State Of HIPAA – 2027 Predictions
It has been three decades since President Clinton signed the Health Insurance Portability and Accountability Act (HIPAA) into law in 1996, and a quarter of a century has passed since the HIPAA Privacy Rule took effect, yet HIPAA compliance is still proving a challenge for many HIPAA-regulated entities. Noncompliance with the HIPAA Rules is frequently identified by the HHS Office for Civil Rights (OCR) and state attorneys general in compliance audits and investigations of complaints and data breaches.
Over the past 25 years, the HIPAA Rules have been updated on multiple occasions, and there are pending changes to the HIPAA Privacy and Security Rules that are due to be finalised in the next 18 months, the first of which is due in August 2026. This article explores the current state of HIPAA compliance and some of the key aspects of the HIPAA Rules that are proving difficult for HIPAA-regulated entities, along with predictions for 2026 and 2027.
HIPAA Predictions for 2026 and 2027
A final rule implementing changes to the HIPAA Privacy Rule to improve care coordination is pencilled in for release in August 2026. The Notice of Proposed Rulemaking (NPRM) was issued in the final days of the first Trump administration, but has lain dormant during the Biden administration. The proposed rule was revived by OCR, which has made progress on a final rule, having held a Tribal consultation in early 2026. A final rule is now imminent. The Office of Management and Budget (OMB) 2026 Regulatory Agenda indicates the final rule will be issued in August 2026, but the date is not set in stone. With OCR now focused on this final rule rather than the final rule implementing changes to the HIPAA Security Rule, it seems unlikely that the Privacy Rule update will face a lengthy delay.
The final rule implementing the proposed Privacy Rule changes is likely to be the only major HIPAA development in the second half of 2026, although an NPRM seeking comment on a new time frame for responses to HIPAA Right of Access requests is likely to be issued before the end of the year. A target has been set for November 2026, and given that this is an area that has been under consideration for several years, an NPRM seeking comment on the proposed changes can be expected before the end of the year.
Looking into the crystal ball for longer-term predictions, the HIPAA Security Rule update will be the next major HIPAA change. Regulated entities had the shock of seeing the extent of the proposed changes in late 2024. The 125-page document includes extensive new security measures and cybersecurity practices, and updates to the language, removing the distinction between addressable and required elements, eliminating much of the flexibility previously afforded to regulated entities. OCR received more than 4,700 public comments in response to the NPRM. A great deal of the feedback was negative, with the proposed rule criticised for the unworkable timeline, difficulty of implementation for smaller regulated entities, lack of flexibility, and the cost of compliance.
The target date for a final rule implementing the proposed changes was set as May 2026, although a revised target has since been given for July 2027. The can may have been kicked down the road to allow OCR to focus on the final rule implementing the Privacy Rule coordinated care changes, but the Security Rule changes are coming. The July 2027 date in the OMB regulatory agenda may be optimistic; however, I expect a final rule to be issued in the second half of 2027, although it will likely differ from the proposed rule, given the extensive criticism OCR received in response to its NPRM.
In terms of HIPAA enforcement, OCR has been focused on compliance with the risk analysis provision of the HIPAA Security Rule, and plans to extend this initiative to also include risk management. HIPAA Security Rule enforcement is likely to remain focused on these two areas in 2026; however, the initiative could well be expanded further in 2027 to encompass more elements of HIPAA Security Rule compliance, guided by the findings of OCR’s 2024/2025 HIPAA compliance audits.
How Did We Do With Our 2025 HIPAA Predictions?
One of the easiest predictions I made in 2025, given the backlash to the HIPAA Privacy Rule to Support Reproductive Healthcare Privacy, was that it would either not survive the year or would not be enforced by the current administration. The Privacy Rule update was issued by OCR in April 2024 under the Biden Administration in response to the Supreme Court decision that overturned Roe v. Wade, which made the legality of abortion a matter for the states. The final rule had a compliance deadline of December 23, 2024. The rule was challenged in court, and on June 18, 2025, the U.S. District Court for the Northern District of Texas issued an order declaring it unlawful, vacating most of the Rule aside from the Notice of Privacy Practices requirements. Prior to that, OCR rescinded its guidance on gender affirming care, in response to an Executive Order by President Trump that made it U.S. policy to only recognize two genders.
