Author: Colington Consulting

  • 5 HIPAA Compliance Gaps That Put Healthcare Organizations at Risk

    Why Small Gaps Create Big Exposure

    HIPAA compliance failures rarely begin with a single dramatic mistake. More often, they stem from overlooked documentation, inconsistent staff practices, incomplete risk reviews, or security controls that have not kept pace with operational change. For healthcare providers and business associates, these gaps can increase exposure during audits, investigations, and breach response.

    Colington Consulting helps organizations build defensible HIPAA compliance programs that are practical, documented, and aligned with real-world regulatory expectations. Below are five common compliance gaps that deserve immediate attention.

    1. Incomplete Risk Assessments

    A HIPAA risk assessment should do more than satisfy a checkbox. It should identify where protected health information is created, stored, transmitted, and exposed across systems, vendors, workflows, and physical environments. When assessments are outdated, too narrow, or unsupported by evidence, organizations may struggle to demonstrate a reasonable compliance posture.

    A defensible risk assessment creates the foundation for stronger decisions, better documentation, and more credible compliance efforts.

    2. Weak Risk Management Follow-Through

    Finding risks is only the beginning. A common problem is the absence of a documented risk management plan that prioritizes issues, assigns responsibility, and tracks remediation over time. Without follow-through, known weaknesses remain unresolved and can become harder to explain after an incident.

    3. Staff Training That Lacks Depth

    HIPAA training should reflect actual job responsibilities and current threats, not just generic annual reminders. Workforce members need clear guidance on privacy expectations, security practices, phishing awareness, device use, reporting procedures, and how to handle protected health information in day-to-day operations.

    • Role-based training improves relevance
    • Recurring refreshers reinforce accountability
    • Documented completion records support compliance readiness

    4. Outdated Policies and Documentation

    Policies that do not match current systems, vendors, or workflows can create significant compliance risk. Organizations should regularly review privacy and security documentation, business associate oversight practices, facility safeguards, and incident response procedures to ensure written materials reflect operational reality.

    5. Limited Access to Expert Guidance

    Many organizations do not need a large internal compliance department, but they do need reliable expertise when important decisions arise. Virtual HIPAA compliance officer support and hourly consulting can help leadership evaluate risks, respond to questions, and strengthen documentation before issues escalate.

    What a Stronger Program Looks Like

    A stronger HIPAA compliance program is not built on assumptions. It is built on documented assessments, practical risk management, informed staff, current policies, and access to experienced consulting support. When these elements work together, organizations are better positioned to reduce risk exposure and respond confidently to regulatory scrutiny.

    How Colington Consulting Helps

    Colington Consulting supports healthcare providers and business associates with HIPAA risk assessments, risk management plans, staff training, policy reviews, privacy and security rule documentation, facility security planning, and ongoing consulting guidance. The goal is to help organizations create compliance programs that are practical, defensible, and ready for real-world challenges.

    If your organization is unsure whether its current HIPAA program would hold up under an audit, investigation, or breach review, now is the right time to evaluate the gaps and strengthen the foundation.

    Schedule a Free HIPAA Risk Review

    No Obligation. No Committment

  • Does Billing Medicaid Make Schools HIPAA Covered?

    Schools Are Billing Medicaid for Behavioral Health Services โ€” Does That Make Your District a HIPAA Covered Entity?

    Quick answer: In most cases, yes โ€” technically. The moment your district (or a provider it employs) electronically bills Medicaid for a student’s mental health or behavioral health services, federal rules treat you as a HIPAA โ€œcovered entityโ€ for that transaction. In practice, though, HIPAA’s Privacy Rule almost never governs the actual student records โ€” FERPA does, because the information lives in an โ€œeducation record.โ€ The real compliance risk isn’t a phantom HIPAA violation; it’s assuming neither law applies and skipping the safeguards both actually require.

    Why Districts Are Asking This Question Right Now

    School-based Medicaid billing for mental and behavioral health services has expanded quickly, and much of that growth is happening outside the traditional special-education framework:

    โ€ข A growing number of states โ€” including Arkansas, Missouri, Minnesota, Tennessee, and South Carolina โ€” now allow districts to bill Medicaid for behavioral health services without even filing a State Plan Amendment.

