Author: Colington Consulting

  • OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    OCR and ONC Just Updated the Free SRA Tool; Here’s Why That Doesn’t Solve Your Risk Analysis Problem

    Quick answer: On September 10, 2026, OCR and ONC released version 3.7 of the Security Risk Assessment (SRA) Tool, adding new content on remote access, telework, and system activity logging, as well as expanded asset examples and revised reports. The update is genuinely useful, but it doesn’t change what makes the SRA Tool a weak standalone fit for many organizations: it doesn’t stop you from leaving sections incomplete; OCR itself has never confirmed the tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard; OCR has described the tool as built for smaller organizations without ever defining what that means; and a broad, general questionnaire can’t fully account for how ePHI actually moves through your specific organization. For most practices, the SRA Tool is a reasonable starting point, not a finish line.

    OCR and ONC Just Released SRA Tool Version 3.7

    On September 10, 2026, HHS’s Office for Civil Rights and the Office of the National Coordinator for Health IT announced version 3.7 of the free SRA Tool. According to the release, the update includes:

    • Revised assessment coverage and scope questions and education
    • New remote access and telework questions and education
    • Updated system activity logging language and education
    • Expanded asset examples to reflect newer technology
    • Updated software libraries for bug and vulnerability fixes
    • Report revisions to capture additional details and comments

    OCR and ONC also scheduled webinars on September 15 and 16, 2026, to walk organizations through the new features. All of this is a real improvement over the prior version; it’s also not, on its own, the same as a compliant HIPAA risk analysis, and that gap is where many organizations run into trouble.

    The Tool Lets You Stop Before You’re Finished

    During the September 2026 OCR/NIST โ€œSafeguarding Health Informationโ€ conference, Nick Heesters, Senior Advisor for Cybersecurity in OCR’s Health Information Privacy, Data, and Cybersecurity Division, described a pattern OCR has seen play out in real investigations: organizations that used the SRA Tool but left portions of it incomplete. The software doesn’t require every section to be finished before a user can close it out or generate a report; it simply picks back up wherever the user left off, whenever that happens to be.

    That flexibility is convenient for whoever is filling it out. It’s a liability for the organization relying on it, since an incomplete assessment isn’t a defense in an investigation; it’s a finding. If your risk analysis has gaps because the tool allowed those gaps to sit unresolved, OCR treats that the same way it treats any other incomplete risk analysis.

    OCR Has Never Said the SRA Tool Meets Its Own Standard

    Here’s the detail worth sitting with. At past OCR/NIST conferences, Heesters has been asked directly whether OCR considers output from the SRA Tool to be an โ€œaccurate and thoroughโ€ risk analysis, which is OCR’s own standard under the Security Rule’s Security Management Process provision. He hasn’t given a direct yes or no. His answer has consistently been that the SRA Tool is one of the tools an organization can use as part of a broader risk analysis process, not a guarantee of adequacy on its own.

    The agency that enforces this standard has had multiple chances to say that its own free tool satisfies it, but hasn’t. That’s not a condemnation of the tool; it’s a statement about its limits, and it should shape how much weight any organization places on a completed SRA Tool questionnaire on its own.

    OCR Built This Tool With Smaller Organizations in Mind, and Never Said What โ€œSmallerโ€ Means

    OCR and ONC have described the SRA Tool as designed for small and medium-sized health care providers. Neither agency has defined where that scope actually ends. No stated employee count, revenue threshold, patient volume, or system complexity marks the line between an organization the tool was built for and one that has outgrown it.

    That ambiguity matters because many organizations using the tool don’t actually know which side of that undefined line they’re on. A practice with ten providers and a single EHR is a very different compliance environment than a forty-provider, multi-specialty group running telehealth, a patient portal, and three billing vendors; yet nothing in OCR’s own materials tells either one whether the tool was designed with them in mind. Absent a definition, organizations tend to assume the tool fits them because it’s free and easy to access, not because OCR ever confirmed that it does.

    A Broad Checklist Wasn’t Built Around Your Environment

    OCR’s own guidance, reinforced at the same 2026 conference, describes a risk analysis as an assessment of risk to ePHI at three distinct stages: where it’s created or enters the organization, where it flows internally between systems and departments, and where it leaves the organization entirely. A compliant risk analysis must trace all three stages for your specific systems, your specific vendors, and your specific workforce, not a generalized questionnaire built to apply to every covered entity at once.

    The SRA Tool asks the same structured questions of a practice with five providers, a hospital system, and a school district billing Medicaid. When your organization’s actual ePHI flow doesn’t map cleanly to the tool’s built-in categories, gaps appear, and the tool has no way to flag a misapplied category or a missed system entirely.

    What This Costs Small and Midsize Practices in Practice

    None of this means the SRA Tool has no value; it’s free, and it gives an organization a starting structure. But the real cost shows up when practice staff, who aren’t compliance professionals and aren’t expected to be, spend hours interpreting technical questions about encryption, access controls, and system logging, only to close out a tool that was never confirmed to fit their size or environment in the first place. That’s hours spent and a false sense of security produced, at the same time.

    Frequently Asked Questions

    Does using the free HHS SRA Tool satisfy HIPAA’s risk analysis requirement?

    Not necessarily. OCR has repeatedly declined to confirm that output from the SRA Tool meets its own โ€œaccurate and thoroughโ€ risk analysis standard, describing it instead as one tool that can support a broader risk analysis process.

    Does OCR require organizations to use the SRA Tool?

    No. OCR and ONC offer the SRA Tool as a free resource to help organizations conduct a risk analysis; it isn’t a mandated format, and using it doesn’t by itself guarantee compliance with the Security Rule’s risk analysis requirement.

    Is the SRA Tool meant for organizations of any size?

    OCR and ONC have described the tool as designed for small and medium-sized health care providers, but neither agency has defined what counts as small or medium. Organizations of any size can use it, but there’s no official guidance on where it stops being an appropriate fit.

    Can I leave sections of the SRA Tool incomplete and finish later?

    Yes, and that’s part of the concern. The software allows users to save an incomplete assessment and resume it later, which means an organization may end up relying on a risk analysis that was never completed.

    What did OCR update in SRA Tool version 3.7?

    Version 3.7, released September 10, 2026, added revised assessment coverage and scope questions, new remote access and telework content, updated system activity logging language, expanded asset examples, updated software libraries, and revised reporting.

    What should a practice do instead of relying only on the SRA Tool?

