many programs off guard: a gap analysis, which compares current practice against a checklist, does not satisfy this requirement. Tim Noonan made the point from the podium by comparing a screwdriver to a hammer: both are useful, and neither substitutes for the other.
Nick Heesters, OCR’s Senior Advisor for Cybersecurity, restated the standard in three parts. A sufficient risk analysis addresses risk to electronic protected health information as it is created or enters the organization, as it moves within the organization, and as it leaves. The session made concrete what failure at each stage looks like. In one investigation OCR described, an organization certified that a system held no ePHI, so its web server logs went unprotected by design. A patient-facing form on that system crashed under certain inputs and dumped everything it was processing into those logs, where an attacker eventually found it. Nobody had asked where the data actually went. That is the question the risk analysis exists to answer.
The enforcement record reflects this as well. OCR’s settlements with OSF HealthCare for $552,250, with the Spencer Gifts group health plan for $450,000, and with the Star Group health benefits plan for $245,000 each followed a ransomware incident, and each cited a failure to conduct an accurate and thorough risk analysis. In the investigations I have supported, the risk analysis is among the first documents requested, and what it reveals about the rest of the program is usually apparent before anything else is reviewed.
On the second day, NIST reviewed its work on post-quantum cryptography, a federal effort to protect data against a decryption capability that does not exist yet, on a timeline running to 2035. That is the horizon they are planning against. The concern is that an industry that has not met a twenty-year-old requirement asking it to document where its data lives has no realistic path to what comes after.
What to do today
If you take one action after reading this, make it the risk analysis.
If your organization has completed a risk analysis, consider whether it meets the standard: accurate, thorough, current, and covering ePHI at every stage and not just related to the electronic health record.
If your organization has not completed a risk analysis, or has not completed one within the past year, that is where to start. Not because a new rule is coming, but because the requirement is in force today and has been for twenty years.
The exercise costs less than avoiding it. You may find your controls are sound, in which case you now hold documentation that demonstrates your protection was deliberate. You may find gaps, in which case you know what they are and can work through them in order of severity. Either outcome leaves you in a materially better position.
I spent two days listening to people’s plans for the next decade, and my key takeaway is this: to be prepared to defend against future challenges assumes the ability to defend against current ones. The distance between where most organizations are and where they will need to be is widening. There is room to argue about what the final rule should require, and some of those arguments have merit. What there is no argument about is what the rule requires today. Now is the time to get caught up.
Author: Jake Dewberry is President and Chief Legal Officer for Abyde, the leading HIPAA compliance software company that helps medical practices simplify HIPAA, OSHA, and other regulatory requirements through automated software compliance tools and ongoing support. Jake is a healthcare compliance professional with more than a decade of experience in the healthcare industry. As Chief Legal Officer at Abyde, he advises healthcare organizations on regulatory compliance, privacy, and risk management, with a particular focus on HIPAA and OSHA requirements. A graduate of Western Michigan University Cooley Law School and Auburn University, Jake is also recognized for his commitment to public service and access to justice. In 2026, he received The Florida Bar’s President’s Pro Bono Service Award for the Sixth Judicial Circuit in recognition of his work supporting children in foster care.
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The HIPAA Journal is the leading source of information on the Health Insurance Portability and Accountability Act (HIPAA), providing the best-available HIPAA Training and news coverage of regulatory developments, enforcement actions, data breaches, and best practices for compliance. The HIPAA Journal’s HIPAA training is produced by a team of HIPAA experts, each with over a decade of expertise, who are deeply committed to high-quality HIPAA education.
Subscribe To Weekly
News Digest
HIPAA News
Regulatory Changes
Breach News
HITECH News
HIPAA Advice
Unsubscribe Anytime
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
The Administrative Requirements of the Privacy Rule (§164.530) requires covered entities to train all members of their workforces on the policies and procedures developed to comply with the Privacy and Breach Notification Rules. Naturally, the sooner training is provided, the less chance there is of an inadvertent impermissible disclosure due to a lack of knowledge. It is important to note that training must be provided even if a new member of the workforce has held a similar role in a previous position and that some states have mandatory time frames within which training must be provided (for example, in Texas, training must be provided within 90 days).
It is necessary to prove the breach notification requirements are complied with to ensure covered entities and business associates do not overlook notifying individuals in the required timeframe when submitting an annual breach report to HHS’ Office for Civil Rights for breaches affecting fewer than 500 individuals. Some organizations have delayed notifying individuals about data breaches, increasing the risk of individuals’ data being used to commit identity theft or fraud before individuals have the opportunity to protect themselves from such events. The burden of proof standard mitigates the likelihood of individuals being overlooked.