    โ€ข Schools nationally receive an estimated $4โ€“6 billion a year in Medicaid reimbursement for school-based services, and only a fraction of states have expanded reimbursement beyond students served under IDEA.

    โ€ข Students are roughly six times more likely to access mental health care when it’s offered at school, which is pushing more districts to add counselors, therapists, and telehealth partnerships โ€” and to bill Medicaid for them.

    As behavioral health billing becomes a bigger part of how districts fund student services, the HIPAA question follows naturally: if we’re submitting health care claims, are we now a HIPAA-regulated organization?

    The Technical Answer: Electronic Medicaid Billing Makes You a Covered Entity

    HHS guidance is direct on this point: a school that employs a health care provider โ€” a school psychologist, counselor, therapist, or nurse โ€” who electronically submits a Medicaid claim for a covered transaction becomes a HIPAA โ€œcovered entityโ€ for that transaction. This is true whether the district thinks of itself as a health care organization or not.

    It doesn’t matter who does the billing. A school nurse submitting a claim, a contracted mental health provider billing on the district’s behalf, or a telehealth vendor billing under the district’s Medicaid provider number can all trigger covered-entity status for the underlying transaction.

    But FERPA โ€” Not the HIPAA Privacy Rule โ€” Usually Still Governs the Records

    HIPAA’s own regulations carve out an exception: information maintained in โ€œeducation recordsโ€ as defined under FERPA is excluded from HIPAA’s definition of protected health information (45 CFR ยง 160.103).

    Because nearly every health-related record a K-12 school keeps on a student โ€” nurse visit logs, counseling session notes, therapy records tied to an IEP or 504 plan โ€” meets FERPA’s definition of an education record, HIPAA’s privacy protections generally don’t apply to it. FERPA’s do instead.

    The result is a scenario that confuses a lot of administrators: your district can be a HIPAA covered entity that, for privacy purposes, has no protected health information at all โ€” because everything it holds is a FERPA education record instead.

    Where HIPAA Doesn’t Go Away Entirely

    Covered-entity status isn’t purely academic. Even when the Privacy Rule steps aside, a few things still apply:

    โ€ข Your district must still comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself โ€” whoever submits the claim, and whatever software or clearinghouse touches it, has to meet those technical standards.

    โ€ข If a contracted provider bills independently under its own name โ€” for example, an outside behavioral health agency or telehealth vendor that isn’t itself subject to FERPA โ€” that provider may be a full HIPAA covered entity for the records it creates, privacy rule included.

    โ€ข Private and religious schools generally don’t receive federal education funding and typically aren’t subject to FERPA at all โ€” which means a private school billing Medicaid electronically may be a HIPAA covered entity with no FERPA exclusion to fall back on.

    Why the Distinction Actually Matters for Your Compliance Program

    This isn’t just a legal technicality. It changes what your district is required to do in several concrete ways:

    1. Consent requirements differ. FERPA requires written parental (or eligible student) consent before disclosing information for Medicaid billing purposes โ€” a separate requirement from HIPAA authorization, and the one that usually governs here.

    2. Breach response follows different rules. Education records generally trigger FERPA and state student-data-privacy breach obligations, not the HIPAA Breach Notification Rule โ€” unless an independent, non-FERPA-covered provider’s records are involved.

    3. Vendor paperwork needs to match reality. Internal school-based providers typically need FERPA-compliant data-sharing or โ€œschool officialโ€ agreements. Outside billing vendors, clearinghouses, or telehealth partners that are themselves HIPAA covered entities need Business Associate Agreements.

    4. Security expectations are converging either way. FERPA doesn’t include HIPAA’s detailed Security Rule requirements, but cyber insurers, state privacy laws, and CMS program-integrity reviews increasingly expect HIPAA-grade safeguards around any system that touches Medicaid claims data โ€” regardless of which privacy law technically applies to the record.

    A Compliance Checklist for Districts Billing Medicaid for Behavioral Health

    โ€ข Map every point where a district employee or contracted provider submits an electronic Medicaid claim for mental or behavioral health services.

    โ€ข For each record type, confirm the governing framework: education record โ†’ FERPA governs privacy; independent outside provider not subject to FERPA โ†’ HIPAA Privacy Rule likely governs.