    Use it as a starting point if you choose to, but pair it with, or replace it with, a risk analysis conducted by someone who can map ePHI creation, flow, and exit points specific to your organization, and who can speak to whether the result would hold up under OCR’s own standard.

    Why Spend Hours on a Tool OCR Won’t Vouch For?

    A free tool that OCR itself won’t confirm meets its own standard, that was built with an undefined idea of โ€œsmallerโ€ in mind, that lets you walk away with unfinished sections, and that treats a five-provider practice the same as a five-hundred-provider health system isn’t a shortcut. It’s a slower path to the same uncertainty you started with.

    Colington Consulting’s lead consultants have personally conducted more than 1,000 HIPAA risk assessments; we work directly with your systems, your vendors, and your staff, and build a documented, defensible risk analysis mapped to how ePHI actually moves through your organization, not a generic questionnaire built to apply to everyone at once.

    Get a free HIPAA Risk Review. We’ll show you where a generic tool would leave gaps and what a thorough, defensible risk analysis looks like for your organization.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, โ€œHHS Releases Updated Security Risk Assessment Tool,โ€ September 10, 2026.

    U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โ€œSafeguarding Health Information: Building Assurance Through HIPAA Securityโ€ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.

    U.S. Department of Health and Human Services, Office for Civil Rights, and Office of the National Coordinator for Health IT, Security Risk Assessment (SRA) Tool product documentation and user guide.

    45 C.F.R. ยง 164.308(a)(1), Security Management Process (Risk Analysis and Risk Management).

  • What OCR Told Us at the 2026 HIPAA Security Conference: Enforcement, Risk Analysis, and Policy Gaps

    What OCR Told Us at the 2026 HIPAA Security Conference: Enforcement, Risk Analysis, and Policy Gaps

    Quick answer: At the OCR/NIST โ€œSafeguarding Health Informationโ€ conference held September 2 to 3, 2026, in Gaithersburg, Maryland, HHS’s Office for Civil Rights delivered a consistent message across sessions: enforcement is not slowing down; risk analyses remain the most commonly cited deficiency because they are still inaccurate or incomplete; and many organizations still lack the documented policies and procedures needed to turn a risk analysis into an actual risk management program. OCR was direct on one point in particular: organizations should not wait for a breach, or a completed OCR investigation, before conducting a compliant risk analysis.

    Why This Conference Matters for Compliance Programs

    Each year, OCR and NIST’s Information Technology Laboratory co-host this conference to walk through where enforcement is headed and where organizations continue to fall short. This year’s agenda, spanning two full days, included briefings from OCR’s Director, threat intelligence updates from the Health Information Sharing and Analysis Center, and a dedicated OCR track on the Health Information Privacy, Data, and Cybersecurity Division’s own enforcement data.

    For compliance teams that could not attend, the sessions functioned less like a lecture and more like a preview of what OCR expects to see when it opens the next investigation, whether that investigation starts with a breach report or a routine complaint.

    Three themes ran through nearly every OCR-led session.

    1. Enforcement Is Not Slowing Down

    OCR used its own numbers to make the point directly. As of this year’s conference, OCR reported 21 completed ransomware investigations and 14 completed investigations under its Risk Analysis Enforcement Initiative; separately, its Right of Access Initiative, focused on individuals being denied timely access to their own health records, has produced 55 completed enforcement actions to date, with a newly stated focus on parent and personal representative access requests.

    The shift in breach data helps explain where that enforcement attention is concentrated. Comparing OCR’s historical breach portal data, September 2009 through December 2025, against the first seven months of 2026:

    • Hacking and IT incidents grew from 52 percent of reported large breaches to 75 percent.
    • Network servers, as the breach location, grew from 39 percent to 68 percent.
    • Theft, once 18 percent of reported breaches, has fallen to roughly 1 percent.
    • Physical causes, such as paper records and lost laptops, have both dropped to a small share of the total.

    In short, OCR’s own data show breaches are concentrated almost entirely in network-based, hacking-related incidents, and its enforcement priorities follow that data. Organizations that assume a strong physical security posture covers their exposure are missing where the actual risk, and the actual enforcement attention, now sits.

    2. OCR Still Finds Risk Analyses Inaccurate and Incomplete

    If OCR repeated one message more than any other, it was this: a risk analysis is requested in every Security Rule investigation OCR conducts, and it remains one of the most commonly deficient documents organizations produce.

    OCR drew a specific distinction that trips up many compliance programs: a gap analysis is not the same as a risk analysis. A gap analysis compares current practices against a checklist or a set of standards. A risk analysis, as required under the Security Rule’s Security Management Process standard, is a more rigorous exercise; it requires organizations to assess risks to all electronic protected health information at every stage in which that information exists within the organization, with enough specificity to drive decisions.

    OCR’s guidance broke this down into three stages that a thorough risk analysis has to cover:

    • Where ePHI is created or enters the organization: file transmissions and uploads, manual data entry or edits to existing ePHI, and lab results or images coming in from outside systems.
    • Where ePHI flows within the organization: movement into EHR systems, between clinical and other departments, through applications such as office productivity tools, web and mobile platforms, and remote access, and across infrastructure such as backups and system logs.
    • Where ePHI leaves the organization: email, fax, and file transfer applications, collaboration tools, and equipment disposal.

    An organization that has assessed risk at only one of these three stages, most commonly the point where ePHI enters or lives in the primary EHR, has not completed the kind of accurate and thorough risk analysis the Security Rule actually requires. This is very likely why risk analysis deficiencies remain the most cited finding across OCR’s enforcement actions.

    3. Organizations Still Lack Comprehensive Policies and Procedures

    The third theme is closely tied to the second. OCR was clear that a risk analysis is not the finish line; it is meant to be a direct input into an organization’s risk management process, used to develop corrective actions for each identified risk and to guide the implementation of security measures that reduce risk to a reasonable and appropriate level while protecting the confidentiality, integrity, and availability of ePHI.

    In practice, this is where many compliance programs stall. A risk analysis is completed, findings are documented, and then the corresponding policies, procedures, and corrective action plans are never built, updated, or tied back to what the risk analysis actually found. The Right of Access Initiative is a clear example of this gap in action: individuals have a right under the Privacy Rule to timely access to their own health records, generally within 30 days, with the possibility of one 30-day extension, and at a reasonable, cost-based fee. OCR continues to receive a high volume of complaints alleging denial of access, which points less to organizations being unaware of the rule and more to access request procedures that are not documented, not followed consistently, or not updated to reflect current staff and systems.