Given the huge number of hacking and ransomware incidents reported by HIPAA-regulated entities in recent years, there is a pressing need for an update to the HIPAA Security Rule. OCR has published voluntary cybersecurity performance goals for the healthcare and public health sector consisting of two sets of high-impact cybersecurity best practices; however, voluntary goals have not been sufficient to combat modern threats, which are likely to increase further due to AI.
I predicted that the proposed HIPAA Security Rule would be pushed through in some form, likely watered down in response to the volume of criticism received, but the final rule failed to materialize. In a 2026 press call with OCR on the establishment of OCR’s enforcement program for the Part 2 regulations, the OCR Director explained that a decision whether to issue a final rule implementing the HIPAA Security Rule changes will be made by the current administration. While initially having a May 2026 date for the release of a final rule, it is now a longer-term action. The can has been kicked down the road for now, with a target date set for July 2027.
In my 2025 predictions, I suggested that OCR would work on implementing a final rule implementing the proposed changes to the HIPAA Privacy Rule to support coordinated care, as the NPRM was issued by OCR under the previous Trump administration. While I predicted that would happen in 2025, it now has a 2026 release date. The requirement to decrease the time for covered entities to respond to requests for protected health information made pursuant to the right of access will take longer, with an NPRM due to be issued in November 2026.
One of my 2024 predictions was that OCR would start cracking down on late breach notifications, as a growing number of regulated entities have been issuing notifications about data breaches well past the 60-day deadline. OCR does appear to be paying closer attention to breach notices, as in 2025, five enforcement actions included penalties for HIPAA Breach Notification Rule failures.
How Did We Do With Our 2024 HIPAA Predictions?
- OCR will increase enforcement actions for violations of the HIPAA Security Rule that have contributed to data breaches and HIPAA Breach Notification Rule violations for failing to issue timely notifications to individuals whose PHI has been compromised in data breaches. 2024 will see record numbers of settlements and civil monetary penalties.
- I was not far off, as the OCR Director confirmed that 22 HIPAA enforcement actions were closed in 2024 with financial penalties, which almost made it a record year for penalties; however, I was a little too hopeful that there would be a clampdown on late breach notifications. Individual notifications continue to be issued by some regulated entities, many months after a data breach has occurred.
- The HIPAA Right of Access will continue to be an enforcement priority for OCR – This is low-hanging fruit. The investigations are straightforward and require few OCR resources, and the findings of investigations are unlikely to face legal challenges.
- OCR has continued to target noncompliance with this HIPAA Privacy provision and has now imposed 51 penalties for failing to provide timely access to medical records and charging excessive amounts for providing those records.
- OCR is planning a HIPAA Security Rule update in Spring 2023, which we predict will include several new mandatory requirements for cybersecurity, including stricter access control requirements such as mandatory multi-factor authentication.
- It took longer than planned; however, OCR published its proposed HIPAA Security Rule in December 2024, and multifactor authentication, encryption, network segmentation, penetration tests, annual internal Security Rule audits, 6-monthly vulnerability scans, anti-malware software, checks of Security Rule compliance, and other cybersecurity measures will – if enacted – become mandatory.
- A final rule will be introduced regarding disclosures of reproductive health information, which will be prohibited for reasons other than treatment, payment, and healthcare operations and for PHI to be used for identifying, investigating, and prosecuting patients, providers, and others involved in the provision of legal reproductive health care services, in response to the overturning of Roe v. Wade
- This was one of OCR’s key priorities, and the final rule was added to the Federal Register on April 26, 2024, and took effect on December 23, 2024.
- The lawsuit filed by the AHA in response to OCR’s December 2022 guidance on tracking technologies makes strong arguments that OCR has stretched the definition of protected health information to more than the current statute can bear. Should that challenge not prove to be successful, 2024 will see the first enforcement action over the use of tracking technologies on hospital websites. If the lawsuit is successful, further rulemaking will be proposed regarding tracking technologies to ensure patient privacy.
- The challenge was successful, and the guidance was partially vacated. While there were no OCR enforcement actions regarding tracking technologies, the New York Attorney General imposed a $300,000 financial penalty on New York Presbyterian Hospital for using pixels and other website tracking tools.