    โ€ข Update consent forms so FERPA consent language explicitly covers disclosure of information for Medicaid billing purposes.

    โ€ข Audit vendor contracts: FERPA-compliant data-sharing agreements for internal providers, Business Associate Agreements for any outside billing vendor, clearinghouse, or telehealth partner that qualifies as a HIPAA covered entity.

    โ€ข Apply HIPAA-grade technical safeguards โ€” encryption, access controls, audit logging โ€” to whatever system actually submits the Medicaid claims, even if the broader student record system is FERPA-governed.

    โ€ข Train school health staff, counselors, and administrators on which framework governs which piece of information. This is where most real-world confusion, and risk, actually lives.

    Frequently Asked Questions

    Does billing Medicaid for a student’s counseling or therapy services make our school district a HIPAA covered entity?

    Generally, yes. If the district or a health care provider it employs submits an electronic Medicaid claim for a covered transaction, HHS treats the district as a HIPAA covered entity for that transaction โ€” even if the district doesn’t think of itself as a health care organization.

    Does that mean the HIPAA Privacy Rule applies to our students’ behavioral health records?

    Usually not. If those records qualify as โ€œeducation recordsโ€ under FERPA โ€” which most school-maintained counseling and mental health records do โ€” HIPAA’s Privacy Rule explicitly excludes them, and FERPA governs privacy instead.

    Do we still need to worry about HIPAA at all?

    Yes. Your district still has to comply with HIPAA’s Transaction, Code Set, and Identifier Rules for the Medicaid billing itself. And if you contract with an outside provider that isn’t subject to FERPA, that provider’s records may be governed by the full HIPAA Privacy Rule.

    What’s the difference between FERPA consent and HIPAA authorization for Medicaid billing?

    FERPA requires written parental or eligible-student consent before disclosing information for Medicaid billing purposes. HIPAA authorization is a separate, more detailed requirement that generally doesn’t apply when the record is a FERPA education record โ€” but it can apply to an independent HIPAA-covered provider working with your district.

    What should our district do first?

    Start by mapping every point where student behavioral health information is electronically billed to Medicaid, then confirm which framework โ€” FERPA or HIPAA โ€” governs each record and each vendor relationship involved.

    Not Sure Which Rules Apply to Your District’s Medicaid Billing? Find Out Before It Becomes a Problem

    FERPA and HIPAA overlap in ways that trip up even well-run compliance programs โ€” especially as more districts add behavioral health billing to their Medicaid programs. The safest move is finding out now exactly which framework governs each piece of your student health data and each vendor relationship, not after an incident forces the question.

    Get a free HIPAA Risk Review. We’ll help you map where FERPA and HIPAA intersect in your district’s Medicaid billing and show you exactly where your compliance gaps are.

    Schedule Your Free HIPAA Risk Review

    Sources

    U.S. Department of Health and Human Services & U.S. Department of Education, Joint Guidance on the Application of FERPA and HIPAA to Student Health Records (December 2019 update).

    45 CFR ยง 160.103 โ€” HIPAA definitions; exclusion of FERPA โ€œeducation recordsโ€ from โ€œprotected health information.โ€

    MACPAC, School-Based Services for Students Enrolled in Medicaid (March 2024), macpac.gov.

    Healthy Schools Campaign, Medicaid Funding for School-Based Services.

  • HIPAA Security Rule Delay: Why You’re Not Off the Hook

    Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ€” the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.

    What Actually Happened

    In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:

    • Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
    • Mandatory multi-factor authentication on all systems touching ePHI
    • 72-hour incident reporting timelines
    • Annual penetration testing
    • Tighter oversight and contractual obligations for business associates

    More than 100 hospital systems and provider associations โ€” including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ€” formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.

    HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ€” and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.

    What the Delay Does Not Change

    This is the part that gets lost in the headlines:

    1. The current Security Rule is still active and enforceable. Every requirement already on the books โ€” risk analysis, access controls, audit controls, transmission security, business associate agreements โ€” remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
    2. OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
    3. State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
    4. The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ€” they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.

    “We Have More Time” Is the Wrong Read

    The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:

    • Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
    • A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
    • Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ€” that risk doesn’t disappear because the paperwork is delayed.

    What Compliance Teams Should Do With the Extra Time

    Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.