    The pattern OCR described is consistent: a risk analysis without a connected risk management program, and policies without a documented, current process behind them, are both incomplete compliance postures, even when each piece looks reasonable on its own.

    What OCR Wants Organizations to Do Right Now

    OCR’s message on timing was direct, and it is worth stating exactly as presented: organizations should not wait for a breach, or for a completed OCR investigation, before conducting a compliant risk analysis. Waiting is, itself, the exposure.

    OCR also pointed attendees to its own risk analysis resources, including a risk analysis explainer video, the Security Risk Assessment (SRA) Tool, and ongoing guidance and cybersecurity newsletters, all built to help organizations complete a risk analysis that meets the Security Rule’s standard rather than a lighter gap assessment.

    Organizations must also notify affected individuals of a breach no later than 60 calendar days after discovery, a deadline that does not shift based on the organization’s size or complexity.

    Frequently Asked Questions

    Is OCR’s HIPAA enforcement slowing down in 2026?

    No. OCR reported 21 completed ransomware investigations, 14 completed Risk Analysis Enforcement Initiative investigations, and 55 completed Right of Access enforcement actions as of its 2026 conference, and its breach data shows hacking and network server incidents making up a growing share of reported breaches.

    Is a gap analysis the same as a HIPAA risk analysis?

    No. OCR was explicit that a gap analysis, which compares current practices to a checklist, does not meet the Security Rule’s risk analysis requirement. A compliant risk analysis assesses risk to all ePHI as it is created, as it flows through the organization, and as it leaves the organization.

    Does OCR require a risk analysis for every investigation?

    Yes. OCR stated that it requests a risk analysis in every Security Rule investigation it conducts, which makes an outdated or incomplete risk analysis one of the most common findings across enforcement actions.

    What is OCR’s Right of Access Initiative?

    It is an enforcement initiative focused on individuals being denied timely access to their own health records. The HIPAA Privacy Rule requires access generally within 30 days, with one possible 30-day extension, at a reasonable, cost-based fee; OCR has completed 55 enforcement actions under this initiative and has signaled a new focus on parent and personal representative access.

    Should organizations wait for a breach before doing a risk analysis?

    No. OCR was clear on this point: organizations should not wait for a breach or a completed OCR investigation before conducting a compliant risk analysis.

    Not Sure Your Risk Analysis Would Hold Up to OCR’s Standard? Colington Consulting Can Help You Find Out

    OCR was clear that a risk analysis needs to cover ePHI at every stage it exists in your organization, feed directly into a documented risk management program, and stay current, not sit as a one-time project. Colington Consulting works directly with covered entities and business associates to build and maintain the accurate, thorough risk analysis and related policies and procedures OCR expects to see before an investigation starts.

    Get a free HIPAA Risk Review. We will help you see exactly where your risk analysis and policies and procedures stand relative to what OCR is actually enforcing, and show you where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, and National Institute of Standards and Technology, โ€œSafeguarding Health Information: Building Assurance Through HIPAA Securityโ€ Conference, September 2 to 3, 2026, NIST Gaithersburg Campus, Gaithersburg, MD.

    U.S. Department of Health and Human Services, Office for Civil Rights, conference session materials: Risk Management; Key Takeaways; Right of Access Initiative; Risk Analysis: Accurate and Thorough.

    U.S. Department of Health and Human Services, Office for Civil Rights, HIPAA Breach Portal data, breaches by type and location of breach, September 23, 2009 through July 31, 2026.

    45 C.F.R. ยง 164.308(a)(1) โ€” Security Management Process (Risk Analysis and Risk Management).

    45 C.F.R. ยง 164.524 โ€” Right of Access.

  • Why Syncing Data to the Cloud Isnโ€™t a Valid HIPAA Ransomware Strategy

    Why Syncing Data to the Cloud Isnโ€™t a Valid HIPAA Ransomware Strategy

    If your practice or business relies on continuous cloud sync or daily cloud snapshots as your primary disaster recovery strategy, your ePHI is far more vulnerable than you think.

    Modern malware doesn’t just encrypt local workstations; it actively targets connected network drives, mapped cloud folders, and online backup repositories. If your backup target is continuously connected to your network, ransomware can encrypt the backup right along with your live electronic Protected Health Information (ePHI).

    The Flaw in Standard Cloud Sync

    Standard cloud storage services mirror changes made on local devices in real time. If a ransomware strain silently encrypts files on a local server, those encrypted files instantly sync to the cloud, overwriting clean versions.

    In its Ransomware and HIPAA Fact Sheet, the HHS Office for Civil Rights (OCR) emphasizes that ransomware is specifically designed to deny access to data. Simply having a cloud backup provider sign a Business Associate Agreement (BAA) satisfies administrative requirements. Still, it does not satisfy the technical requirements of data recovery if the underlying backup mechanism is vulnerable to simultaneous encryption.

    What the HIPAA Security Rule Actually Requires

    Under the HIPAA Security Rule, maintaining retrievable data isn’t just an IT best practiceโ€”it is an explicit legal mandate under the Contingency Plan standard (45 C.F.R. ยง 164.308(a)(7)).

    According to HHS guidance on HIPAA contingency planning, covered entities and business associates must implement three core specifications:

    1. Data Backup Plan (ยง 164.308(a)(7)(ii)(A)): Establish and implement procedures to create and maintain retrievable, exact copies of ePHI.
    2. Disaster Recovery Plan (ยง 164.308(a)(7)(ii)(B)): Establish procedures to restore any lost data resulting from an emergency or cyberattack.
    3. Testing and Revision Procedures (ยง 164.308(a)(7)(ii)(E)): Perform periodic testing and revision of contingency plans to verify data can actually be restored.

    Building an HHS-Aligned Cyber Resilience Strategy

    To meet OCR expectations during a post-incident investigation, HHS security guidance recommends moving beyond basic cloud sync to a resilient backup framework:

    • Maintain Isolated/Air-Gapped Copies: Backups must be decoupled from the primary network. Immutable storageโ€”where data is written once and cannot be altered or deleted, even by an administrative accountโ€”ensures ransomware cannot wipe out recovery points.
    • Implement Strict Access Controls: Under 45 C.F.R. ยง 164.308(a)(3), backup administrative controls must be isolated, requiring multi-factor authentication (MFA) and restricted access to prevent credential-based wiping.
    • Document Regular Restoration Tests: OCR auditors evaluate whether an organization regularly tests data restoration. Running routine restoration drills proves that backup files are uncorrupted and accessible within necessary operational timeframes.