- The HHS’ Centers for Medicare and Medicaid Services (CMS) will introduce new cybersecurity requirements as a condition for participation in the Medicare and Medicaid programs.
- The HHS has confirmed that CMS will do this, but it is still on the to-do list.
- State Attorneys General will step up enforcement of HIPAA compliance and will impose more financial penalties against healthcare organizations that have failed to meet minimum standards for cybersecurity.
- I was wrong on this one, as only New York increased its enforcement activities to a significant degree, fining 4 healthcare organizations for cybersecurity failures in 2024, including one multi-state action with Connecticut and New Jersey. California and Indiana both announced two penalties for cybersecurity failures.
HIPAA Enforcement in 2024 and 2025
OCR has been enforcing HIPAA compliance more aggressively in recent years, imposing more financial penalties for HIPAA violations. In her end-of-year recap before the administration change, OCR Director Melanie Fontes Rainer confirmed that 2024 was almost a record year for HIPAA enforcement, with more than $9.9 million collected across 22 settlements and civil monetary penalties, including a $4,750,000 settlement with Montefiore Medical Center to resolve multiple HIPAA Security Rule violations. While 22 enforcement cases were closed in 2024, OCR delayed announcing six of the enforcement actions until January 2025. OCR continued to aggressively enforce compliance with the HIPAA Rules throughout the year, announcing 21 HIPAA cases involving financial penalties, including the 6 settlements rolled over from 2024. Across those 21 enforcement actions, OCR collected $8,330,066 in financial penalties.

In contrast to 2022, when 17 of the 22 financial penalties resolved alleged violations of the HIPAA Right of Access – the failure to provide individuals with timely access to their medical records and only charge a reasonable cost-based fee – only 5 of OCR’s 22 closed enforcement actions in 2024 resolved HIPAA Right of Access violations, showing that the enforcement initiative has been effective at reducing noncompliance.
After a successful challenge to the penalty imposed on University of Texas MD Anderson Cancer Center in 2019 for HIPAA Security Rule failures that vacated the financial penalty, OCR appeared reluctant to pursue penalties for HIPAA Security Rule violations, with only 2 enforcement actions for alleged Security Rule violations in 2021 and a further 2 in 2022.
OCR has now adopted a different approach and is scrutinizing compliance with one aspect of the HIPAA Security Rule – the risk analysis. OCR’s investigations and compliance audits clearly show that the risk analysis is the most common HIPAA Security Rule violation. In the round of HIPAA audits conducted in 2016-2017, OCR found that most audited healthcare organizations were not fully compliant with this Security Rule provision, either never having conducted a risk analysis, failing to conduct a risk analysis regularly enough, or not conducting comprehensive and accurate risk analyses covering all systems where ePHI is collected, stored, or transmitted. In 2025, 16 of the 21 announced enforcement actions involved penalties for risk analysis failures, making it the most common reason for a financial penalty for HIPAA noncompliance in 2025.
OCR has faced challenges with HIPAA enforcement due to a significant increase in its workload while its budget has remained flat. OCR investigates all data breaches of 500 or more records, and data breaches have increased at an alarming rate. OCR explained in its annual reports to Congress that since fiscal year 2017, it has received a 100% increase in large breach reports, largely driven by an increase in hacking incidents, especially ransomware attacks. In 2021, 75% of the breaches affecting 500 or more individuals were due to hacking incidents, compared to 41.6% of data breaches in 2017. The problem has been getting worse. In 2025, 81% of the 789 reported data breaches were hacking/IT incidents.

In addition to having to investigate more than twice the number of data breaches as in 2017, between 2017 and 2021, OCR also saw a 28% increase in complaints about potential HIPAA violations, yet aside from annual increases for inflation, OCR is working with the same budget as in 2017. OCR explained in its 2022 report to Congress that it has been forced to decrease its enforcement staff by 45%, and with its resources under incredible strain, that naturally has an impact on the speed of investigations and the number of cases where financial penalties can be pursued. Further, with such an incredibly heavy workload, it has been difficult to retain staff. The DOGE purge of HHS staff in the early days of the current administration has not helped matters.