    1. Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ€” these are the two changes most likely to survive the rulemaking process largely intact.
    2. Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
    3. Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ€” this is the kind of internal capability that takes real time to build.
    4. Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.

    Frequently Asked Questions

    Is the HIPAA Security Rule update dead?

    No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.

    Do I still have to comply with HIPAA Security Rule requirements right now?

    Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.

    When will the new HIPAA Security Rule requirements take effect?

    HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.

    What should healthcare organizations do now?

    Use the additional time to close gaps against the proposed requirements โ€” especially encryption, MFA, business associate oversight, and incident response โ€” rather than waiting for a final rule to start preparing.

    Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To

    The safest move during this delay isn’t waiting โ€” it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.

    Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.

    Schedule Your Free HIPAA Risk Review โ†’

    Source

    U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ€” RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Is the New HIPAA Security Rule Final Yet?

    Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now

    Quick answer: No. As of mid-2026, the proposed HIPAA Security Rule overhaul is still just that โ€” proposed. OCR has not issued a final rule, its informal May 2026 target came and went with nothing published, and a coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the rule altogether. That said, organizations shouldn’t treat “not final” as “not urgentโ€ as HIPAA’s civil penalty tiers already increased this year under current law, and history shows compliance windows shrink fast once a final rule does land.

    What the Proposed Rule Would Actually Change

    The HIPAA Security Rule hasn’t seen a substantive update since 2013. The Notice of Proposed Rulemaking published in January 2025 would be the most significant rewrite in the rule’s history, and the headline change is structural: it eliminates the long-standing distinction between “addressable” and “required” safeguards. Today, organizations can implement reasonable alternatives to certain controls and document why. Under the proposal, that flexibility disappears โ€” nearly every safeguard becomes mandatory.

    In practice, that means encryption of electronic PHI at rest and in transit with no documented-alternative exception, multi-factor authentication required for any system that touches ePHI, network segmentation written explicitly into the technical safeguards, and a shift from occasional testing to recurring, scheduled technical assessments such as penetration testing. Business associates would also face tighter, faster incident-reporting obligations to the covered entities they serve.

    Where Things Actually Stand

    OCR’s own regulatory agenda pointed to a May 2026 finalization, but that window has passed without action. Pushback has been significant: HHS’s own regulatory impact analysis estimated roughly $9 billion in first-year industry compliance costs, climbing toward $34 billion over five years, and that price tag is a big part of why provider groups are lobbying for withdrawal rather than finalization. There’s no confirmed new timeline. If and when a final rule does publish, the expected compliance runway is short โ€” roughly 60 days until the rule takes effect, then another 180 days to come into full compliance.

    The Part That’s Already Real: Penalties Went Up

    Separately from the Security Rule fight, OCR’s civil monetary penalty tiers received their routine annual inflation adjustment effective January 28, 2026. The top tier โ€” willful neglect that goes uncorrected โ€” now caps at $2,190,294 per calendar-year violation category, with the other tiers adjusted upward as well. This is current law today, independent of whatever happens with the proposed overhaul.

    What to Do Now, Regardless of the Final Rule’s Fate

    The organizations best positioned aren’t waiting for a final rule to start the clock. Encrypting ePHI everywhere, rolling out MFA, segmenting networks, and testing on a schedule are good security practice today and lower your real exposure under the penalty structure that already exists. A practical starting point: refresh your documented risk analysis, confirm your business associate agreements already require prompt breach notification language, and budget for these controls now rather than scrambling on a 240-day deadline later.

    Frequently Asked Questions

    Has the HIPAA Security Rule update been finalized? No. As of mid-2026 it remains a proposed rule with no confirmed finalization date.

    Will MFA become mandatory under HIPAA? Under the proposed rule, yes โ€” for any system accessing ePHI. It isn’t legally required yet, though many auditors already treat it as a baseline expectation.

    How long would organizations get to comply once it’s final? Industry estimates point to about 240 days total: roughly 60 days until the rule takes effect, then 180 more days to reach full compliance.