    Action Steps for Practice Managers

    1. Audit Backup Isolation: Verify with your IT team or Managed Service Provider (MSP) whether your backups are truly air-gapped or protected by immutable object locking.
    2. Verify Testing Logs: Ensure your technical staff or vendor provides written verification of successful data restoration tests to include in your annual Security Risk Assessment (SRA) documentation.

    Not Sure Your Backups Would Actually Survive a Ransomware Attack? Colington Consulting Can Help You Find Out

    A cloud sync tool and a signed Business Associate Agreement feel like protection, but they do not test whether your data actually comes back after an attack. Colington Consulting works directly with practices and businesses to build a documented, defensible contingency plan that meets the Security Ruleโ€™s backup, disaster recovery, and testing requirements, not just the appearance of one.

    Get a free HIPAA Risk Review. We will help you evaluate your backup isolation, restoration testing, and contingency planning against what OCR actually expects, and show you exactly where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

  • Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Quick answer: No, and this is one of the most common and most understandable misconceptions in healthcare compliance. A skilled managed service provider, or MSP, can lock down your network, patch your systems, and manage backups better than most practices could on their own; if that MSP handles protected health information, it is likely a business associate with its own direct HIPAA obligations. None of that, on its own, satisfies your practice’s obligations. The Security Rule requires every covered entity to maintain its own compliance program; a practice still needs its own risk analysis, policies, workforce training, and a signed business associate agreement with every vendor that touches patient data, including its IT partner.

    Where the False Sense of Security Comes From

    It is an easy assumption to make. A practice hires a capable IT company; that company installs firewalls, manages antivirus tools, sets up secure backups, and generally keeps the network running well. From the practice’s point of view, the technical side of compliance feels handled. The trouble is that HIPAA compliance is not only a technical question. It also requires a documented risk analysis, written policies and procedures, a designated privacy and security officer, workforce training records, and an incident response plan tied specifically to protected health information. A great MSP can support several of these pieces; it cannot generate them on its own, and it certainly cannot sign them on the practice’s behalf.

    What a Good MSP Actually Covers, and What It Doesn’t

    Most reputable MSPs are genuinely strong at the technical safeguards: encryption, access controls, patch management, monitoring, and secure backups. Where the gap tends to show up is on the administrative side, since a Security Risk Analysis, HIPAA-specific workforce training, and a program for managing business associate agreements across every vendor a practice uses are compliance program tasks, not network tasks; they belong to the covered entity, even when an MSP is excellent at its own job.

    Why Not Every MSP Understands HIPAA Either

    This is the part that deserves equal attention. In our experience, most MSPs are genuinely good at IT; general cybersecurity, network uptime, and help desk support are their bread and butter. HIPAA, though, is a specific regulatory framework with its own definitions, documentation requirements, and enforcement history, and general IT training does not automatically cover it. A provider that assumes any IT company can double as a HIPAA partner is often building its compliance program on an assumption nobody actually verified. This is not a knock on MSPs; it is simply a reminder that HIPAA knowledge and IT skill are two different areas of expertise, and a practice should confirm, in writing, that its MSP genuinely understands the requirements rather than assuming it by default. Because of this, Colington Consulting works only with MSP referral partners who demonstrably understand HIPAA’s administrative, physical, and technical safeguard requirements, not just general network security.

    The Data Behind the Confidence Gap

    A recent survey of 214 IT leaders and practice managers at healthcare organizations with fewer than 250 employees found that 98 percent believed their email platforms encrypted messages by default, and more than 80 percent expressed overall confidence in their HIPAA compliance posture; in reality, tools like Microsoft 365 and Google Workspace do not guarantee that protection, and encryption can silently fail if a recipient’s server does not support current protocols. The same survey found that 83 percent believed a patient’s consent to email removed the legal requirement for safeguards, which is incorrect. As the Director of the HHS Office for Civil Rights has said, risk assessments are not optional; they are foundational, and that obligation applies to the covered entity’s own program, even when a capable vendor manages the network.

    What This Means for Your Practice

    • A signed business associate agreement with your MSP covers how it protects data, not whether your practice as a whole is HIPAA compliant.
    • Your practice still needs its own current Security Risk Analysis, documented policies, and workforce training records; none of that transfers from a vendor.
    • Ask your MSP directly how it stays current on HIPAA-specific requirements, not just general cybersecurity best practices.
    • A strong MSP and a strong compliance program work together; one does not substitute for the other.

    Frequently Asked Questions

    If our IT company signs a business associate agreement, are we HIPAA compliant?

    No. A business associate agreement establishes how your MSP is expected to protect data it can access; it does not satisfy your practice’s own obligation to complete a Security Risk Analysis, maintain policies, or train your workforce.

    Does a HIPAA-compliant MSP mean we do not need our own compliance program?

    No. Even organizations with excellent technical safeguards still need their own documented risk analysis, policies, and training; these are the covered entity’s own administrative requirements, and they hold regardless of how compliant your MSP is with its own separate obligations.

    How do we know if our MSP actually understands HIPAA?

    Ask specific questions, such as how they support your Security Risk Analysis, how they handle breach notification timelines, and whether they can speak to the difference between HIPAA and general cybersecurity best practices; a partner who cannot answer clearly is a signal worth taking seriously.

    Not Sure If Your IT Setup Actually Covers Your Compliance Obligations? Colington Consulting Can Help You Find Out

    A capable MSP is a valuable part of a compliance program; it was never meant to be the whole program. Colington Consulting works directly with small and midsize providers to build the documented, defensible pieces that sit outside of IT, and we only refer clients to MSP partners who genuinely understand HIPAA’s requirements.

    Get a free HIPAA Risk Review. We’ll help you see exactly where your IT setup ends and your compliance obligations begin, and show you what still needs to be built.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, statement on HIPAA Security Rule risk assessment obligations.

    Paubox, survey of 214 IT leaders and practice managers at healthcare organizations under 250 employees, reported in Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong.”

  • Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Quick answer: HIPAA has been federal law since 1996, yet small and midsize providers still get tripped up by it, and the reason is rarely carelessness. Most owners and office managers never received formal HIPAA training; they inherited assumptions from a prior job, a vendor’s marketing page, or an online forum, and those assumptions are often wrong. The confusion tends to fall into two camps that look opposite but create the same exposure: providers who assume a tool or vendor already handles compliance for them, and providers who never learned the regulations well enough to tell a permitted disclosure from one that actually requires authorization. Both leave real gaps, and OCR, along with a growing number of state regulators, is actively finding them.