OCR can increase funding through its enforcement actions, as the funds collected can be used for enforcement purposes, but fines and settlements are unpredictable. In addition, penalty amounts have fallen considerably. In 2017, OCR collected $19,393,000 in penalties in 10 enforcement cases, then $28,683,400 in penalties the following year in 11 HIPAA cases. In 2022, OCR collected just $2,170,140 in penalties in 22 enforcement cases, and while penalties have increased, in 2025, only $8.3 million was collected in 21 enforcement actions. The average HIPAA fine in 2017 was approximately $1,939,000, and $2,607,000 in 2018. In 2025, the average financial penalty was just $396,000.
The decrease in penalty amounts is due to a reinterpretation of the language of the HITECH Act, which has seen the maximum penalties for HIPAA violations reduced in three of the four penalty tiers. OCR has asked Congress to increase the maximum penalties for HIPAA violations and is constantly pushing to have its budget increased, but there are no indications at present that additional funding will be provided, nor that penalty amounts will be increased as requested.

* The OCR Director stated that $9.9 million was raised in enforcement actions in 2024, although some of the enforcement actions closed in 2024 were not announced until 2025.
Budgetary pressures have forced OCR to look at other ways of increasing funding, such as improving efficiency and productivity by restructuring to get better use of its existing resources. In 2023, OCR restructured and created a new enforcement division, and that appears to have been effective; however, restructuring alone has not been enough to make much of a dent in the backlog of data breach investigations.
The new enforcement initiative targeting risk analysis compliance has made a difference. Investigations of data breaches require a lot of resources, as do enforcement actions. By targeting the risk analysis requirement, the most common HIPAA Security Rule violation, OCR has been able to hold more HIPAA-regulated entities to account for violating this essential Security Rule requirement and investigate data breaches more quickly, helping to clear the backlog a lot faster.
State attorneys general also enforce the HIPAA Rules, and in 2023, 16 investigations resulted in settlements or civil monetary penalties to resolve violations of HIPAA and state privacy laws. There was a reduction in State Attorney General enforcement actions in 2024, with only 9 actions resulting in financial penalties, with only California, Indiana, New York, and Washington taking action against HIPAA-regulated entities for cybersecurity and privacy failures, with New Jersey and Connecticut also participating in one multi-state action. In 2025, only New York imposed a financial penalty for cybersecurity failures by one HIPAA-covered entity. The number of data breaches has continued to increase, but state attorneys general appear to have lost interest in pursuing penalties for HIPAA violations.
The State of HIPAA Compliance
OCR conducts HIPAA audits to assess the state of HIPAA compliance. The second phase of HIPAA audits was conducted in 2016 and 2017, and showed that compliance with the HIPAA Rules had improved, although few of the audited entities were found to be fully compliant with all aspects of the HIPAA Rules. The HIPAA audits do not result in HIPAA penalties, as OCR has stated that were that to be the case, few entities would submit to a voluntary audit. The audits do provide a snapshot of the state of HIPAA compliance, and guide OCR’s rulemaking, enforcement, and outreach efforts.
OCR launched its third phase of HIPAA audits in 2024 and 2025, and planned to review compliance at 50 HIPAA covered entities and business associates. These audits were much more focused than in previous rounds of audits, looking solely at HIPAA Security Rule compliance. OCR has used the audits to identify aspects of compliance most pertinent to hacking incidents and ransomware attacks, which have soared in recent years. OCR is using these audits to examine mechanisms for compliance, identify promising practices for protecting the privacy and security of health information, and discover risks and vulnerabilities that may not have been uncovered by its investigations of data breaches and enforcement activities. While OCR has stated its intention to conduct an ongoing program of compliance audits, an ongoing compliance audit program has failed to materialize due to budget constraints.
The findings of the 2024/2025 HIPAA audits have yet to be made public; however, the 2016-2017 HIPAA audit program identified many areas of noncompliance, with most covered entities found to have failed to achieve full compliance in the following areas:
- The HIPAA Security Rule risk analysis and risk management requirements
- Timely breach notifications and adequate content of breach notifications
- Prominent posts of Notices of Privacy Practices on websites and insufficient content of those notices
- Timely responses to individuals’ right of access requests and charges for copies of medical records
Many of the compliance issues identified by OCR in the 2016/2017 compliance audit program continue to pose problems for HIPAA-regulated entities, as can be seen in OCR’s enforcement actions, which give an indication of the current state of HIPAA compliance.