    Did HIPAA penalties increase in 2026? Yes. The annual inflation adjustment took effect January 28, 2026, raising the maximum penalty tier.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed on June 18, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Sources:

    • U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” Notice of Proposed Rulemaking, 90 Fed. Reg. 898 (Jan. 6, 2025). federalregister.gov
    • HHS.gov, “HIPAA Security Rule NPRM” overview page. hhs.gov
    • HHS.gov, Fact Sheet on the HIPAA Security Rule NPRM. hhs.gov
    • U.S Department of Health and Human Services, “Annual Civil Monetary Penalties Inflation Adjustment,” Fed. Reg. (Jan. 28, 2026). federalregister.gov
    • HHS.gov, “Summary of the HIPAA Security Rule” (current rule in effect). hhs.gov

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • When Are NEMT Organizations HIPAA Business Associates?

    Non-Emergency Medical Transportation (NEMT) providers serve a critical role in helping patients access healthcare services. However, one of the most common compliance questions in the industry is straightforward: When is a NEMT organization considered a HIPAA Business Associate?

    For most providers, the answer is simpler than expectedโ€”yet often misunderstood.

    Understanding the Business Associate Role

    HIPAA Business Associate (BA) is any organization that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity, such as a healthcare provider, health plan, or managed care organization.

    PHI includes identifiable information connected to healthcare services. In the NEMT context, that often looks like patient names tied to medical appointments, transportation arranged for treatment, Medicaid identifiers, or trip data linked to healthcare delivery.

    If your operations involve this type of information, even at a basic level, HIPAA likely applies.

    How NEMT Providers Become Business Associates

    In most healthcare transportation models, NEMT organizations are functioning as an extension of the healthcare system. This is particularly true in Medicaid and broker-driven environments, where transportation is a defined benefit tied to care.

    When trip requests are received from a broker, hospital, dialysis center, or health plan, they almost always include information that connects an individual to medical services. That connection is what transforms routine transportation data into PHI.

    Dispatch teams, drivers, and administrative staff all interact with this information in some formโ€”whether scheduling rides, confirming appointments, or maintaining trip records. Even if the data seems limited, the healthcare context is what matters.

    The role of the NEMT provider in these scenarios is not just logistical. It supports treatment access, continuity of care, and patient outcomes. From a regulatory standpoint, that places the organization squarely within the definition of a Business Associate.

    The Role of Data Storage and Technology

    Many NEMT providers assume HIPAA only applies when they actively use patient information. In reality, simply maintaining or storing PHI is enough to trigger Business Associate status.

    Trip manifests, dispatch software, billing platforms, and ride history logs often contain patient identifiers linked to healthcare services. These systemsโ€”whether cloud-based or localโ€”must be evaluated through a HIPAA compliance lens.

    Communication tools are another important factor. Dispatch-to-driver coordination frequently involves mobile apps, texting, or call systems. If these channels include PHI, they must be secured appropriately. Standard consumer tools without safeguards can create immediate compliance risks.

    What HIPAA Requires from NEMT Business Associates

    Once classified as a Business Associate, an NEMT organization takes on defined responsibilities under HIPAA.

    This includes executing Business Associate Agreements (BAAs) with covered entities, implementing safeguards to protect PHI, and training workforce members on privacy and security expectations. Organizations are also responsible for identifying risks, monitoring their environment, and responding to potential breaches.

    Importantly, these obligations apply across the organizationโ€”not just in the back office. Drivers, dispatchers, and management all play a role in protecting patient information.

    Common Misunderstandings in the NEMT Industry

    A frequent misconception is that NEMT providers are โ€œjust transportationโ€ and therefore outside the scope of healthcare regulation. In reality, the moment transportation is linked to medical care and involves patient-specific information, the regulatory landscape changes.

    This misunderstanding often leads to gaps such as missing BAAs, unsecured devices, or untrained staff. Over time, these issues increase exposure to audits, penalties, and contract challenges with healthcare partners.

    Key Takeaways

    Most NEMT organizations working within healthcare networks should assume they are operating as Business Associates. The combination of receiving, storing, and using patient information tied to medical services establishes that role in the majority of cases.

    Compliance is not just a contractual requirementโ€”it is a foundational part of operating responsibly within the healthcare ecosystem.

    Final Thoughts

    For NEMT providers, the question is rarely whether HIPAA applies, but rather whether compliance practices fully reflect that reality. Organizations that take a proactive approachโ€”aligning their policies, technology, and workforceโ€”are better positioned to reduce risk and strengthen partnerships.