    Thirty Years Old, Still Misunderstood

    HIPAA is not a new law, and that is part of the problem. It has been amended, reinterpreted, and layered with guidance so many times since 1996 that the version most people learned, whether from a compliance seminar a decade ago or a coworker’s offhand explanation, is often out of date. Add in the fact that most clinicians and practice administrators never sat through a formal HIPAA course in school, and you get a compliance culture built on secondhand information rather than the actual rule text.

    That gap shows up constantly in small practice communities online, where one commenter insists a tool is safe, another insists it never can be, and a third says solo practices simply do not get looked at. None of them are working from the regulation itself; they are working from what they have heard. The confusion is understandable. It is also, according to compliance experts who work directly with small practices, a training problem rather than a character problem, and it is fixable once the actual myths are named and corrected.

    Myth One: “Our Software Already Makes Us HIPAA Compliant”

    This is the myth doing the most quiet damage right now. A recent survey of IT leaders and practice managers at organizations with fewer than 250 employees found that nearly all of them believed their email platform automatically encrypted messages containing patient information. In reality, common business tools like Microsoft 365 and Google Workspace do not guarantee that protection by default; encryption can drop entirely if the recipient’s mail server does not support current protocols, leaving protected health information exposed without anyone realizing it. Close to half of healthcare email breaches trace back to Microsoft 365 environments alone.

    The same false confidence shows up with EHR platforms. A vendor’s business associate agreement covers how that vendor handles data inside its own system; it does not cover how your staff handles PHI outside the EHR, and it does not satisfy your own obligation to conduct a Security Risk Analysis. An EHR is a clinical documentation tool. It is not a compliance program, no matter what the marketing page implies.

    Myth Two: “Regulators Only Care About Big Health Systems”

    Every headline breach involves a hospital system or a national health plan, so it is an easy leap to assume enforcement follows the same pattern. It does not. OCR has been explicit that practice size does not create an exemption, and enforcement data backs that up: small medical and dental practices accounted for the majority of OCR’s financial penalties in a recent reporting year. Investigations are frequently triggered by something small, a single patient complaint, a lost laptop, or a phishing email that catches one employee, not a headline grade breach.

    Risk analysis failures have been the single most cited deficiency in OCR enforcement actions for more than a decade, and that pattern holds regardless of organization size. A five provider practice and a five hundred provider hospital system are held to the same underlying standard; the hospital system just has more staff to absorb the work.

    Myth Three: “HIPAA Only Applies Once Someone Is Officially Our Patient”

    It is a natural assumption. In most professional relationships, obligations start once a formal engagement begins, so providers assume PHI protections kick in once someone signs an intake form or shows up for a first visit. HIPAA does not draw that line. Protected health information is defined as individually identifiable information related to a person’s past, present, or future healthcare, which means a phone call, an intake questionnaire, or even a scheduling message can already be covered before a formal patient relationship exists.

    Myth Four: “The Safest Move Is to Share Nothing With Anyone”

    Overcorrection is just as common as underprepared, and it carries its own cost. Some practices become convinced they cannot discuss a patient anywhere on the premises, or that every routine disclosure for treatment purposes needs a separate signed authorization. Compliance risk management professionals who work with small providers regularly see practices treat ordinary care coordination, like transferring records to a specialist for continued treatment, as though it required the same authorization process as a marketing disclosure. It does not. HIPAA already permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization each time; practices that add friction here are not being safer, they are just slower, and staff eventually start looking for workarounds that create real risk.

    Myth Five: “A HIPAA Compliant Vendor Means We Are a HIPAA Compliant Practice”

    This one deserves its own heading because it is so common. Signing on with a vendor who advertises HIPAA compliant software, hosting, or messaging is a meaningful step, but it addresses one piece of a much larger program. Your practice still needs its own current Security Risk Analysis, its own written policies and procedures, its own workforce training, and its own documented incident response plan; none of that transfers from a vendor’s compliance posture to yours. Even organizations with no self funded health plan or complex vendor stack still need these four documented pieces, because they are what OCR asks for first in any investigation or audit.

    Why This Confusion Is Expensive, Not Just Awkward

    None of this would matter much if the stakes were low, but they are not. Healthcare has held the highest average breach cost of any industry sector for well over a decade running, and small practices absorb that cost with far less cushion than a large system. State regulators have also become more active alongside OCR, with several states bringing high profile settlements against small practices in the past year, which means a multi-state practice can no longer rely on federal HIPAA alone; state overlay requirements increasingly apply too.

    The pattern across almost every enforcement action tells the same story: it is rarely one dramatic mistake. It is a pile of ordinary, unremarkable decisions, a personal phone used for patient texts because it is faster, a new scheduling tool adopted without a signed business associate agreement, a risk analysis that was accurate three systems ago and never got updated, that nobody treated as a compliance decision when it was made.

    What Actually Clears Up the Confusion

    The fix is not memorizing the regulation. It is building a small number of documented habits that hold up regardless of which myth an employee picked up somewhere along the way.

    • Treat your Security Risk Analysis as a living document, not a one time project; update it whenever you change EHR systems, add a telehealth platform, or bring on new staff.
    • Confirm encryption in writing rather than assuming it; ask your email and EHR vendors directly whether encryption is guaranteed by default or dependent on the recipient’s system.
    • Map every point where PHI can leave your walls, phone, email, fax, text, patient portal, and confirm a business associate agreement or a documented safeguard covers each one.
    • Separate treatment, payment, and healthcare operations disclosures, which generally do not require a signed authorization, from marketing or research disclosures, which usually do.
    • Put workforce training on a real schedule, not a onboarding checkbox; most confusion traces back to staff repeating what they were told once, years ago, by someone who was also guessing.

    A Quick Self Check for Small and Midsize Practices

    โ˜  Do you have a Security Risk Analysis completed or updated within the last twelve months?

    โ˜  Have you confirmed, in writing, whether your email and messaging platforms encrypt PHI by default?

    โ˜  Do your written policies distinguish between disclosures that require patient authorization and those that do not?

    โ˜  Does every vendor touching PHI have a current, signed business associate agreement on file?

    โ˜  Has your team received HIPAA training in the last year, beyond a one time onboarding session?

    โ˜  If you offer a self funded employee health plan, has it been assessed as its own separate covered entity?

    Frequently Asked Questions

    Is a small medical or dental practice actually at risk of a HIPAA investigation?