While many types of impermissible uses and disclosures, data thefts, and unauthorized access events are clearly notifiable breaches, there are also many types that are not. If it can be determined that an impermissible use or disclosure does not qualify as a notifiable breach by using the exclusion criteria in §164.402, it will not be necessary to comply with the breach notification requirements – saving organizations time and money, and a potential compliance review by HHS’ Office for Civil Rights.
Although it is not a requirement of HIPAA to provide an anonymous reporting channel, members of the workforce should be encouraged to speak out when they believe a violation of HIPAA has occurred in order that the incident can be investigated and corrected if necessary. It is felt (although cannot not proven) that anonymous reporting channels generate more reports because members of the workforce feel protected against retaliation. However, if an anonymous reporting channel is provided, it needs to be used in compliance with HIPAA, and any PHI contained within the anonymous report has to be safeguarded against unauthorized access, loss, and theft.
It is necessary to monitor business associate compliance because a covered entity can be held liable for a violation of HIPAA by a business associate if the covered entity “knew, or by exercising reasonable diligence, should have known” of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate’s obligations under the HIPAA Business Associate Agreement.
It is important to execute HIPAA-compliant Agreements with business associates because if an Agreement does not comply with the relevant standards it is invalid. If an Agreement is invalid, covered entities are not permitted to disclose PHI to the business associate, and any disclosure of this nature would represent a violation of HIPAA.
It is important to identify partners and vendors that qualify as business associates because when a service is provided for or on behalf of a covered entity that involves the creation, receipt, maintenance, or transmission of PHI, a HIPAA Business Associate Agreement has to be entered into which stipulates the permitted uses and disclosures of PHI by the business associate, both parties’ compliance obligations, and other terms that may apply.
There are many examples of when it may be necessary to retrieve documentation within a specific timeframe to comply with HIPAA. The most common is when an individual requests access to their PHI maintained in a designated record set. Less common examples include when an individual wishes to revoke an authorization or when HHS’ Office for Civil Rights requests documentation to resolve a HIPAA complaint. In most cases, the documentation has to be provided within 30 days.
The application of sanctions is important to ensure members of the workforce do not take compliance shortcuts “to get the job done”, and the shortcuts deteriorate into a culture of non-compliance. The sanctions applied should be relevant to the nature of the violation. For example, a verbal warning and/or refresher training may be appropriate for a minor violation, while repeated or more serious violations should attract harsher sanctions. The application of sanctions must be documented and records stored for at least 6 years, either physically in paper records or with HIPAA compliance software.
It is important for organizations to monitor changes to transaction code systems for two reasons. The first is that using out-of-date transaction codes can result in delays to (for example) authorizations and payments. The second reason is that organizations who persistently use out-of-date transaction codes can be reported to CMS – which has the authority to enforce Part 162 of HIPAA via corrective action plans and financial penalties.
The National Provider Identifier identifies your organization or subparts of your organization in Part 162 transactions. It is important that NPIs are used correctly in (for example) eligibility checks and authorization requests to prevent delays in responses to requests for treatment. It is also important that NPIs are used correctly in claims and billing transactions to make sure payments are received on time.
Automatic logoff capabilities are important to prevent unauthorized users from accessing ePHI when a device is unattended. Additionally, if a device is lost or stolen, the device cannot be used to access ePHI without the login credentials being known and used.
It is important that login credentials and passwords are not shared for systems that contain ePHI because, if multiple users are using the same access credentials, it will be impossible to determine when specific users access ePHI. As well as eliminating the usefulness of audit logs and access reports, if a system has been configured to reject multiple logins using the same credentials, it could result in users being blocked from accessing ePHI when necessary, or the system being corrupted.
The requirements to implement and test a data backup plan, an emergency mode operations plan, and a disaster recovery plan fall within the contingency plan standard of the Security Rule (§164.308). These requirements are designed to ensure the integrity and availability of ePHI in the event of a natural or manmade disaster.
Information access policies should make sure that the right people have access to the right level of ePHI at the right time. This means the policies have to be sufficiently flexible to support changing roles, promotions, and time off due to (for example) a suspension or maternity leave. The policies should also include procedures for terminating access to ePHI when a member of the workforce leaves so the departing individual cannot access the organization’s ePHI remotely.
The requirement to have a security management process is the first standard in the HIPAA Security Rule’s Administrative Safeguards. The process must consist of at least a risk analysis, an actioned remediation plan, a sanctions policy, and procedures to regularly review information system activity. All analyses, remediation plans, sanctions, and reviews must be documented. Documentation must be stored for at least 6 years, either physically on paper on via HIPAA compliance software.
