Setting the Stage for More Government Oversight
by Jay Hodes, President – Colington Consulting
The dust has settled, and more facts have been coming to light regarding the recent HIPAA data breach at Anthem Blue Cross Blue Shield. It was only a matter of time before the U.S. Congress started making some noise about cybersecurity. Within days of news reports of the Anthem breach, the U.S. Senate Committee on Health, Education, Labor and Pensions announced a bipartisan initiative to focus on the security of health information technology. This initiative will also look at the health industryโs overall preparedness for cyber threats.
Although the timing was ironic and clearly not related to the Anthem breach, the White House announced its 2016 proposed budget that includes an increase in funding for HIPAA compliance programs. The proposed budget indicates around a 10% percent increase in funding for the Office for Civil Rights (OCR). OCR is the agency within the U.S. Department of Health and Human Services (HHS) with HIPAA compliance and oversight responsibilities.
As far as the possible budget increase for OCR, we will wait to see what type of mood Congress is in to approve this. And, even with this congressional initiative, any proposed fixes will take time and money. In the meantime, hopefully the Anthem case sends a loud and clear message to all healthcare providers to up their game when it comes to protecting patient health information. Healthcare providers, plans and clearinghouses need to go on the offensive and be proactive when it comes to having the proper information technology safeguards in place. The threat of Congressional action or a beefed up OCR must not be the incentive to do so.
Regrettably, the use of encryption is not a requirement of the HIPAA Security Rule. As shocking as that sounds, that does not mean covered entities do not need to encrypt their patient data. What the guidelines call for, as provided by HHS, is this:
The encryption implementation specification is addressable, and must therefore be implemented if, after a risk assessment, the entity has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI [electronic protected health information]. If the entity decides that the addressable implementation specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative measure, presuming that the alternative is reasonable and appropriate. If the standard can otherwise be met, the covered entity may choose to not implement the implementation specification or any equivalent alternative measure and document the rationale for this decision.
It is incumbent on covered entities to conduct a HIPAA Risk Assessment in order to make the determination on whether it is reasonable and appropriate to their particular circumstance to use encryption software. The assessment must be the basis for the decision. And if the decision is made not to encrypt, then the justification must be made abundantly clear in documentation.
So if there is a breach and OCR asks during an investigation why your organization did not encrypt its protected health information, the justification must be based on a low threat to your data. Make sure you can back that up with documentation that is solid and well-defined. Possible civil and criminal prosecution will be based on the proof you provide.
Need Help with Your HIPAA Compliance Program?
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.
- This article was updated on June 23, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
- Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.