    Yes. OCR has increasingly focused enforcement attention on smaller practices, and in a recent reporting year, small medical and dental practices accounted for the majority of OCR’s financial penalties. Investigations are often triggered by a single patient complaint or a routine incident, not a large scale breach.

    Does using a HIPAA compliant EHR mean our practice is fully compliant?

    No. An EHR vendor’s business associate agreement covers how that vendor handles data within its own system. It does not cover how your staff uses PHI outside the EHR, and it does not satisfy your practice’s own requirement to complete and maintain a Security Risk Analysis.

    Does HIPAA require a signed authorization before discussing a patient with another treating provider?

    Generally, no. HIPAA permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization for each instance. Authorization requirements typically apply to disclosures outside those categories, such as marketing.

    When do HIPAA protections actually start applying to a person’s information?

    Protected health information is defined by an individual’s past, present, or future healthcare, not by whether a formal patient relationship has begun. Information shared during an intake call or scheduling message can already be covered.

    What is the single most common deficiency OCR cites in enforcement actions?

    Risk analysis failures. An incomplete, outdated, or missing Security Risk Analysis has been the most frequently cited deficiency in OCR enforcement for more than a decade, across organizations of every size.

    Not Sure Where Your Practice Actually Stands? Colington Consulting Can Help You Find Out

    Most of the small and midsize providers we work with are not careless; they are working from secondhand information that was never fully accurate to begin with. Colington Consulting works hands on with small practices, clinics, and specialty groups to replace assumptions with a documented, defensible compliance program built for organizations that do not have a dedicated compliance department.

    Get a free HIPAA Risk Review. We will walk through where your practice’s understanding of HIPAA may be out of date, identify the gaps that matter most, and show you exactly where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong,” reporting on Paubox survey data of IT leaders and practice managers at organizations under 250 employees.

    Patient Protect, “HIPAA Compliance for Independent Medical Practices: The Complete 2026 Guide.”

    Facet Technologies, “What the 2026 HIPAA Changes Actually Mean for Your Practice.”

    HIPAA Journal, “Editorial: HIPAA Compliance Challenges for Small Medical Practices” and “Why You Don’t Need to Understand HIPAA to Make Your Small Practice HIPAA Compliant.”

    Physicians Practice, “Four Common HIPAA Misconceptions.”

    U.S. Department of Health and Human Services, HIPAA Guidance Materials, hhs.gov.

  • 5 HIPAA Compliance Gaps That Put Healthcare Organizations at Risk

    Why Small Gaps Create Big Exposure

    HIPAA compliance failures rarely begin with a single dramatic mistake. More often, they stem from overlooked documentation, inconsistent staff practices, incomplete risk reviews, or security controls that have not kept pace with operational change. For healthcare providers and business associates, these gaps can increase exposure during audits, investigations, and breach response.

    Colington Consulting helps organizations build defensible HIPAA compliance programs that are practical, documented, and aligned with real-world regulatory expectations. Below are five common compliance gaps that deserve immediate attention.

    1. Incomplete Risk Assessments

    A HIPAA risk assessment should do more than satisfy a checkbox. It should identify where protected health information is created, stored, transmitted, and exposed across systems, vendors, workflows, and physical environments. When assessments are outdated, too narrow, or unsupported by evidence, organizations may struggle to demonstrate a reasonable compliance posture.

    A defensible risk assessment creates the foundation for stronger decisions, better documentation, and more credible compliance efforts.

    2. Weak Risk Management Follow-Through

    Finding risks is only the beginning. A common problem is the absence of a documented risk management plan that prioritizes issues, assigns responsibility, and tracks remediation over time. Without follow-through, known weaknesses remain unresolved and can become harder to explain after an incident.

    3. Staff Training That Lacks Depth

    HIPAA training should reflect actual job responsibilities and current threats, not just generic annual reminders. Workforce members need clear guidance on privacy expectations, security practices, phishing awareness, device use, reporting procedures, and how to handle protected health information in day-to-day operations.

    • Role-based training improves relevance
    • Recurring refreshers reinforce accountability
    • Documented completion records support compliance readiness

    4. Outdated Policies and Documentation

    Policies that do not match current systems, vendors, or workflows can create significant compliance risk. Organizations should regularly review privacy and security documentation, business associate oversight practices, facility safeguards, and incident response procedures to ensure written materials reflect operational reality.

    5. Limited Access to Expert Guidance

    Many organizations do not need a large internal compliance department, but they do need reliable expertise when important decisions arise. Virtual HIPAA compliance officer support and hourly consulting can help leadership evaluate risks, respond to questions, and strengthen documentation before issues escalate.

    What a Stronger Program Looks Like

    A stronger HIPAA compliance program is not built on assumptions. It is built on documented assessments, practical risk management, informed staff, current policies, and access to experienced consulting support. When these elements work together, organizations are better positioned to reduce risk exposure and respond confidently to regulatory scrutiny.

    How Colington Consulting Helps

    Colington Consulting supports healthcare providers and business associates with HIPAA risk assessments, risk management plans, staff training, policy reviews, privacy and security rule documentation, facility security planning, and ongoing consulting guidance. The goal is to help organizations create compliance programs that are practical, defensible, and ready for real-world challenges.

    If your organization is unsure whether its current HIPAA program would hold up under an audit, investigation, or breach review, now is the right time to evaluate the gaps and strengthen the foundation.

    Schedule a Free HIPAA Risk Review

    No Obligation. No Committment

  • Does Billing Medicaid Make Schools HIPAA Covered?

    Schools Are Billing Medicaid for Behavioral Health Services โ€” Does That Make Your District a HIPAA Covered Entity?

    Quick answer: In most cases, yes โ€” technically. The moment your district (or a provider it employs) electronically bills Medicaid for a student’s mental health or behavioral health services, federal rules treat you as a HIPAA โ€œcovered entityโ€ for that transaction. In practice, though, HIPAA’s Privacy Rule almost never governs the actual student records โ€” FERPA does, because the information lives in an โ€œeducation record.โ€ The real compliance risk isn’t a phantom HIPAA violation; it’s assuming neither law applies and skipping the safeguards both actually require.

    Why Districts Are Asking This Question Right Now

    School-based Medicaid billing for mental and behavioral health services has expanded quickly, and much of that growth is happening outside the traditional special-education framework:

    โ€ข A growing number of states โ€” including Arkansas, Missouri, Minnesota, Tennessee, and South Carolina โ€” now allow districts to bill Medicaid for behavioral health services without even filing a State Plan Amendment.