HIPAA Authorization Forms have to comply with §164.508 in order to be valid. If a HIPAA Authorization Form lacks the core elements or required statements, if it is difficult for the individual to understand, or if it is completed incorrectly, the authorization will be invalid and any subsequent use or disclosure of PHI made on the reliance of the authorization will be impermissible. For this reason, members of the workforce responsible for obtaining valid authorizations must be trained on the implementation specifications of this standard. HIPAA Authorization Forms must be stored for a minimum of 6 years.
A HIPAA Notice of Privacy Practices advises patients and plan members of their privacy rights, how the organization can use or disclose PHI, and how an individual can complain if they believe their privacy rights have been violated or their PHI has been used or disclosed impermissibly. Notices must be reviewed and amended as necessary whenever a material change affects either an individual’s rights or how PHI can be used or disclosed. They must then be re-distributed and/or re-displayed in accordance with §164.520.
Members of the workforce must know how to respond to patient access and accounting requests – even if it is to direct the request to the HIPAA Privacy Officer – because the primary reason for complaints to HHS’ Office for Civil Rights in recent years has been the failure to respond in the time allowed with the information requested. At present, the majority of HIPAA enforcement activities focus on non-compliance with the patients’ rights standards of the HIPAA Privacy Rule.
The reason it is necessary to have procedures in place to respond to patients exercising their HIPAA rights is that some rights are susceptible to exploitation. For example, procedures should be in place to verify the identity of patients, review confidentiality requests, and determine if a request is being made to support an abusive, deceptive, or harmful activity.
The minimum necessary standard (§164.502(b) and §164.512(d)) requires that only the minimum necessary information is used or disclosed to achieve the purpose of the use or disclosure. This is to better protect the privacy of individually identifiable health information. However, the standard does not apply in every circumstance, and covered entities that apply the standard too rigidly could encounter communication challenges or, in some cases, be in violation of other HIPAA regulations.
The healthcare sector and healthcare records in particular is often targeted by hackers due to the billing details contained in medical records and ransomware value of the personal information in Protected Health Information. Email is one of the most common attack vectors. It is important healthcare staff know how to identify malicious software and phishing emails because the detection capabilities of security software are often limited to how the software is configured and how frequently it is updated. Even the best security software can allow threats to evade detection and, when this happens, users need to be able to identify the threat and report it so other users do not (for example) open a malicious attachment or interact with a phishing email.
It is important that all members of the workforce receive ongoing security awareness training for two reasons. The first reason – that training is provided to all members of the workforce – is because an attacker can infiltrate a network via a device that does not have access to electronic PHI, and then move laterally through the network until they find a healthcare database to attack. The second reason – that training must be ongoing – is due to the evolving nature of cyberthreats. Members of the workforce must be informed about the latest threats, how to recognize them, and how to report them.
The documentation and record keeping of every HIPAA training session is important for two reasons – so that covered entities can keep up to date with which members of the workforce have received what training in the event of transfers or promotions, and so that covered entities can demonstrate the training has been provided in the event of an OCR compliance investigation. Workforce attestation is also required by some state laws with more stringent privacy protections than HIPAA.
The provision of refresher training when there is a material change to policies and procedures is necessary to ensure all members of the workforce affected by the change are made aware of it. Refresher training only has to be provided to those the change affects; but, if the training relates to a change in HIPAA policies and procedures, the training must be documented and – where required by state law – attested to by those who attend. In addition, it is a best practice to provide annual refresher training to all members of the workforce so that those not directly affected by material changes to policies and procedures are made aware of them.
Although covered entities and business associates have many similar HIPAA compliance obligations, some regulations apply differently to each type of organization depending on the nature of their activities. If you qualify as a covered entity, and you also provide services to other covered entities as a business associate, it will be necessary for you to complete the assessment twice.
Wait… Don’t Leave Empty-Handed!
Get the FREE
HIPAA Compliance
Checklist
The best resource to view
your compliance requirements
and avoid HIPAA violations.
Wait… Don’t Leave
Empty-Handed!
Get the FREE
HIPAA Compliance Checklist
View your compliance requirements and avoid HIPAA violations
Delivered via email so please ensure you enter your email address correctly.
Your Privacy Respected
HIPAA Journal Privacy Policy
Delivered via email so please ensure you enter your email address correctly.
Your Privacy Respected
HIPAA Journal Privacy Policy
Please enter correct email address
Your Privacy Respected
HIPAA Journal Privacy Policy
Is Your Organization HIPAA Compliant?
Find Out With Our Free HIPAA Compliance Checklist
source
This is a newsfeed from leading technology publications. No additional editorial review has been performed before posting.