    Next Steps for NEMT Providers

    At Colington Consulting, we specialize in helping NEMT providers operating as HIPAA Business Associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current compliance posture as an NEMT organization.

    • Reviewed on June 16, 2026 by:ย Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: ย 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e) ย 
    • Disclaimer:ย The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • What Are HIPAA Workforce Training Requirements?

    Under federal regulation 45 C.F.R. ยง 164.530(b)(1), all HIPAA Covered Entities and Business Associates are legally required to provide security and privacy training to every member of their workforce. Training must be delivered to new employees within a reasonable period after hiring and updated whenever a significant change occurs in company policies, software, or federal regulations. Failing to properly train employees is one of the most common triggers for Office for Civil Rights (OCR) investigations and costly financial settlements. A single employee clicking on a phishing link or mishandling Protected Health Information (PHI) can breach data security, transforming workforce training from a legal chore into your strongest line of defense.

    A common misconception is that HIPAA training is only for doctors, nurses, and medical staff. Under the law, workforce members is broadly defined to include full-time and part-time employees, volunteers, interns, contractors, and temporary staff. Administrative personnel in billing, human resources, IT, and reception roles must also be trained if they have any potential to encounter protected data. Essentially, if someone works under your direct control and could come into contact with PHI, they require formal compliance training.

    Timing is critical for maintaining a defensible position during an OCR audit. New workforce members must receive training within a reasonable period after joining the organization, which best practice dictates should occur within the first 30 to 90 days of employment. This onboarding training should ideally conclude before individuals are granted unsupervised access to systems containing Electronic Protected Health Information (ePHI). Additionally, if your organization updates its internal privacy policies, implements new Electronic Health Record (EHR) software, or if federal regulations change, affected workforce members must receive immediate retraining on those specific updates. While the law does not explicitly mandate annual training, the HIPAA Security Rule requires an ongoing security awareness training program, meaning compliance experts strongly recommend annual refresher courses alongside monthly phishing simulations.

    To satisfy both the Privacy and Security Rules, an effective training curriculum must address broad data handling principles alongside specific technological safeguards. Your training program must cover core privacy fundamentals, including what constitutes PHI, the minimum necessary standard, proper disclosure rules, and patient rights. On the technical side, employees need guidance on password management best practices, log-in monitoring protocols, and recognizing malware or phishing attempts. Finally, the training must cover organizational policies like mobile device management for personal devices, data backup protocols, physical data destruction, and clear instructions on your internal sanction policies for reporting a suspected data breach.

    If an auditor or investigator requests proof of compliance, simply stating that you train your staff is not enough. You must maintain audit-ready documentation, which means keeping signed acknowledgments or digital logs proving each employee completed their assigned modules. You must also log the exact dates training was completed and keep a record of the specific curriculum, slides, or videos used.

    Need help evaluating your organization’s current training protocols or overall compliance posture? You can schedule a HIPAA risk review with Colington Consulting to identify structural gaps before they lead to an enforcement action.

    • Reviewed on June 13, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The formal regulatory source for HIPAA workforce training requirements is 45 C.F.R. ยง 164.530(b)(1). This specific section falls under the administrative requirements of the HIPAA Privacy Rule, which dictates that a Covered Entity or Business Associate must train all members of its workforce on the policies and procedures regarding Protected Health Information (PHI) as necessary and appropriate for them to carry out their functions within the organization.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • How to Properly Dispose of PHI and ePHI Under HIPAA Regulations

    Healthcare organizations and business associates handle massive amounts of Protected Health Information (PHI) daily. However, managing data securely doesn’t stop while it is in useโ€”it extends through final destruction. Failing to securely dispose of patient records is one of the quickest ways to trigger an Office for Civil Rights (OCR) investigation, leading to severe data breaches and costly compliance fines.

    Here is what your organization needs to know about meeting HIPAA disposal requirements for both physical and electronic records.

    What Are the HIPAA Requirements for Disposing of PHI?

    The Health Insurance Portability and Accountability Act (HIPAA) does not mandate one specific method for destroying records. Instead, it requires organizations to implement reasonable and appropriate safeguards to ensure patient data cannot be reconstructed or impermissibly disclosed.

    The HIPAA Privacy Rule and Paper Records

    Under 45 CFR 164.530(c), covered entities and business associates must apply administrative, technical, and physical safeguards to protect the privacy of PHI through its final disposition.