    โ€ข Schools nationally receive an estimated $4โ€“6 billion a year in Medicaid reimbursement for school-based services, and only a fraction of states have expanded reimbursement beyond students served under IDEA.

    โ€ข Students are roughly six times more likely to access mental health care when it’s offered at school, which is pushing more districts to add counselors, therapists, and telehealth partnerships โ€” and to bill Medicaid for them.

    As behavioral health billing becomes a bigger part of how districts fund student services, the HIPAA question follows naturally: if we’re submitting health care claims, are we now a HIPAA-regulated organization?

    The Technical Answer: Electronic Medicaid Billing Makes You a Covered Entity

    HHS guidance is direct on this point: a school that employs a health care provider โ€” a school psychologist, counselor, therapist, or nurse โ€” who electronically submits a Medicaid claim for a covered transaction becomes a HIPAA โ€œcovered entityโ€ for that transaction. This is true whether the district thinks of itself as a health care organization or not.

    It doesn’t matter who does the billing. A school nurse submitting a claim, a contracted mental health provider billing on the district’s behalf, or a telehealth vendor billing under the district’s Medicaid provider number can all trigger covered-entity status for the underlying transaction.

    But FERPA โ€” Not the HIPAA Privacy Rule โ€” Usually Still Governs the Records

    HIPAA’s own regulations carve out an exception: information maintained in โ€œeducation recordsโ€ as defined under FERPA is excluded from HIPAA’s definition of protected health information (45 CFR ยง 160.103).

    Because nearly every health-related record a K-12 school keeps on a student โ€” nurse visit logs, counseling session notes, therapy records tied to an IEP or 504 plan โ€” meets FERPA’s definition of an education record, HIPAA’s privacy protections generally don’t apply to it. FERPA’s do instead.

    The result is a scenario that confuses a lot of administrators: your district can be a HIPAA covered entity that, for privacy purposes, has no protected health information at all โ€” because everything it holds is a FERPA education record instead.

    Where HIPAA Doesn’t Go Away Entirely

    Covered-entity status isn’t purely academic. Even when the Privacy Rule steps aside, a few things still apply:

    โ€ข Your district must still comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself โ€” whoever submits the claim, and whatever software or clearinghouse touches it, has to meet those technical standards.

    โ€ข If a contracted provider bills independently under its own name โ€” for example, an outside behavioral health agency or telehealth vendor that isn’t itself subject to FERPA โ€” that provider may be a full HIPAA covered entity for the records it creates, privacy rule included.

    โ€ข Private and religious schools generally don’t receive federal education funding and typically aren’t subject to FERPA at all โ€” which means a private school billing Medicaid electronically may be a HIPAA covered entity with no FERPA exclusion to fall back on.

    Why the Distinction Actually Matters for Your Compliance Program

    This isn’t just a legal technicality. It changes what your district is required to do in several concrete ways:

    1. Consent requirements differ. FERPA requires written parental (or eligible student) consent before disclosing information for Medicaid billing purposes โ€” a separate requirement from HIPAA authorization, and the one that usually governs here.

    2. Breach response follows different rules. Education records generally trigger FERPA and state student-data-privacy breach obligations, not the HIPAA Breach Notification Rule โ€” unless an independent, non-FERPA-covered provider’s records are involved.

    3. Vendor paperwork needs to match reality. Internal school-based providers typically need FERPA-compliant data-sharing or โ€œschool officialโ€ agreements. Outside billing vendors, clearinghouses, or telehealth partners that are themselves HIPAA covered entities need Business Associate Agreements.

    4. Security expectations are converging either way. FERPA doesn’t include HIPAA’s detailed Security Rule requirements, but cyber insurers, state privacy laws, and CMS program-integrity reviews increasingly expect HIPAA-grade safeguards around any system that touches Medicaid claims data โ€” regardless of which privacy law technically applies to the record.

    A Compliance Checklist for Districts Billing Medicaid for Behavioral Health

    โ€ข Map every point where a district employee or contracted provider submits an electronic Medicaid claim for mental or behavioral health services.

    โ€ข For each record type, confirm the governing framework: education record โ†’ FERPA governs privacy; independent outside provider not subject to FERPA โ†’ HIPAA Privacy Rule likely governs.

    โ€ข Update consent forms so FERPA consent language explicitly covers disclosure of information for Medicaid billing purposes.

    โ€ข Audit vendor contracts: FERPA-compliant data-sharing agreements for internal providers, Business Associate Agreements for any outside billing vendor, clearinghouse, or telehealth partner that qualifies as a HIPAA covered entity.

    โ€ข Apply HIPAA-grade technical safeguards โ€” encryption, access controls, audit logging โ€” to whatever system actually submits the Medicaid claims, even if the broader student record system is FERPA-governed.

    โ€ข Train school health staff, counselors, and administrators on which framework governs which piece of information. This is where most real-world confusion, and risk, actually lives.

    Frequently Asked Questions

    Does billing Medicaid for a student’s counseling or therapy services make our school district a HIPAA covered entity?

    Generally, yes. If the district or a health care provider it employs submits an electronic Medicaid claim for a covered transaction, HHS treats the district as a HIPAA covered entity for that transaction โ€” even if the district doesn’t think of itself as a health care organization.

    Does that mean the HIPAA Privacy Rule applies to our students’ behavioral health records?

    Usually not. If those records qualify as โ€œeducation recordsโ€ under FERPA โ€” which most school-maintained counseling and mental health records do โ€” HIPAA’s Privacy Rule explicitly excludes them, and FERPA governs privacy instead.

    Do we still need to worry about HIPAA at all?

    Yes. Your district still has to comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself. And if you contract with an outside provider that isn’t subject to FERPA, that provider’s records may be governed by the full HIPAA Privacy Rule.

    What’s the difference between FERPA consent and HIPAA authorization for Medicaid billing?

    FERPA requires written parental or eligible-student consent before disclosing information for Medicaid billing purposes. HIPAA authorization is a separate, more detailed requirement that generally doesn’t apply when the record is a FERPA education record โ€” but it can apply to an independent HIPAA-covered provider working with your district.

    What should our district do first?

    Start by mapping every point where student behavioral health information is electronically billed to Medicaid, then confirm which framework โ€” FERPA or HIPAA โ€” governs each record and each vendor relationship involved.

    Not Sure Which Rules Apply to Your District’s Medicaid Billing? Find Out Before It Becomes a Problem

    FERPA and HIPAA overlap in ways that trip up even well-run compliance programs โ€” especially as more districts add behavioral health billing to their Medicaid programs. The safest move is finding out now exactly which framework governs each piece of your student health data and each vendor relationship, not after an incident forces the question.