Most Common HIPAA Violations in OCR’s Enforcement Actions (2020-2025)
| HIPAA Violation | Enforcement Actions |
| HIPAA Right of Access | 54 |
| Risk Analysis | 41 |
| Recording and Reviewing Activity in Information Systems Containing ePHI | 13 |
| Risk Management | 9 |
| Breach Notifications (including HHS, individuals, and the media) | 5 |
| Notice of Privacy Practices | 4 |
| Business Associate Agreements | 4 |
| Lack of Technical Safeguards | 4 |
| Impermissible Disclosure on Social Media/Internet | 4 |
| Audit Controls | 3 |
| Technical and Nontechnical Evaluation | 3 |
| HIPAA Privacy Rule Policies | 2 |
| Policies and Procedures for Responding to Security Incidents | 2 |
| Appointment of a HIPAA Privacy Officer | 2 |
| Procedures for Creating and Maintaining Retrievable Exact Copies of ePHI | 1 |
| Minimum Necessary Standard | 1 |
The above list of the most common HIPAA violations identified in OCR enforcement actions includes many that could have been avoided with HIPAA training, such as HIPAA right of access violations, social media violations, and ineffective HIPAA compliance program management.
The most common HIPAA Security Rule violation is the failure to conduct a comprehensive and accurate risk analysis to identify risks and vulnerabilities to ePHI. OCR has made the risk analysis one of its key enforcement priorities due to the extent of noncompliance and its importance to cybersecurity. Imposing penalties for risk analysis failures has helped to ensure that regulated entities appreciate the importance of a risk analysis, but guidance on how to conduct a risk analysis was clearly needed. In April 2026, OCR released a video presentation in which Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, explains the requirements of this implementation specification, its importance, and potential risk management violations identified by OCR in its investigations.
The OCR Director has explained that the risk analysis enforcement initiative will evolve in 2026 to also cover risk management. OCR wants to see evidence not only that all risks to ePHI have been identified, but that they have been subjected to a HIPAA-compliant risk management process and have been reduced to a reasonable level. While OCR has not stated that the HIPAA Breach Notification Rule is a key enforcement initiative, in 2025, five enforcement actions included penalties for breach notification failures, including notices to the HHS Secretary, individuals, and media. Three of the eight enforcement actions in 2026 (January to July) included penalties for breach notification failures, which shows this is an area OCR is closely monitoring.
Top HIPAA Security Rule Compliance Challenges in 2026
Complying with all HIPAA provisions and implementation specifications can be a challenge, especially for smaller healthcare providers and business associates who do not have extensive resources to devote to HIPAA compliance. While the soon-to-be-implemented Privacy Rule update aims to decrease the compliance burden to a degree, the coming changes to the HIPAA Security Rule are another matter entirely.
HIPAA compliance software can simplify and automate compliance and provide comprehensive risk management processes for both compliance officers and practice managers to follow, covering all provisions and implementation specifications of the HIPAA Rules to ensure that nothing is missed. For small to mid-sized practices and business associates especially, compliance software can provide considerable peace of mind.
Based on OCR’s compliance audits and enforcement actions, the same areas of noncompliance are discovered time and again, and are the most common reasons for financial penalties for noncompliance.
Risk Analyses
The HIPAA Security Rule mandates that regulated entities must conduct a comprehensive and accurate organization-wide risk analysis to identify risks and vulnerabilities to electronic protected health information (ePHI). The risk analysis process needs to be ongoing, and the best practice is to conduct these at least annually or as needed, such as following any material change to policies, procedures, technologies, and business practices. The risk analysis must be comprehensive, which means an organization must identify all ePHI within the organization, all systems that touch ePHI, and all external ePHI created, received, maintained, or transmitted by business associates. All threats to that information must be identified, including human, natural, and environmental threats to ePHI and the systems on which the ePHI is stored. The HHS has developed a Security Risk Assessment Tool to help regulated entities with this vital process, and has released a video presentation to explain what is required.