    • The Goal: Prevent data from being readable, reconstructed, or otherwise compromised during or after the disposal process.
    • Common Violation: Tossing intact paper charts, sign-in sheets, or billing records directly into a standard trash can or public dumpster.

    The HIPAA Security Rule and ePHI

    For digital data, 45 CFR 164.310(d)(2)(i) mandates strict policies and procedures regarding the final disposition of electronic PHI (ePHI) and the hardware or electronic media on which it is stored.

    • The Goal: Ensure that ePHI is permanently cleared or purged before electronic media is re-used, recycled, or thrown away.
    • Common Violation: Donating old office computers or discarding broken hard drives without completely degaussing or physically destroying the storage media.

    Approved Methods for HIPAA-Compliant Data Destruction

    Because federal law is flexible, your organization can choose the methods that best fit your workflow, provided they guarantee the data is unrecoverable.

    Destroying Paper Records and X-Rays

    For physical media, the objective is to ensure the PHI is rendered essentially unreadable and cannot be reconstructed. Approved disposal methods include shredding, burning, pulping, or incinerating the documents. Simply tearing up a patient chart by hand or throwing intact records into a recycling bin does not meet federal compliance standards.

    Destroying Electronic Media (ePHI)

    For digital data, organizations must ensure that ePHI cannot be retrieved from the hardware or electronic media on which it was stored. Compliant methods include clearing (overwriting the data with non-sensitive information), purging (degaussing or demagnetizing the media to flip the magnetic fields), or physical destruction of the hardware itself. Physical destruction of electronic media can be achieved through specialized disintegration, incineration, or hard drive shredding.

    Managing Off-Site and Remote Employee Disposal

    With the rise of remote work and telehealth, secure disposal extends far beyond the clinic walls. Under 45 CFR 164.530(b), your workforce must be actively trained on remote data destruction policies.

    To maintain compliance with off-site employees, organizations generally utilize one of two strategies:

    1. The Return Policy: Requiring remote workforce members to securely hold and return all physical PHI to the main facility for professional shredding and disposal.
    2. The Direct Shred Policy: Permitting employees to shred paper records themselves only if the organization provides approved shredding equipment and maintains a strict verification and logging process.

    Compliance Tip: If a workforce member fails to follow your established disposal protocols, HIPAA requires that your organization apply formal, documented sanctions to the employee.

    Streamline Your HIPAA Compliance Program

    Managing the final disposition of PHI requires clear, written policies and routine staff training. If you aren’t sure whether your current destruction protocols meet federal standards, we can help.

    Colington Consulting provides customized compliance programs, comprehensive policy development, and expert risk management plans to keep your organization defensibly positioned against OCR audits.

    Schedule Your Free 30-Minute HIPAA Risk Review Now

    Frequently Asked Questions About PHI Disposal

    Can you throw away paper charts in a dumpster if they are ripped up?

    No. Simply ripping up paper charts by hand does not meet the HIPAA standard of making the text completely unreadable and impossible to reconstruct. Documents must be thoroughly shredded, pulped, or incinerated.

    Does HIPAA require a certificate of destruction?

    While the text of the HIPAA Rules does not explicitly mandate a “certificate of destruction,” utilizing a third-party shredding vendor that provides one is considered an industry best practice. It serves as vital documentation during an OCR audit to prove your organization followed proper physical safeguards.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • HIPAA Compliance: Timely Medical Records Access

    As a healthcare provider or business associate, you likely spend a massive amount of energy protecting patient data from unauthorized eyes. But are you equally focused on giving patients access to their own data?

    Under the HIPAA Privacy Rule, patients have a legal right to review and obtain copies of their protected health information (PHI). The HHS Office for Civil Rights (OCR) has aggressively ramped up its Right of Access Initiative, leveling heavy fines against organizations that delay or deny these requests.

    Below, we break down exactly what you need to do to stay compliant, avoid OCR penalties, and fulfill medical records requests efficiently.

    What is the HIPAA Right of Access Standard?

    The Core Rule: The HIPAA Right of Access standard requires covered entities to provide individuals (or their designated personal representatives) with access to inspect or obtain a copy of their PHI in a designated record set.