    Get a free HIPAA Risk Review. We’ll help you map where FERPA and HIPAA intersect in your district’s Medicaid billing and show you exactly where your compliance gaps are.

    Schedule Your Free HIPAA Risk Review

    Sources

    U.S. Department of Health and Human Services & U.S. Department of Education, Joint Guidance on the Application of FERPA and HIPAA to Student Health Records (December 2019 update).

    45 CFR ยง 160.103 โ€” HIPAA definitions; exclusion of FERPA โ€œeducation recordsโ€ from โ€œprotected health information.โ€

    MACPAC, School-Based Services for Students Enrolled in Medicaid (March 2024), macpac.gov.

    Healthy Schools Campaign, Medicaid Funding for School-Based Services.

  • HIPAA Security Rule Delay: Why You’re Not Off the Hook

    Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ€” the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.

    What Actually Happened

    In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:

    • Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
    • Mandatory multi-factor authentication on all systems touching ePHI
    • 72-hour incident reporting timelines
    • Annual penetration testing
    • Tighter oversight and contractual obligations for business associates

    More than 100 hospital systems and provider associations โ€” including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ€” formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.

    HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ€” and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.

    What the Delay Does Not Change

    This is the part that gets lost in the headlines:

    1. The current Security Rule is still active and enforceable. Every requirement already on the books โ€” risk analysis, access controls, audit controls, transmission security, business associate agreements โ€” remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
    2. OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
    3. State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
    4. The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ€” they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.

    “We Have More Time” Is the Wrong Read

    The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:

    • Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
    • A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
    • Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ€” that risk doesn’t disappear because the paperwork is delayed.

    What Compliance Teams Should Do With the Extra Time

    Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.

    1. Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ€” these are the two changes most likely to survive the rulemaking process largely intact.
    2. Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
    3. Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ€” this is the kind of internal capability that takes real time to build.
    4. Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.

    Frequently Asked Questions

    Is the HIPAA Security Rule update dead?

    No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.

    Do I still have to comply with HIPAA Security Rule requirements right now?

    Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.

    When will the new HIPAA Security Rule requirements take effect?

    HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.

    What should healthcare organizations do now?

    Use the additional time to close gaps against the proposed requirements โ€” especially encryption, MFA, business associate oversight, and incident response โ€” rather than waiting for a final rule to start preparing.

    Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To

    The safest move during this delay isn’t waiting โ€” it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.

    Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.

    Schedule Your Free HIPAA Risk Review โ†’

    Source

    U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ€” RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Is the New HIPAA Security Rule Final Yet?

    Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now

    Quick answer: No. As of mid-2026, the proposed HIPAA Security Rule overhaul is still just that โ€” proposed. OCR has not issued a final rule, its informal May 2026 target came and went with nothing published, and a coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the rule altogether. That said, organizations shouldn’t treat “not final” as “not urgentโ€ as HIPAA’s civil penalty tiers already increased this year under current law, and history shows compliance windows shrink fast once a final rule does land.

    What the Proposed Rule Would Actually Change

    The HIPAA Security Rule hasn’t seen a substantive update since 2013. The Notice of Proposed Rulemaking published in January 2025 would be the most significant rewrite in the rule’s history, and the headline change is structural: it eliminates the long-standing distinction between “addressable” and “required” safeguards. Today, organizations can implement reasonable alternatives to certain controls and document why. Under the proposal, that flexibility disappears โ€” nearly every safeguard becomes mandatory.

    In practice, that means encryption of electronic PHI at rest and in transit with no documented-alternative exception, multi-factor authentication required for any system that touches ePHI, network segmentation written explicitly into the technical safeguards, and a shift from occasional testing to recurring, scheduled technical assessments such as penetration testing. Business associates would also face tighter, faster incident-reporting obligations to the covered entities they serve.

    Where Things Actually Stand

    OCR’s own regulatory agenda pointed to a May 2026 finalization, but that window has passed without action. Pushback has been significant: HHS’s own regulatory impact analysis estimated roughly $9 billion in first-year industry compliance costs, climbing toward $34 billion over five years, and that price tag is a big part of why provider groups are lobbying for withdrawal rather than finalization. There’s no confirmed new timeline. If and when a final rule does publish, the expected compliance runway is short โ€” roughly 60 days until the rule takes effect, then another 180 days to come into full compliance.

    The Part That’s Already Real: Penalties Went Up

    Separately from the Security Rule fight, OCR’s civil monetary penalty tiers received their routine annual inflation adjustment effective January 28, 2026. The top tier โ€” willful neglect that goes uncorrected โ€” now caps at $2,190,294 per calendar-year violation category, with the other tiers adjusted upward as well. This is current law today, independent of whatever happens with the proposed overhaul.

    What to Do Now, Regardless of the Final Rule’s Fate

    The organizations best positioned aren’t waiting for a final rule to start the clock. Encrypting ePHI everywhere, rolling out MFA, segmenting networks, and testing on a schedule are good security practice today and lower your real exposure under the penalty structure that already exists. A practical starting point: refresh your documented risk analysis, confirm your business associate agreements already require prompt breach notification language, and budget for these controls now rather than scrambling on a 240-day deadline later.

    Frequently Asked Questions

    Has the HIPAA Security Rule update been finalized? No. As of mid-2026 it remains a proposed rule with no confirmed finalization date.

    Will MFA become mandatory under HIPAA? Under the proposed rule, yes โ€” for any system accessing ePHI. It isn’t legally required yet, though many auditors already treat it as a baseline expectation.

    How long would organizations get to comply once it’s final? Industry estimates point to about 240 days total: roughly 60 days until the rule takes effect, then 180 more days to reach full compliance.

    Did HIPAA penalties increase in 2026? Yes. The annual inflation adjustment took effect January 28, 2026, raising the maximum penalty tier.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed on June 18, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Sources:

    • U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” Notice of Proposed Rulemaking, 90 Fed. Reg. 898 (Jan. 6, 2025). federalregister.gov
    • HHS.gov, “HIPAA Security Rule NPRM” overview page. hhs.gov
    • HHS.gov, Fact Sheet on the HIPAA Security Rule NPRM. hhs.gov
    • U.S Department of Health and Human Services, “Annual Civil Monetary Penalties Inflation Adjustment,” Fed. Reg. (Jan. 28, 2026). federalregister.gov
    • HHS.gov, “Summary of the HIPAA Security Rule” (current rule in effect). hhs.gov

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.