Risk Management Processes
Once risks and vulnerabilities have been identified, they must be subjected to risk management processes to reduce them to a low and acceptable level in a timely manner. Risks must be assessed, and remediations prioritized to ensure that the risks most likely to be exploited are addressed first. OCR has stated that it is expanding its risk analysis enforcement initiative in 2026 to include risk management. OCR will want to see evidence that risks have been remediated in a timely manner. Risk management processes also need to be extended to third parties – business associates – which means performing due diligence on vendors throughout the supply chain and implementing processes to identify, assess, and manage vendor risk at each stage of the vendor life cycle – onboarding, ongoing, and offboarding. Reducing risk exposure from vendor relationships is one of the biggest security challenges in healthcare in 2026 and a pressing issue, as hackers are actively targeting the supply chain.
Technical Security Controls
The HIPAA Security Rule does not currently specify the technical controls that should be implemented to secure systems containing ePHI, as these need to be based on the specific IT architectures of each regulated entity. That will change if the final rule updating the HIPAA Security Rule is released largely unchanged from the proposed rule. It is the responsibility of each regulated entity to ensure that appropriate security controls are implemented and that they are effective at reducing risk. Security controls need to be regularly subjected to security assessments to make sure they have been implemented correctly, are operating as intended, and are achieving the desired outcome. HIPAA-regulated entities should conduct regular vulnerability scans and penetration tests to gain a better understanding of their security posture and identify security gaps that need to be addressed.
Audit Controls and Information System Activity Reviews
All IT systems that touch ePHI must have audit controls and create logs of system activity, and reviews of information system activity should be conducted on audit logs, access reports, and security incident tracking reports on an ongoing basis. Despite information system activity reviews being a requirement of the HIPAA Security Rule, OCR’s investigations have revealed many organizations only conduct reviews on an ad-hoc basis in response to potential security incidents. Regular reviews allow HIPAA-regulated entities to rapidly identify unauthorized access to ePHI by malicious insiders and hackers. All too often, regulated entities discover unauthorized access by insiders and hackers that has been ongoing for many months.
Access Controls
Technical policies and procedures need to be developed, implemented, and maintained for all electronic information systems that contain or allow access to ePHI to only permit access to persons or software programs that have been granted access rights per the organization’s access management policies and procedures. Access controls need to be based on the principle of least privilege, and access must be promptly revoked when individuals leave employment or no longer require access to ePHI. Ineffective access controls can be exploited by malicious actors to move laterally within networks and view or steal huge volumes of ePHI.
Staff Cybersecurity Training
Increased staff cybersecurity training is needed to teach employees about the different cybersecurity threats to PHI, which are increasing due to AI. Cybersecurity training helps the staff identify common threats like phishing, malware, and ransomware, and the role they must play in ensuring the cybersecurity of their organization. It also covers how to protect PHI, focusing on secure data handling, strong password practices, and spotting the signs of a security breach. The aim is to make sure all staff members know about these threats and how to prevent them to keep their networks and patient data safe and secure.
Challenges with HIPAA Privacy Rule Compliance in 2026
Several aspects of HIPAA Privacy Rule compliance are likely to continue to prove challenging for HIPAA-regulated entities in 2026, and compliance officers will need to ensure that they update their policies and procedures to comply with the soon-to-be-issued final rule implementing changes to the Privacy Rule to improve care coordination. Based on enforcement actions and compliance investigations by OCR, the following HIPAA Privacy Rule issues are still causing issues for some covered entities.
Timely Access to Medical Records
The 2016 HIPAA compliance audits identified widespread noncompliance with the HIPAA Right of Access, and increasing numbers of complaints were being received from individuals struggling to obtain copies of their medical records. OCR launched a new compliance initiative in 2019 targeting noncompliance with the HIPAA Right of Access, and the bulk of OCR’s subsequent enforcement actions to date have been for noncompliance with the HIPAA Right of Access. OCR is continuing with this enforcement initiative and has already issued more than 50 financial penalties for noncompliance. Further, OCR has indicated that it expects to reduce the time frame for providing records in response to right of access requests from 30 days to 15 days.