    This right applies regardless of whether the records are stored electronically (e.g., in an EHR system) or physically in paper files.

    How Quickly Must a Provider Respond to a Medical Records Request?

    According to guidelines from the U.S. Department of Health and Human Services (HHS), covered entities must provide the requested health information within 30 calendar days of receiving the request.

    Can You Get an Extension?

    Yes, but only under strict conditions:

    • If the records are archived off-site or otherwise not readily accessible, you may request a one-time, 30-day extension.
    • To legally claim this extension, you must provide the patient with a written explanation of the delay and the exact date they can expect their records.

    The Real Cost of Non-Compliance: OCR Enforcement Trends

    Many organizations mistakenly believe that minor administrative delays won’t trigger federal scrutiny. However, the OCR has made it clear that ignoring the 30-day window can lead to steep penalties.

    In one notable Right of Access enforcement actionโ€”the 19th case resolved under the initiativeโ€”a provider took nearly two years to deliver a childโ€™s medical records to their parent. The result? The organization was forced to implement a strict corrective action plan and pay a $5,000 settlement for a single potential violation. Bigger organizations have faced six-figure fines for similar delays.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI). Specifically, 45 CFR ยง 164.524(b)(2) dictates the 30-day response timeline and the strict conditions required for a one-time, 30-day extension. HHS OCR Enforcement Guidance: The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA and Social Media: What are the Rules?

    by Jay Hodes, Presidentย – Colington Consultingย 

    The use of social media in todayโ€™s society continues to grow as more Americans interact through one or more social media platforms. Whether writing a blog article, posting on Facebook or tweeting on Twitter, many users see social media as a primary means to communicate. According the Pew Research Center, as many as 46% of users โ€œdiscussed a news issue or eventโ€ on a social media platform.

    As more healthcare providers use or consider using social media for business purposes, HIPAA plays a more significant role in what can be said in a Facebook post, a tweet or a blog article. There are some clear challenges when it comes to meeting the requirements of the HIPAA Privacy Rule. But those challenges do not need to be obstacles, as long as there is proper guidance on what can or cannot be posted.ย 

    My advice when it comes to the use of social media in a healthcare organization is to have a comprehensive, written policy and procedure. The less discretion the better, meaning there is always structured guidance to follow with little to no wiggle room.

    In formulating your organizationโ€™s social media policy, start with the 3 Wโ€™s: Who, What and Where. ย 

    • Who โ€“ Determine who is permitted to post material on social media on behalf of the organization. Designate a specific person as the organizationโ€™s official social media administrator.
    • What โ€“ Determine what can be posted. The policy should include how to handle an individual that posts a medical question on a social media platform. As an example, if a patient can ask specific questions about a medical condition on your Facebook page, how does your organization address it? I caution from a possible liability standpoint that it may be inappropriate to respond with advice. A better response would be to ask the individual to contact the office to discuss the specific concern.
    • Where โ€“ Determine where and on what platforms posting will occur. The policy must clearly state which social media sites the organization will use. ย 

    Guidelines issued by the AMA on social media say, โ€œBe cognizant of standards of patient privacy and confidentiality. Don’t post sensitive patient information online or transmit it without appropriate protection.โ€ The guidelines also say to โ€œmaintain the appropriate boundaries of the patient-physician relationship, just as in any other context.โ€ This means following all the applicable standards of the HIPAA Privacy Rule.

    Another area of concern is the use of patient testimonials. This is a somewhat newer trend in the healthcare provider marketing strategy. Any patient testimonials used by a healthcare organization must comply with the HIPAA Privacy Rule. A healthcare provider, as a covered entity, must obtain the written authorization of the patient prior to any use or disclosure of the individualโ€™s protected health information for marketing purposes.

    In an enforcement case, a California physical therapy practice paid a settlement of $25,000 to the HHS Office for Civil Rights for a HIPAA privacy violation. There were allegations that the practice posted patient testimonials to its website without legal, HIPAA-compliant authorization. This is not a situation you want to find yourself in.

    If your organization embraces social media as a method to market or provide information, have robust policies and procedures in place and follow them. You can be social, but be safe.

    Schedule a 30-Minute HIPAA Risk Review and find out if your organization’s social media policy stands up to the HIPAA Privacy Rule