Tracking Technologies
In 2022, investigations of tracking technologies on websites revealed the extent to which third-party code snippets were being used by healthcare organizations to track website visitors. The code snippets collect valuable data on website and web app user activity, which can be used to improve those services; however, the code can also collect identifiable health information and transmit that information to third parties for marketing and advertising purposes. Those third parties typically do not sign business associate agreements, and using the code without a BAA in place or first obtaining consent from individuals to share that information can violate patient privacy.
OCR issued guidance on tracking technologies and HIPAA in December 2022, and the OCR Director issued a statement confirming OCR will be enforcing this aspect of compliance. Many lawsuits have been filed against healthcare providers over privacy violations due to the use of tracking technologies, some of which have resulted in multi-million-dollar settlements. OCR’s guidance was challenged in court by the American Hospital Association, and a Texas judge ruled that OCR’s guidance was unlawful, partially vacating the guidance. While the ruling means that the tools can be used on unauthenticated web pages, tracking tools must not be used on authenticated web pages such as patient portals.
Staff HIPAA Training
The annual Verizon Data Breach Investigations Reports highlight the extent to which data breaches are caused by human error. Out of all data breaches analyzed by Verizon in 2024, 68% involved a non-malicious human element. Those data breaches include misconfigurations, responses to phishing and social engineering attacks, failures to set strong passwords, and other mistakes. These mistakes often expose ePHI and make it easy for hackers to gain access to healthcare networks. The only way to tackle human error is through education. The HIPAA Privacy Rule requires regulated entities to provide training on HIPAA policies relevant to each individual’s role, while the HIPAA Security Rule requires a security awareness training program. In the case of the latter, increasing the frequency of training can help create a security culture and eradicate bad security practices.
Looking Forward – Pending Changes to the HIPAA Rules
While updates to the HIPAA Rules are made fairly infrequently, there are pending changes to the HIPAA Privacy Rule that are expected to be finalized in August 2026. The proposed update to the HIPAA Security Rule has been delayed until mid 2027, giving HIPAA covered entities and business associates more time to plan for the new mandatory cybersecurity requirements.
The proposed changes to the HIPAA Security Rule are extensive and will be time-consuming and costly to implement, and will be potentially problematic for small medical practices and business associates. Rural healthcare providers that are already struggling with limited resources will find the proposed requirements particularly challenging to implement.
The HHS will provide a grace period to allow the changes to be implemented before compliance becomes mandatory. The deadline for implementing the required changes mandated by the proposed Security Rule attracted considerable criticism. The delay to the final rule means regulated entities have been provided with extra time to improve security, and they should use that time wisely to ensure that they can meet the compliance deadline when the final rule is issued. By starting to implement some of the key requirements, such as the creation and maintenance of a comprehensive and accurate asset inventory and following the proposed, more prescriptive risk analysis requirements, they will be able to make significant improvements to their security posture and ease the pain when the final rule is issued.
States are also introducing new laws to better protect the privacy of state residents and ensure they are notified quickly in the event of privacy breaches, while New York has introduced strict new cybersecurity requirements for general hospitals to combat the growing number of cyberattacks and data breaches. New York started enforcing compliance in 2025 and issued a $500,000 financial penalty to resolve cybersecurity failures. Staying up-to-date with changes to federal and state laws and ensuring compliance will be an ongoing challenge.
The proposed HIPAA updates to the Privacy Rule are intended to improve care coordination while reducing the compliance burden on covered entities to some degree, while the proposed update to the HIPAA Security Rule is intended to improve the privacy and security of personally identifiable information and combat the growing number of hacking incidents and ransomware attacks, which have plagued the sector for several years. OCR issued voluntary cybersecurity performance goals consisting of high-impact measures for making significant improvements to security; however, they have not been sufficient by themselves. Hacking incidents continue to increase, with new records set for healthcare data breaches almost annually.
The proposed HIPAA changes are naturally a cause of concern for many HIPAA-regulated entities, which will have to spend considerable time, effort, and money implementing the changes and ensuring their employees are fully trained on the new requirements. The HHS has previously proposed financial assistance for certain entities to help them implement the necessary changes to improve security. It remains to be seen whether Congress will approve the necessary grants and funding to ease the financial burden on regulated entities and help them comply with the new Security Rule requirements and implement the necessary measures to harden security.
Steve Alder, Editor-in-Chief, HIPAA Journal



